【NetCore】Net6 Jwt 鑒權


Jwt 鑒權

基本:生成一個 Token

// 以下信息需要與鑒權的地方一致
var key = "1234567890123456";

Claim[] claims = new[] { new Claim("user", username) };

var keyBytes = Encoding.UTF8.GetBytes(key);
var creds = new SigningCredentials( new SymmetricSecurityKey(keyBytes),
                                    SecurityAlgorithms.HmacSha256 );

var jwtSecurityToken = new JwtSecurityToken(
    issuer: "wosperry.com",
    audience: "wosperry.com",
    claims: claims,
    expires: DateTime.Now.AddMinutes(5), // 五分鍾后過期
    signingCredentials: creds );

var token = new JwtSecurityTokenHandler().WriteToken(jwtSecurityToken);

封裝

  1. 定義 Options
public class TokenOptions
{
    public string SecretKey { get; set; }
    public string Issuer { get; set; }
    public string Audience { get; set; }
    public int ExpireMinutes { get; set; } = 30;
}
  1. appsettings.json 添加相關的配置
{
  "TokenOptions": {
    "SecretKey": "123456789456789456",
    "Issuer": "wosperry.com",
    "Audience": "wosperry.com",
    "ExpireMinutes": 2
  }
}
  1. 封裝服務
// 接口
public interface IJwtService
{
    Task<string> CreateTokenAsync(string username);
}
// 實現
public class JwtService : IJwtService
{
    public TokenOptions TokenOptions { get; }

    public JwtService(IOptions<TokenOptions> options)
    {
        TokenOptions = options.Value;
    }

    public Task<string> CreateTokenAsync(string username)
    {
        // 添加一些需要的鍵值對
        Claim[] claims = new[] { new Claim("user", username) };

        var keyBytes = Encoding.UTF8.GetBytes(key);
        var creds = new SigningCredentials( new SymmetricSecurityKey(keyBytes),
                                        SecurityAlgorithms.HmacSha256 );

        var jwtSecurityToken = new JwtSecurityToken(
            issuer: TokenOptions.Issuer,// 簽發者
            audience: TokenOptions.Audience,// 接收者
            claims: claims,// payload
            expires: DateTime.Now.AddMinutes(TokenOptions.ExpireMinutes),// 過期時間
            signingCredentials: creds);// 令牌

        var token = new JwtSecurityTokenHandler().WriteToken(jwtSecurityToken);
        return Task.FromResult(token);
    }
}
  1. 入口配置
var section = builder.Configuration.GetSection("TokenOptions"); // 獲取TokenOptions配置
var tokenOptions = section.Get<TokenOptions>();

builder.Services.AddTransient<IJwtService, JwtService>(); // 注冊Jwt服務到容器
builder.Services.Configure<TokenOptions>(section); // 注入IOptions需要這個
builder.Services.AddAuthentication(JwtBearerDefaults.AuthenticationScheme)
                .AddJwtBearer(options =>
                {
                    options.TokenValidationParameters = new TokenValidationParameters
                    {
                        ValidateIssuer = true,//是否在令牌期間驗證簽發者
                        ValidateAudience = true,//是否驗證接收者
                        ValidateLifetime = true,//是否驗證失效時間
                        ValidateIssuerSigningKey = true,//是否驗證簽名
                        ValidAudience = tokenOptions.Audience,//接收者
                        ValidIssuer = tokenOptions.Issuer,//簽發者,簽發的Token的人
                        IssuerSigningKey = new SymmetricSecurityKey(Encoding.UTF8.GetBytes(tokenOptions.SecretKey))
                    };
                });

  1. 請求管道配置( 注意順序 !!!
// 注意順序,不然 401
app.UseAuthentication();
app.UseAuthorization();

  1. 方便 swagger 設置 Header
builder.Services.AddSwaggerGen(c =>
{
    c.SwaggerDoc("v1", new() { Title = "Perry測試用", Version = "v1", Description = "Perry測試用\r\nPerry測試用\r\nPerry測試用\r\n" });
    c.AddSecurityDefinition("Bearer", new OpenApiSecurityScheme
    {
        Description = "JWT Authorization header using the Bearer scheme.",
        Name = "Authorization",
        In = ParameterLocation.Header,
        Scheme = "bearer",
        Type = SecuritySchemeType.Http,
        BearerFormat = "JWT"
    });

    c.AddSecurityRequirement(new OpenApiSecurityRequirement {
                        {
                            new OpenApiSecurityScheme
                            {
                                Reference = new OpenApiReference { Type = ReferenceType.SecurityScheme, Id = "Bearer" }
                            },
                            new List<string>()
                        } });
});



博客園:https://www.cnblogs.com/wosperry/p/net6_jwt.html


免責聲明!

本站轉載的文章為個人學習借鑒使用,本站對版權不負任何法律責任。如果侵犯了您的隱私權益,請聯系本站郵箱yoyou2525@163.com刪除。



 
粵ICP備18138465號   © 2018-2025 CODEPRJ.COM