ASP.NET 5 OAuth承载令牌认证

前端之家收集整理的这篇文章主要介绍了ASP.NET 5 OAuth承载令牌认证前端之家小编觉得挺不错的,现在分享给大家,也给大家做个参考。
我试图在ASP.NET 5中实现OAuth承载令牌身份验证,并且正在努力寻找一个如何做到这一点的例子,因为OWIN的东西在ASP.NET 5中发生了变化.

例如IApplicationBuilder.USEOAuthAuthorizationServer()和IApplicationBuilder. USEOAuthBearerAuthentication()不再存在或者我没有参考?

任何指针都将不胜感激.

解决方法

我做了它的工作,但设置Thinktecture的身份服务器v 3作为我的令牌提供者,但我认为如果你有另一个令牌提供者将是相同的流程….

(更新:我添加了一个github repo代码here)

这里是我的启动类:(Identityserver v3也运行在Vnext上,稍作调整).通知我有同一个网络应用程序的服务器和网络api.如果您有两个不同的网站项目,那么这也是可以的,但这里是为了演示…

  1. public class Startup
  2. {
  3. // For more information on how to configure your application,visit http://go.microsoft.com/fwlink/?LinkID=398940
  4. public void ConfigureServices(IServiceCollection services)
  5. {
  6. services.AddMvc();
  7. }
  8.  
  9. public void Configure(IApplicationBuilder app)
  10. {
  11. app.Map("/core",core =>
  12. {
  13. var factory = InMemoryFactory.Create(
  14. users: Users.Get(),clients: Clients.Get(),scopes: Scopes.Get());
  15.  
  16. var idsrvOptions = new IdentityServerOptions
  17. {
  18. IssuerUri = "https://idsrv3.com",SiteName = "test vnext Identity server",Factory = factory,SigningCertificate = Certificate.Get(),RequireSsl = false,CorsPolicy = CorsPolicy.AllowAll,AuthenticationOptions = new AuthenticationOptions
  19. {
  20. }
  21. };
  22.  
  23. core.UseIdentityServer(idsrvOptions);
  24. });
  25.  
  26. app.Map("/api",api =>
  27. {
  28.  
  29. api.USEOAuthBearerAuthentication(options => {
  30. options.Authority = Constants.AuthorizationUrl;
  31. options.MetadataAddress = Constants.AuthorizationUrl + "/.well-known/openid-configuration";
  32. options.TokenValidationParameters.ValidAudience = "https://idsrv3.com/resources";
  33. });
  34.  
  35. api.UseMvc();
  36.  
  37. });
  38.  
  39. }
  40. }

从这里你可以看到我的IdentityServerV3被映射到’/ core’,并在同一个Web应用程序项目(可能是另一个)中,我有一个web api使用MVC.下面是控制器:

  1. [Authorize]
  2. [Route("[controller]")]
  3. public class Test : Controller
  4. {
  5. [HttpGet]
  6. public JsonResult Get()
  7. {
  8. return Json(new
  9. {
  10. message = "You See this then it's ok auth is :" + User.Identity.IsAuthenticated,});
  11. }
  12. }

我已经在我的身份服务器中配置了一个客户端:

  1. new Client
  2. {
  3. //Resource Owner Flow Client (our web UI)
  4. ClientName = "WebUI",Enabled = true,ClientId = "IdentityWebUI",ClientSecrets = new List<ClientSecret>
  5. {
  6. new ClientSecret("secret".Sha256())
  7. },Flow = Flows.ResourceOwner,AccessTokenType = AccessTokenType.Jwt,AccessTokenLifetime = 3600
  8.  
  9. }

这里是User(用于InMemory用户):

  1. return new List<InMemoryUser>
  2. {
  3. new InMemoryUser
  4. {
  5. Username = "testUser",Password = "testPwd",Subject = "I am the Subject"
  6. }
  7.  
  8. };

在fidler中,我发出以下POST以获取一个承载令牌:

  1. POST : http://localhost:4357/core/connect/token
  2.  
  3. User-Agent: Fiddler
  4. Host: localhost:4357
  5. Content-Length: 67
  6. Content-Type: application/x-www-form-urlencoded
  7. Authorization: Basic SWRlbnRpdHlXZWJVSTpzZWNyZXQ=
  8.  
  9. grant_type=password&username=testUser&password=testPwd&scope=openid

在响应中你会得到一个Access_token

  1. {"access_token":"eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiIsIng1dCI6ImEzck1VZ01Gdjl0UGNsTGE2eUYzekFrZnF1RSIsImtpZCI6ImEzck1VZ01Gdjl0UGNsTGE2eUYzekFrZnF1RSJ9.eyJjbGllbnRfaWQiOiJJZGVudGl0eVdlYlVJIiwic2NvcGUiOiJvcGVuaWQiLCJzdWIiOiJJIGFtIHRoZSBTdWJqZWN0IiwiYW1yIjoicGFzc3dvcmQiLCJhdXRoX3RpbWUiOjE0MjgzOTQ3MzAsImlkcCI6Imlkc3J2IiwiaXNzIjoiaHR0cHM6Ly9pZHNydjMuY29tIiwiYXVkIjoiaHR0cHM6Ly9pZHNydjMuY29tL3Jlc291cmNlcyIsImV4cCI6MTQyODM5ODMzMCwibmJmIjoxNDI4Mzk0NzMwfQ.cbB4YrRXaaRDNw8BjeI4Q1DvXN28xmJScMJBGWCM_zSLcH1i63cQVTmR8X86rGP5VrR0Ly4-EmWZ8911Vh4jc4Ua0Kgz2n7RbmQ6VqQX5Z_lM3F8EIgD81kpUn0v3hhSFW06aJ2Lo1XOZG_re84xGgqre-H4dC0XZR6IQMEAQ9Q5dOXBh8V1NxyLSh0PzyrRRmOnEndoaY4uaIFtbp9j7KnXxQ3ZdGmaYAO96xuhHfO1DbgRdw6fYyf4nnC795yhnwDh1QZGxPsFaysJSA_3-cjmw-29m-Ga0hD1ALfVE7R57iNLxkB6dyEuz1UFJhJyibRDW9sNspo2gQFZZGxMKQ","expires_in":3600,"token_type":"Bearer"}

那么我使用access_token来调用我的web api

这里是小提琴手(在作曲家窗格中)

  1. GET http://localhost:4357/api/Test
  2.  
  3. User-Agent: Fiddler
  4. Host: localhost:4357
  5. Content-Length: 0
  6. Content-Type: application/x-www-form-urlencoded
  7. Authorization: Bearer eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiIsIng1dCI6ImEzck1VZ01Gdjl0UGNsTGE2eUYzekFrZnF1RSIsImtpZCI6ImEzck1VZ01Gdjl0UGNsTGE2eUYzekFrZnF1RSJ9.eyJjbGllbnRfaWQiOiJJZGVudGl0eVdlYlVJIiwic2NvcGUiOiJvcGVuaWQiLCJzdWIiOiJJIGFtIHRoZSBTdWJqZWN0IiwiYW1yIjoicGFzc3dvcmQiLCJhdXRoX3RpbWUiOjE0MjgzOTQ3MzAsImlkcCI6Imlkc3J2IiwiaXNzIjoiaHR0cHM6Ly9pZHNydjMuY29tIiwiYXVkIjoiaHR0cHM6Ly9pZHNydjMuY29tL3Jlc291cmNlcyIsImV4cCI6MTQyODM5ODMzMCwibmJmIjoxNDI4Mzk0NzMwfQ.cbB4YrRXaaRDNw8BjeI4Q1DvXN28xmJScMJBGWCM_zSLcH1i63cQVTmR8X86rGP5VrR0Ly4-EmWZ8911Vh4jc4Ua0Kgz2n7RbmQ6VqQX5Z_lM3F8EIgD81kpUn0v3hhSFW06aJ2Lo1XOZG_re84xGgqre-H4dC0XZR6IQMEAQ9Q5dOXBh8V1NxyLSh0PzyrRRmOnEndoaY4uaIFtbp9j7KnXxQ3ZdGmaYAO96xuhHfO1DbgRdw6fYyf4nnC795yhnwDh1QZGxPsFaysJSA_3-cjmw-29m-Ga0hD1ALfVE7R57iNLxkB6dyEuz1UFJhJyibRDW9sNspo2gQFZZGxMKQ

然后我得到响应仍然在fidler:

您可以按照下面的link获得更多信息,但与vnext无关.我将在此创建一个帖子,因为我需要一个angularJS应用程序来验证和使用隐式流而不是资源所有者流…与visual studio 2015预览

猜你在找的asp.Net相关文章