Jwt 鑒權
基本:生成一個 Token
// 以下信息需要與鑒權的地方一致
var key = "1234567890123456";
Claim[] claims = new[] { new Claim("user", username) };
var keyBytes = Encoding.UTF8.GetBytes(key);
var creds = new SigningCredentials( new SymmetricSecurityKey(keyBytes),
SecurityAlgorithms.HmacSha256 );
var jwtSecurityToken = new JwtSecurityToken(
issuer: "wosperry.com",
audience: "wosperry.com",
claims: claims,
expires: DateTime.Now.AddMinutes(5), // 五分鍾后過期
signingCredentials: creds );
var token = new JwtSecurityTokenHandler().WriteToken(jwtSecurityToken);
封裝
- 定義
Options
類
public class TokenOptions
{
public string SecretKey { get; set; }
public string Issuer { get; set; }
public string Audience { get; set; }
public int ExpireMinutes { get; set; } = 30;
}
- 在
appsettings.json
添加相關的配置
{
"TokenOptions": {
"SecretKey": "123456789456789456",
"Issuer": "wosperry.com",
"Audience": "wosperry.com",
"ExpireMinutes": 2
}
}
- 封裝服務
// 接口
public interface IJwtService
{
Task<string> CreateTokenAsync(string username);
}
// 實現
public class JwtService : IJwtService
{
public TokenOptions TokenOptions { get; }
public JwtService(IOptions<TokenOptions> options)
{
TokenOptions = options.Value;
}
public Task<string> CreateTokenAsync(string username)
{
// 添加一些需要的鍵值對
Claim[] claims = new[] { new Claim("user", username) };
var keyBytes = Encoding.UTF8.GetBytes(key);
var creds = new SigningCredentials( new SymmetricSecurityKey(keyBytes),
SecurityAlgorithms.HmacSha256 );
var jwtSecurityToken = new JwtSecurityToken(
issuer: TokenOptions.Issuer,// 簽發者
audience: TokenOptions.Audience,// 接收者
claims: claims,// payload
expires: DateTime.Now.AddMinutes(TokenOptions.ExpireMinutes),// 過期時間
signingCredentials: creds);// 令牌
var token = new JwtSecurityTokenHandler().WriteToken(jwtSecurityToken);
return Task.FromResult(token);
}
}
- 入口配置
var section = builder.Configuration.GetSection("TokenOptions"); // 獲取TokenOptions配置
var tokenOptions = section.Get<TokenOptions>();
builder.Services.AddTransient<IJwtService, JwtService>(); // 注冊Jwt服務到容器
builder.Services.Configure<TokenOptions>(section); // 注入IOptions需要這個
builder.Services.AddAuthentication(JwtBearerDefaults.AuthenticationScheme)
.AddJwtBearer(options =>
{
options.TokenValidationParameters = new TokenValidationParameters
{
ValidateIssuer = true,//是否在令牌期間驗證簽發者
ValidateAudience = true,//是否驗證接收者
ValidateLifetime = true,//是否驗證失效時間
ValidateIssuerSigningKey = true,//是否驗證簽名
ValidAudience = tokenOptions.Audience,//接收者
ValidIssuer = tokenOptions.Issuer,//簽發者,簽發的Token的人
IssuerSigningKey = new SymmetricSecurityKey(Encoding.UTF8.GetBytes(tokenOptions.SecretKey))
};
});
- 請求管道配置( 注意順序 !!! )
// 注意順序,不然 401
app.UseAuthentication();
app.UseAuthorization();
- 方便
swagger
設置 Header
builder.Services.AddSwaggerGen(c =>
{
c.SwaggerDoc("v1", new() { Title = "Perry測試用", Version = "v1", Description = "Perry測試用\r\nPerry測試用\r\nPerry測試用\r\n" });
c.AddSecurityDefinition("Bearer", new OpenApiSecurityScheme
{
Description = "JWT Authorization header using the Bearer scheme.",
Name = "Authorization",
In = ParameterLocation.Header,
Scheme = "bearer",
Type = SecuritySchemeType.Http,
BearerFormat = "JWT"
});
c.AddSecurityRequirement(new OpenApiSecurityRequirement {
{
new OpenApiSecurityScheme
{
Reference = new OpenApiReference { Type = ReferenceType.SecurityScheme, Id = "Bearer" }
},
new List<string>()
} });
});
博客園:https://www.cnblogs.com/wosperry/p/net6_jwt.html