ASP.NET Core Ocelot+Consul+Nginx+JWT 構建微服務鑒權中心


ASP.NET Core Ocelot+Consul+Nginx+JWT 構建微服務鑒權中心

  1. 構建鑒權中心 通過webapi的形式給微服務頒發可以登錄的有效JWT Token
  2. 構建用戶微服務 管理用戶信息
  3. 構建測試用微服務
  4. 構建網關層,對微服務進行轉發和鑒權
  5. 使用Consul 進行服務的注冊 發現

訪問流程:

Nginx=>3個鑒權中心集群=》訪問問User 微服務驗證用戶正確性=》驗證成功鑒權中心頒發有效Token

Nginx=>(網管層)Ocelot 鑒權=》Consul(服務注冊發現)=》測試微服務

鑒權中心 Common.AuthenticationCenter

Controllers文件

AuthenticationController.cs

通過訪問用戶微服務的登錄接口,如果登錄成功就頒發JWT Token

[Route("api/[controller]")]
[ApiController]
public class AuthenticationController : ControllerBase
    {
        #region MyRegion

        private ILogger<AuthenticationController> _logger = null;
        private IJWTService _iJWTService = null;
        private readonly IConfiguration _iConfiguration;
        private HttpHelperService _HttpHelperService = null;

        public AuthenticationController(ILoggerFactory factory,
            ILogger<AuthenticationController> logger,
            IConfiguration configuration
            , IJWTService service
            , HttpHelperService httpHelperService)
        {
            this._logger = logger;
            this._iConfiguration = configuration;
            this._iJWTService = service;
            _HttpHelperService = httpHelperService;
        }

        #endregion MyRegion

        [Route("Get")]
        [HttpGet]
        public IEnumerable<int> Get()
        {
            return new List<int>() { 1, 2, 3, 4, 6, 7 };
        }

        [Route("GetKey")]
        [HttpGet]
        public string GetKey()
        {
            string keyDir = Directory.GetCurrentDirectory();
            if (RSAHelper.TryGetKeyParameters(keyDir, false, out RSAParameters keyParams) == false)
            {
                keyParams = RSAHelper.GenerateAndSaveKey(keyDir, false);
            }

            return JsonConvert.SerializeObject(keyParams);
            //return "";
        }

        [Route("Login")]
        [HttpPost]
        public HttpJsonResponse Login([FromForm] string username, [FromForm] string password)
        {
            User user = _HttpHelperService.VerifyUser(username, password);
            if (user is not null)//應該數據庫
            {
                string token = this._iJWTService.GetToken(username, password, user);
                return HttpJsonResponse.SuccessResult(token);
            }
            else
            {
                return HttpJsonResponse.FailedResult("校驗失敗");
            }
        }
    }

Utility 文件夾

Model 文件夾

User.cs

用戶微服務的 Model 抽象

public class User
    {
        /// <summary>
        /// 主鍵ID
        /// </summary>
        public long Id { get; set; }

        /// <summary>
        /// 創建時間
        /// </summary>
        public DateTime CreateTime { get; set; } = DateTime.Now;

        /// <summary>
        /// 修改時間
        /// </summary>
        public DateTime UpdateTime { get; set; } = DateTime.Now;

        /// <summary>
        /// 用戶名
        /// </summary>
        public string UserName { get; set; } = string.Empty;

        /// <summary>
        /// 密碼
        /// </summary>
        public string Password { get; set; } = string.Empty;

        /// <summary>
        /// 用戶昵稱
        /// </summary>
        public string NickName { get; set; } = string.Empty;

        /// <summary>
        /// 用戶部門ID
        /// </summary>
        public long DepartmentId { get; set; } = -1;

        /// <summary>
        /// 用戶頭像
        /// </summary>
        public string Avatar { get; set; } = string.Empty;

        /// <summary>
        /// 是否是老師
        /// </summary>
        public bool IsTeacher { get; set; } = false;

        /// <summary>
        /// 用戶規則ID 測試期間 方便測試暫不關聯規則表 -1表示普通用戶具有查詢權限 0代表管理員具有增加 刪除 修改權限
        /// </summary>
        public long RoleId { get; set; } = -1;
    }

RSA 文件夾

RSAHelper.cs

public class RSAHelper
    {
        /// <summary>
        /// 從本地文件中讀取用來簽發 Token 的 RSA Key
        /// </summary>
        /// <param name="filePath">存放密鑰的文件夾路徑</param>
        /// <param name="withPrivate"></param>
        /// <param name="keyParameters"></param>
        /// <returns></returns>
        public static bool TryGetKeyParameters(string filePath, bool withPrivate, out RSAParameters keyParameters)
        {
            string filename = withPrivate ? "key.json" : "key.public.json";
            string fileTotalPath = Path.Combine(filePath, filename);
            keyParameters = default(RSAParameters);
            if (!File.Exists(fileTotalPath))
            {
                return false;
            }
            else
            {
                keyParameters = JsonConvert.DeserializeObject<RSAParameters>(File.ReadAllText(fileTotalPath));
                return true;
            }
        }

        /// <summary>
        /// 生成並保存 RSA 公鑰與私鑰
        /// </summary>
        /// <param name="filePath">存放密鑰的文件夾路徑</param>
        /// <returns></returns>
        public static RSAParameters GenerateAndSaveKey(string filePath, bool withPrivate = true)
        {
            RSAParameters publicKeys, privateKeys;
            using (var rsa = new RSACryptoServiceProvider(2048))//即時生成
            {
                try
                {
                    privateKeys = rsa.ExportParameters(true);
                    publicKeys = rsa.ExportParameters(false);
                }
                finally
                {
                    rsa.PersistKeyInCsp = false;
                }
            }
            File.WriteAllText(Path.Combine(filePath, "key.json"), JsonConvert.SerializeObject(privateKeys));
            File.WriteAllText(Path.Combine(filePath, "key.public.json"), JsonConvert.SerializeObject(publicKeys));
            return withPrivate ? privateKeys : publicKeys;
        }

        //public static string GenerateAndSaveKey(string filePath, bool withPrivate = true)
        //{
        //    //RSAParameters publicKeys, privateKeys;
        //    using (var rsa = new RSACryptoServiceProvider(2048))//即時生成
        //    {
        //        try
        //        {
        //            //privateKeys = rsa.ExportParameters(true);
        //            //publicKeys = rsa.ExportParameters(false);

        //            //rsa.ExportRSAPublicKey();
        //            //rsa.ExportRSAPrivateKey();

        //            string publicKey = rsa.ToXmlString(false);//publickey
        //            string privateKey = rsa.ToXmlString(true);//privateKey
        //            File.WriteAllText(Path.Combine(filePath, "key.json"), privateKey);
        //            File.WriteAllText(Path.Combine(filePath, "key.public.json"), publicKey);
        //            return withPrivate ? privateKey : publicKey;
        //        }
        //        finally
        //        {
        //            rsa.PersistKeyInCsp = false;
        //        }
        //    }

        //}
    }

ConfigInformation.cs

public class ConfigInformation
    {
        public string RootUrl { get; set; }

        public string UserUrl { get; set; }

        public JWTTokenOptions JWTTokenOptions { get; set; }
    }

HttpHelperService.cs

/// <summary>
/// 就是去調用服務的---暫時沒有Consul---ToDo
/// </summary>
public class HttpHelperService
    {
        #region Option注入

        private readonly ConfigInformation _ConfigInformation;

        public HttpHelperService(IOptionsMonitor<ConfigInformation> configInformation)
        {
            this._ConfigInformation = configInformation.CurrentValue;
        }

        #endregion Option注入

        public User VerifyUser(string name, string password)
        {
            string requestUrl = $"{_ConfigInformation.RootUrl}{_ConfigInformation.UserUrl}?username={name}&password={password}";
            Console.WriteLine(requestUrl);

            HttpResponseMessage sResult = this.HttpRequest(requestUrl, HttpMethod.Get, null);
            if (sResult.IsSuccessStatusCode)
            {
                string content = sResult.Content.ReadAsStringAsync().Result;
                HttpJsonResponse response = JsonConvert.DeserializeObject<HttpJsonResponse>(content);
                User user = JsonConvert.DeserializeObject<User>(JsonConvert.SerializeObject(response.Data));
                return user;
            }
            else
            {
                return null;
            }
        }

        public HttpResponseMessage HttpRequest(string url, HttpMethod httpMethod, Dictionary<string, string> parameter)
        {
            using (HttpClient httpClient = new HttpClient())
            {
                HttpRequestMessage message = new HttpRequestMessage()
                {
                    Method = httpMethod,
                    RequestUri = new Uri(url)
                };
                if (parameter != null)
                {
                    var encodedContent = new FormUrlEncodedContent(parameter);
                    message.Content = encodedContent;
                }
                return httpClient.SendAsync(message).Result;
            }
        }
    }

IJWTService.cs

/// <summary>
/// 封裝注入
/// </summary>
public interface IJWTService
    {
        /// <summary>
        /// 獲取Token
        /// </summary>
        /// <param name="UserName">賬號</param>
        /// <param name="password">密碼</param>
        /// <param name="user">用戶信息</param>
        /// <returns></returns>
        string GetToken(string UserName, string password, User user);
    }

JWTHSService.cs

public class JWTHSService : IJWTService
    {
        #region Option注入

        private readonly JWTTokenOptions _JWTTokenOptions;

        public JWTHSService(IOptionsMonitor<ConfigInformation> configInformation)
        {
            this._JWTTokenOptions = configInformation.CurrentValue.JWTTokenOptions;
        }

        #endregion Option注入

        public string GetToken(string UserName, string password, User user)
        {
            var claims = new[]
            {
                 new Claim("username", user.UserName),
                 new Claim("id", user.Id.ToString()),
                 new Claim(ClaimTypes.Role,user.RoleId.ToString())
            };

            var key = new SymmetricSecurityKey(Encoding.UTF8.GetBytes(this._JWTTokenOptions.SecurityKey));
            var creds = new SigningCredentials(key, SecurityAlgorithms.HmacSha256);
            var token = new JwtSecurityToken(
                issuer: this._JWTTokenOptions.Issuer,
                audience: this._JWTTokenOptions.Audience,
                claims: claims,
                expires: DateTime.Now.AddMinutes(60),//5分鍾有效期
                notBefore: DateTime.Now.AddMilliseconds(5),//1分鍾后有效
                signingCredentials: creds);
            string returnToken = new JwtSecurityTokenHandler().WriteToken(token);
            return returnToken;
        }
    }

JWTRSService.cs

public class JWTRSService : IJWTService
    {
        #region Option注入

        private readonly JWTTokenOptions _JWTTokenOptions;

        public JWTRSService(IOptionsMonitor<ConfigInformation> configInformation)
        {
            this._JWTTokenOptions = configInformation.CurrentValue.JWTTokenOptions;
        }

        #endregion Option注入

        public string GetToken(string userName, string password, User user)
        {
            string jtiCustom = Guid.NewGuid().ToString();//用來標識 Token
            var claims = new[]
            {
                   new Claim(ClaimTypes.Name, user.UserName),
                   new Claim("id", user.Id.ToString()),
                   new Claim(ClaimTypes.Role,user.RoleId.ToString())
            };
            string keyDir = Directory.GetCurrentDirectory();
            if (RSAHelper.TryGetKeyParameters(keyDir, true, out RSAParameters keyParams) == false)
            {
                keyParams = RSAHelper.GenerateAndSaveKey(keyDir);
            }
            var credentials = new SigningCredentials(new RsaSecurityKey(keyParams), SecurityAlgorithms.RsaSha256Signature);

            #region XML

            //string privateKey = RSAHelper.GenerateAndSaveKey(keyDir);
            //var  RSA = new RSACryptoServiceProvider();
            //RSA.FromXmlString(privateKey);
            //var credentials = new SigningCredentials(new RsaSecurityKey(RSA), SecurityAlgorithms.RsaSha256Signature);

            #endregion XML

            var token = new JwtSecurityToken(
               issuer: this._JWTTokenOptions.Issuer,
               audience: this._JWTTokenOptions.Audience,
               claims: claims,
               expires: DateTime.Now.AddMinutes(60),//5分鍾有效期
               signingCredentials: credentials);
            var handler = new JwtSecurityTokenHandler();
            string tokenString = handler.WriteToken(token);
            return tokenString;
        }
    }

JWTTokenOptions.cs

public class JWTTokenOptions
    {
        public string Audience
        {
            get;
            set;
        }

        public string SecurityKey
        {
            get;
            set;
        }

        //public SigningCredentials Credentials
        //{
        //    get;
        //    set;
        //}

        public string Issuer
        {
            get;
            set;
        }
    }

appsettings.json

{
  "Logging": {
    "LogLevel": {
      "Default": "Information",
      "Microsoft": "Warning",
      "Microsoft.Hosting.Lifetime": "Information"
    }
  },
  "AllowedHosts": "*",
  "ConfigInformation": {
    "RootUrl": "http://localhost:10091", //服務調用
    "UserUrl": "/api/userapi/User/validate",
    "JWTTokenOptions": {
      "Audience": "http://localhost:8761",
      "Issuer": "http://localhost:8761",
      "SecurityKey": "MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDI2a2EJ7m872v0afyoSDJT2o1+SitIeJSWtLJU8/Wz2m7gStexajkeD+Lka6DSTy8gt9UwfgVQo6uKjVLG5Ex7PiGOODVqAEghBuS7JzIYU5RvI543nNDAPfnJsas96mSA7L/mD7RTE2drj6hf3oZjJpMPZUQI/B1Qjb5H3K3PNwIDAQAB"
    }
  }
}

key.json

{"D":"ayJEcDAFTdAjKtn/wUvAe0z0RtXcOFENJm55PaTbDV8QAKfKKENY5K+nvU36uSi3qh2xP6NVoo3H3rDlk6X8AEuAOQs+arGfHQ/aL4Ob3skuEioHWszXScJ2KTzrrsolOik9SybNLRSMIgQKyZY5URk3BhLqSvMDwBQ2Nht/mlx+eQi1GpPgiJFH77BlRt3O/LKafAtgS292RxeKUJn3Q4dsn1PtJX+PMPT+bn+9PZXpQtSI8r8yUtrFja61WcGN8aJrG47EfT5wa3J/mcfhEK+4hU2uI3ycW+TaNjuxDZ+nAD4k3pcNT6a1ldSi3CnZKR2p/MUh07oazmx2QEg54Q==","DP":"t58aASvJT2+mQCi9EN5RksOXrgzGNB2U6PeS8NJ9ht6HiA78+fZKrfbxXxz8i/069Tyg7dkzYeKFd93q9FhFKqsOGE67gqjelKIXFTN2s2DFiJ7neFHkIhPisdS/a+SzHziFsxYHJbWobuHlrDw2QcoYGDsgS1Crbatn7t90Hfs=","DQ":"dzpHSw7DD1vwy+mOX5nRJLVniSmcIX8MMWtCXlmzj6CdUddyiGSGFhTB+hjVHLPxsJAzoV4zBFRt1s+CHGlgjhfD6ct58i7bDVG/6OVUI4v95iYiA7kPB44DlOzVjuhlGmTm5Tw5eTwjA3s/5FUuif0DShzt4jam7f+jlTvkXaM=","Exponent":"AQAB","InverseQ":"MTykln8IgIQ2DwhC4d0d/RXNk5/PvKXSY8goldKfxCiAwTmArivvuxfHC01oKFlZkZbPRVvh0rM9QkM4pX9ITfKd4+VoxmDtMMx5oEkbxKMbJQkUvJeADmtcy/zfXq8ZNSNcIkAI4setydA6tOvRZKuudJ5tEpXOxwTel8U5ltM=","Modulus":"o0jSDb5OYfSTPFPjZS67yovVQLEA5OIrey/1mBCH8Xxvo1zLwKPYzWwkRjzSLURZ19V9AeKAiP+JxDtGRzmUflqXY3e7vKeEosk5MoUj4MlBvxVxDL3bdghJaqhARaqsuXQ1dvOGABsDIogBmvCJyJOBHXISLl+hDGIOQSpHqtMFz4UHAF5v62x82oMYT8O4lTfoTSF1+jMH31rCCERXFEz2DUngdsT8gwQncTMrVTS2dIdacvkWmN0yvzLmMqZetv12p10O7jjuN61hlhhccAibGeU3X1veOHS4L9TzQ0rLPK/yTm3QlShWZD8oiLBnNXGhS0m/RTk3Uc7IrvvaqQ==","P":"0daJpBirbZIUYZyqeXW6csoy2eKDO81G4DAe0gzyZUk7ZQ97H3sIRdKU05lmeR0KuEtp71LOaljx2MJ1vawF4zoJ3MQEjzQYQS0Gq5zLPrX/Q+Sy/7Brb9oYlfwDzlyszlZqjSyJjupNOAlpkTkytt6a5g6LtD44mo2A9XCteTM=","Q":"xzSFkOTiJGyTNatXO8pAxZyGg4qjAweJOL5wv5dGqFF7fWx92uJrMcGy6kda5A3aCE0KG0441fWjGPjzb6GvoTzwADRx4mNhOcVV0gx/lbKydc15KaBNEX29TkmYbG4dRQ5wOs+FBm0PAHcQgK64AFYhobG4w8VZBLxCXdwndLM="}

Program.cs

var builder = WebApplication.CreateBuilder(args);

// Add services to the container.
builder.Services.Configure<ConfigInformation>(builder.Configuration.GetSection("ConfigInformation"));
builder.Services.AddTransient<HttpHelperService>();
builder.Services.AddControllers();

#region HS256

builder.Services.AddScoped<IJWTService, JWTHSService>();
//builder.Services.Configure<JWTTokenOptions>(builder.Configuration.GetSection("JWTTokenOptions"));

#endregion HS256

#region RS256

//builder.Services.AddScoped<IJWTService, JWTRSService>();
//builder.Services.Configure<JWTTokenOptions>(builder.Configuration.GetSection("JWTTokenOptions"));

#endregion RS256

// Learn more about configuring Swagger/OpenAPI at https://aka.ms/aspnetcore/swashbuckle
builder.Services.AddEndpointsApiExplorer();
builder.Services.AddSwaggerGen();
builder.Services.AddCors(options =>
{
    options.AddPolicy("default", policy =>
    {
        policy.AllowAnyOrigin()
            .AllowAnyHeader()
            .AllowAnyMethod();
    });
});
var app = builder.Build();

// Configure the HTTP request pipeline.

app.UseSwagger();
app.UseSwaggerUI();

app.UseAuthorization();
app.UseCors("default");
app.MapControllers();

app.Run();

網關 Common.OcelotGateway

appsettings.json

{
  "Logging": {
    "LogLevel": {
      "Default": "Information",
      "Microsoft.AspNetCore": "Warning"
    }
  },
  "AllowedHosts": "*",
  "JWTTokenOptions": {
    "Audience": "http://localhost:8761",
    "Issuer": "http://localhost:8761",
    "SecurityKey": "MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDI2a2EJ7m872v0afyoSDJT2o1+SitIeJSWtLJU8/Wz2m7gStexajkeD+Lka6DSTy8gt9UwfgVQo6uKjVLG5Ex7PiGOODVqAEghBuS7JzIYU5RvI543nNDAPfnJsas96mSA7L/mD7RTE2drj6hf3oZjJpMPZUQI/B1Qjb5H3K3PNwIDAQAB"
  }
}

OcelotConfiguration.json

{
  "Routes": [    
    {
      "UpstreamPathTemplate": "/api/lessonapi/{url}",
      "UpstreamHttpMethod": [
        "Get",
        "Post",
        "Put",
        "Patch",
        "Delete",
        "Options"
      ],
      "UserServiceDIscovery": true,
      "ServiceName": "LessonCenter",
      "LoadBalancerOptions": {
        "Type": "RoundRobin"
      },
      "DownstreamPathTemplate": "/api/lessonapi/{url}",
      "DownstreamScheme": "http",
      "DownstreamHeaderTransform": {
        "Access-Control-Allow-Origin": "*",
        "Access-Control-Allow-Methods": "*",
        "Access-Control-Allow-Headers": "*"
      },
      "AuthenticationOptions": {
        "AuthenticationProviderKey": "UserGatewayKey",
        "AllowedScopes": []
      }
    },
    {
      "UpstreamPathTemplate": "/lesson/swagger/v1/swagger.json",
      "UpstreamHttpMethod": [
        "Get"
      ],
      "UseServiceDiscovery": true,
      "ServiceName": "LessonCenter",
      "LoadBalancerOptions": {
        "Type": "RoundRobin"
      },
      "DownstreamPathTemplate": "/swagger/v1/swagger.json",
      "DownstreamScheme": "http",
      "RateLimitOptions": {
        "ClientWhiteList": [
          "ajun816",
          "superhero"
        ],
        "EnableRateLimiting": true,
        "Period": "5m",
        "PeriodTimespan": 30,
        "Limit": 5
      }
    },
    {
      "UpstreamPathTemplate": "/api/userapi/{url}",
      "UpstreamHttpMethod": [
        "Get",
        "Post",
        "Put",
        "Patch",
        "Delete",
        "Options"
      ],
      "UserServiceDIscovery": true,
      "ServiceName": "UserCenter",
      "LoadBalancerOptions": {
        "Type": "RoundRobin"
      },
      "DownstreamPathTemplate": "/api/userapi/{url}",
      "DownstreamScheme": "http",
      "DownstreamHeaderTransform": {
        "Access-Control-Allow-Origin": "*",
        "Access-Control-Allow-Methods": "*",
        "Access-Control-Allow-Headers": "*"
      }
    },
    {
      "UpstreamPathTemplate": "/user/swagger/v1/swagger.json",
      "UpstreamHttpMethod": [
        "Get"
      ],
      "UseServiceDiscovery": true,
      "ServiceName": "UserCenter",
      "LoadBalancerOptions": {
        "Type": "RoundRobin"
      },
      "DownstreamPathTemplate": "/swagger/v1/swagger.json",
      "DownstreamScheme": "http",
      "RateLimitOptions": {
        "ClientWhiteList": [
          "ajun816",
          "superhero"
        ],
        "EnableRateLimiting": true,
        "Period": "5m",
        "PeriodTimespan": 30,
        "Limit": 5
      }
    },

  "GlobalConfiguration": {
    "BaseUrl": "http://127.0.0.1:8070", //網關對外地址
    "ServiceDiscoveryProvider": {
      "Host": "127.0.0.1",
      "Port": 8500,
      "Type": "Consul" //由Consul提供服務發現
    },
    "RateLimitOptions": {
      "QuotaExceededMessage": "Too many requests, maybe later? 11", // 當請求過載被截斷時返回的消息
      "HttpStatusCode": 666, // 當請求過載被截斷時返回的http status
      "ClientIdHeader": "client_id" // 用來識別客戶端的請求頭,默認是 ClientId
    }
  }
}

Program.cs

var builder = WebApplication.CreateBuilder(args);

// Add services to the container.

builder.Services.AddControllers();
// Learn more about configuring Swagger/OpenAPI at https://aka.ms/aspnetcore/swashbuckle
builder.Services.AddEndpointsApiExplorer();
builder.Services.AddSwaggerGen(c =>
{
    c.SwaggerDoc("v1", new OpenApiInfo { Title = "Common.OcelotGateway", Version = "v1" });
});

builder.Host.ConfigureAppConfiguration((hostingContext, config) =>
{
    config.AddJsonFile("OcelotConfiguration.json", optional: true, reloadOnChange: true);
});

#region JWT檢驗 HS

JWTTokenOptions tokenOptions = new JWTTokenOptions();
builder.Configuration.Bind("JWTTokenOptions", tokenOptions);
string authenticationProviderKey = "UserGatewayKey";

builder.Services.AddAuthentication(JwtBearerDefaults.AuthenticationScheme)//Bearer Scheme
       .AddJwtBearer(authenticationProviderKey, options =>
       {
           options.TokenValidationParameters = new TokenValidationParameters
           {
               //JWT有一些默認的屬性,就是給鑒權時就可以篩選了
               ValidateIssuer = true,//是否驗證Issuer
               ValidateAudience = true,//是否驗證Audience
               ValidateLifetime = true,//是否驗證失效時間---默認還添加了300s后才過期
               ClockSkew = TimeSpan.FromSeconds(0),//token過期后立馬過期
               ValidateIssuerSigningKey = true,//是否驗證SecurityKey
               ValidAudience = tokenOptions.Audience,//Audience,需要跟前面簽發jwt的設置一致
               ValidIssuer = tokenOptions.Issuer,//Issuer,這兩項和前面簽發jwt的設置一致
               IssuerSigningKey = new SymmetricSecurityKey(Encoding.UTF8.GetBytes(tokenOptions.SecurityKey)),//拿到SecurityKey
           };
       });

#endregion JWT檢驗 HS

builder.Services.AddOcelot()
                .AddConsul()
                .AddPolly();

var app = builder.Build();

// Configure the HTTP request pipeline.

app.UseSwagger();
app.UseSwaggerUI(c =>
{
    c.SwaggerEndpoint("/lesson/swagger/v1/swagger.json", "課程 API V1");
    c.SwaggerEndpoint("/user/swagger/v1/swagger.json", "用戶 API V1");
});

app.UseOcelot().Wait();

app.Run();

用戶微服務 UserMicroservice

Controllers文件夾

UserController.cs

[Route("api/userapi/[controller]")]
[ApiController]
public class UserController : ControllerBase
    {
        private readonly IUserService? _userService;

        public UserController(IUserService? userService)
        {
            _userService = userService;
        }

        [HttpGet("all")]
        public HttpJsonResponse GetAll()
        {
            try
            {
                var data = _userService?.GetAll<SysUser>();
                return HttpJsonResponse.SuccessResult(data);
            }
            catch
            {
                return HttpJsonResponse.FailedResult();
            }
        }

        [Route("validate")]
        [HttpGet]
        public HttpJsonResponse ValidateUser(string username, string password)
        {
            try
            {
                var accountInfo = _userService?.ValidateUser(username, password);
                return HttpJsonResponse.SuccessResult(accountInfo);
            }
            catch (Exception ex)
            {
                return HttpJsonResponse.FailedResult(ex.Message);
            }
        }

        [HttpPost("regist")]
        public HttpJsonResponse CreateUser(RegisterModel registerModel)
        {
            try
            {
                var accountInfo = _userService?.CreateUser(registerModel);
                return HttpJsonResponse.SuccessResult(accountInfo);
            }
            catch (Exception ex)
            {
                return HttpJsonResponse.FailedResult(ex.Message);
            }
        }

        [HttpPut("update")]
        public HttpJsonResponse UpdateUser(RegisterModel registerModel)
        {
            try
            {
                var accountInfo = _userService?.UpdateUser(registerModel);
                return HttpJsonResponse.SuccessResult(accountInfo);
            }
            catch (Exception ex)
            {
                return HttpJsonResponse.FailedResult(ex.Message);
            }
        }

        [HttpDelete("delete/{id}")]
        public HttpJsonResponse DeleteUser([FromRoute] long id)
        {
            bool success = _userService?.Delete<SysUser>(id) ?? false;
            return success ? HttpJsonResponse.SuccessResult("刪除成功") :
                HttpJsonResponse.FailedResult("刪除失敗");
        }
    }

appsettings.json

{
  "Logging": {
    "LogLevel": {
      "Default": "Information",
      "Microsoft.AspNetCore": "Warning"
    }
  },
  "AllowedHosts": "*",
  "ConnectionStrings": {
    "MySqlConn": "Server=111.44.222.111;Database=db_user;Uid=root;Pwd=111111;SslMode=none;"
  },
  "CodeFirstSettings": {
    "Migrate": "true", //是否開啟同步(是否進行codefirst創建表)
    "Backup": "true", //是否進行備份
    "ModelPath": "UserModel" //要進行同步的Model程序集路徑
  },
  "SqlSugarSnowFlakeSettings": {
    "WorkerId": "1"
  },
  "ConsulClientOption": {
    "IP": "111.44.222.111",
    "Port": "18500",
    "Datacenter": "dc1"
  },
  "ConsulRegisterOption": {
    "IP": "111.44.222.111",
    "Port": "8761",
    "GroupName": "UserCenter",
    "HealthCheckUrl": "http://111.44.222.111:8761/Health",
    "Interval": 10,
    "Timeout": 5,
    "DergisterCriticalServiceAfter": 20,
    "Tag": "13"
  }
}

Program.cs

var builder = WebApplication.CreateBuilder(args);

// 配置牛頓庫,讓json解析的時候使用我們自定義的解析器 這個解析器不會造成long類型數據的精度損失
builder.Services.AddControllers().AddNewtonsoftJson(options =>
{
    options.SerializerSettings.DateFormatString = "yyyy'-'MM'-'dd' 'HH':'mm':'ss";
    options.SerializerSettings.ContractResolver = new CustomerJsonResolver();
});

// Learn more about configuring Swagger/OpenAPI at https://aka.ms/aspnetcore/swashbuckle
builder.Services.AddEndpointsApiExplorer();
builder.Services.AddSwaggerGen();

// SqlSugar配置
builder.Services.AddSqlSugarSetup(builder.Configuration);
// SqlSugar的雪花ID配置
builder.Services.AddSqlSugarSonwFlakeSetup(builder.Configuration);
// SqlSugarCodeFirst設置
builder.Services.AddCodeFirstSetup(builder.Configuration, typeof(BaseModel));

builder.Services.AddTransient<IUserService, UserService>();

var app = builder.Build();

// Configure the HTTP request pipeline.
app.UseSwagger();
app.UseSwaggerUI(c => c.SwaggerEndpoint("/swagger/v1/swagger.json", "UserMicroservice V1"));

app.UseAuthorization();

app.UsePerOptionsRequest();

app.UseHealthCheckMiddleware();

app.MapControllers();

app.UseConsulConfiguration(builder.Configuration).Wait();

app.Run();

課程微服務 LessonMicroservice

Controllers文件夾

LessonController.cs

[Route("api/lessonapi/[controller]")]
[ApiController]
public class LessonController : ControllerBase
    {
        #region 服務注入

        private readonly ILessonService? _lessonService;

        public LessonController(ILessonService? lessonService)
        {
            _lessonService = lessonService;
        }

        #endregion 服務注入

        /// <summary>
        /// 分頁獲取數據
        /// </summary>
        /// <param name="pageIndex"></param>
        /// <param name="pageSize"></param>
        /// <returns></returns>
        [HttpGet("page")]
        public HttpJsonResponse GetPaged(int pageIndex = 1, int pageSize = 10)
        {
            var data = _lessonService?.GetLessons(pageIndex, pageSize, l => l.CreateTime);
            return HttpJsonResponse.SuccessResult(data);
        }

        /// <summary>
        /// 創建課程
        /// </summary>
        /// <param name="lesson"></param>
        /// <returns></returns>
        [HttpPost("create")]
        [Authorize(Roles = "0")]
        public HttpJsonResponse Create(Lesson lesson)
        {
            var data = _lessonService?.CreateLesson(lesson);
            return HttpJsonResponse.SuccessResult(data);
        }

        /// <summary>
        /// 按條件篩選數據
        /// </summary>
        /// <param name="filter"></param>
        /// <returns></returns>
        [HttpPost("filter")]
        public HttpJsonResponse GetPagedByFilter([FromBody] LessonFilter filter)
        {
            var data = _lessonService?.PagedLessonsByFilter(filter.GetFilterExpression(),
                filter.CategoryId, filter.PageIndex, filter.PageSize);
            return HttpJsonResponse.SuccessResult(data);
        }

        /// <summary>
        /// 按照Id刪除數據
        /// </summary>
        /// <param name="id"></param>
        /// <returns></returns>
        [HttpDelete("delete/{id}")]
        [Authorize(Roles = "0")]
        public HttpJsonResponse DeleteById([FromRoute] long id)
        {
            bool success = _lessonService?.DeleteLessonById(id) ?? false;
            return success ?
                HttpJsonResponse.SuccessResult(success) :
                HttpJsonResponse.FailedResult("刪除課程失敗!");
        }

        /// <summary>
        /// 更新數據
        /// </summary>
        /// <param name="lesson"></param>
        /// <returns></returns>
        [HttpPut("update")]
        [Authorize(Roles = "0")]
        public HttpJsonResponse Update(Lesson lesson)
        {
            var data = _lessonService?.Update<Lesson>(lesson);
            return HttpJsonResponse.SuccessResult(data);
        }
    }

appsettings.json

{
  "Logging": {
    "LogLevel": {
      "Default": "Information",
      "Microsoft.AspNetCore": "Warning"
    }
  },
  "AllowedHosts": "*",
  "ConnectionStrings": {
    "MySqlConn": "Server=111.44.222.111;Database=db_Lesson;Uid=root;Pwd=111111;SslMode=none;"
  },
  "CodeFirstSettings": {
    "Migrate": "true", //是否開啟同步(是否進行codefirst創建表)
    "Backup": "true", //是否進行備份
    "ModelPath": "LessonModel" //要進行同步的Model程序集路徑
  },
  "SqlSugarSnowFlakeSettings": {
    "WorkerId": "1"
  },
  "JWTTokenOptions": {
    "Audience": "http://localhost:8761",
    "Issuer": "http://localhost:8761",
    "SecurityKey": "MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDI2a2EJ7m872v0afyoSDJT2o1+SitIeJSWtLJU8/Wz2m7gStexajkeD+Lka6DSTy8gt9UwfgVQo6uKjVLG5Ex7PiGOODVqAEghBuS7JzIYU5RvI543nNDAPfnJsas96mSA7L/mD7RTE2drj6hf3oZjJpMPZUQI/B1Qjb5H3K3PNwIDAQAB"
  },
  //"ConsulClientOption": {
  //  "IP": "111.44.222.111",
  //  "Port": "18500",
  //  "Datacenter": "dc1"
  //},
  //"ConsulRegisterOption": {
  //  "IP": "111.44.222.111",
  //  "Port": "8761",
  //  "GroupName": "LessonCenter",
  //  "HealthCheckUrl": "http://111.44.222.111:8761/Health",
  //  "Interval": 10,
  //  "Timeout": 5,
  //  "DergisterCriticalServiceAfter": 20,
  //  "Tag": "13"
  //},

  //本地測試ConsulClientOption

  "ConsulClientOption": {
    "IP": "localhost",
    "Port": "8500",
    "Datacenter": "dc1"
  },
  "ConsulRegisterOption": {
    "IP": "localhost",
    "Port": "8761",
    "GroupName": "LessonCenter",
    "HealthCheckUrl": "http://localhost:8761/Health",
    "Interval": 10,
    "Timeout": 5,
    "DergisterCriticalServiceAfter": 20,
    "Tag": "13"
  }
}

Program.cs

var builder = WebApplication.CreateBuilder(args);

// Add services to the container.
// 配置牛頓庫,讓json解析的時候使用我們自定義的解析器 這個解析器不會造成long類型數據的精度損失
builder.Services.AddControllers().AddNewtonsoftJson(options =>
{
    options.SerializerSettings.DateFormatString = "yyyy'-'MM'-'dd' 'HH':'mm':'ss";
    options.SerializerSettings.ContractResolver = new CustomerJsonResolver();
});

// Learn more about configuring Swagger/OpenAPI at https://aka.ms/aspnetcore/swashbuckle
builder.Services.AddEndpointsApiExplorer();
builder.Services.AddSwaggerGen();

// SqlSugar設置
builder.Services.AddSqlSugarSetup(builder.Configuration);
// SqlSugar CodeFirst設置
builder.Services.AddCodeFirstSetup(builder.Configuration, typeof(BaseModel));
// SqlSugar 雪花ID設置
builder.Services.AddSqlSugarSonwFlakeSetup(builder.Configuration);

// 服務注入
builder.Services.AddTransient<ILessonService, LessonService>();

#region jwt校驗  HS

JWTTokenOptions tokenOptions = new JWTTokenOptions();
builder.Configuration.Bind("JWTTokenOptions", tokenOptions);

builder.Services
.AddAuthentication(JwtBearerDefaults.AuthenticationScheme)//Bearer Scheme
.AddJwtBearer(options =>
{
    options.TokenValidationParameters = new TokenValidationParameters
    {
        //JWT有一些默認的屬性,就是給鑒權時就可以篩選了
        ValidateIssuer = true,//是否驗證Issuer
        ValidateAudience = true,//是否驗證Audience
        ValidateLifetime = true,//是否驗證失效時間---默認還添加了300s后才過期
        ClockSkew = TimeSpan.FromSeconds(0),//token過期后立馬過期
        ValidateIssuerSigningKey = true,//是否驗證SecurityKey

        ValidAudience = tokenOptions.Audience,//Audience,需要跟前面簽發jwt的設置一致
        ValidIssuer = tokenOptions.Issuer,//Issuer,這兩項和前面簽發jwt的設置一致
        IssuerSigningKey = new SymmetricSecurityKey(Encoding.UTF8.GetBytes(tokenOptions.SecurityKey)),//拿到SecurityKey
    };
});

#endregion jwt校驗  HS

var app = builder.Build();

// Configure the HTTP request pipeline.

app.UseSwagger();
app.UseSwaggerUI(c => c.SwaggerEndpoint("/swagger/v1/swagger.json", "CommentMicroService V1"));

app.UsePerOptionsRequest();

app.UseHealthCheckMiddleware();

app.UseAuthentication();
app.UseAuthorization();

app.MapControllers();

app.UseConsulConfiguration(builder.Configuration).Wait();

app.Run();


免責聲明!

本站轉載的文章為個人學習借鑒使用,本站對版權不負任何法律責任。如果侵犯了您的隱私權益,請聯系本站郵箱yoyou2525@163.com刪除。



 
粵ICP備18138465號   © 2018-2025 CODEPRJ.COM