TokenHelper.cs 7.4 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177
  1. using Microsoft.Extensions.Options;
  2. using Microsoft.IdentityModel.Tokens;
  3. using Newtonsoft.Json;
  4. using System;
  5. using System.Collections.Generic;
  6. using System.IdentityModel.Tokens.Jwt;
  7. using System.Linq;
  8. using System.Security.Claims;
  9. using System.Security.Cryptography;
  10. using System.Text;
  11. using System.Threading.Tasks;
  12. namespace WebAPIBase.Utils.Jwt
  13. {
  14. /// <summary>
  15. /// Token生成类
  16. /// </summary>
  17. public class TokenHelper : ITokenHelper
  18. {
  19. private readonly IOptions<JWTConfig> _options;
  20. public TokenHelper(IOptions<JWTConfig> options)
  21. {
  22. _options = options;
  23. }
  24. /// <summary>
  25. /// 根据一个对象通过反射提供负载生成token
  26. /// </summary>
  27. /// <typeparam name="T"></typeparam>
  28. /// <param name="user"></param>
  29. /// <returns></returns>
  30. public TnToken CreateToken<T>(T user) where T : class
  31. {
  32. //携带的负载部分,类似一个键值对
  33. List<Claim> claims = new List<Claim>();
  34. //这里我们用反射把model数据提供给它
  35. foreach (var item in user.GetType().GetProperties())
  36. {
  37. object obj = item.GetValue(user);
  38. string value = "";
  39. if (obj != null)
  40. value = obj.ToString();
  41. claims.Add(new Claim(item.Name, value));
  42. }
  43. //创建token
  44. return CreateTokenString(claims);
  45. }
  46. /// <summary>
  47. /// 根据键值对提供负载生成token
  48. /// </summary>
  49. /// <param name="keyValuePairs"></param>
  50. /// <returns></returns>
  51. public TnToken CreateToken(Dictionary<string, string> keyValuePairs)
  52. {
  53. //携带的负载部分,类似一个键值对
  54. List<Claim> claims = new List<Claim>();
  55. //这里我们通过键值对把数据提供给它
  56. foreach (var item in keyValuePairs)
  57. {
  58. claims.Add(new Claim(item.Key, item.Value));
  59. }
  60. //创建token
  61. return CreateTokenString(claims);
  62. }
  63. /// <summary>
  64. /// 生成token
  65. /// </summary>
  66. /// <param name="claims">List的 Claim对象</param>
  67. /// <returns></returns>
  68. private TnToken CreateTokenString(List<Claim> claims)
  69. {
  70. var now = DateTime.Now;
  71. var expires = now.Add(TimeSpan.FromMinutes(_options.Value.AccessTokenExpiresMinutes));
  72. var token = new JwtSecurityToken(
  73. issuer: _options.Value.Issuer,//Token发布者
  74. audience: _options.Value.Audience,//Token接受者
  75. claims: claims,//携带的负载
  76. notBefore: now,//当前时间token生成时间
  77. expires: expires,//过期时间
  78. signingCredentials: new SigningCredentials(new SymmetricSecurityKey(Encoding.UTF8.GetBytes(_options.Value.IssuerSigningKey)), SecurityAlgorithms.HmacSha256));
  79. return new TnToken { TokenStr = new JwtSecurityTokenHandler().WriteToken(token), Expires = expires };
  80. }
  81. /// <summary>
  82. /// 验证身份 验证签名的有效性
  83. /// </summary>
  84. /// <param name="encodeJwt"></param>
  85. /// <param name="validatePayLoad">自定义各类验证; 是否包含那种申明,或者申明的值, </param>
  86. public bool ValiToken(string encodeJwt, Func<Dictionary<string, string>, bool> validatePayLoad = null)
  87. {
  88. var success = true;
  89. var jwtArr = encodeJwt.Split('.');
  90. if (jwtArr.Length < 3)//数据格式都不对直接pass
  91. {
  92. return false;
  93. }
  94. var header = JsonConvert.DeserializeObject<Dictionary<string, string>>(Base64UrlEncoder.Decode(jwtArr[0]));
  95. var payLoad = JsonConvert.DeserializeObject<Dictionary<string, string>>(Base64UrlEncoder.Decode(jwtArr[1]));
  96. //配置文件中取出来的签名秘钥
  97. var hs256 = new HMACSHA256(Encoding.ASCII.GetBytes(_options.Value.IssuerSigningKey));
  98. //验证签名是否正确(把用户传递的签名部分取出来和服务器生成的签名匹配即可)
  99. success = success && string.Equals(jwtArr[2], Base64UrlEncoder.Encode(hs256.ComputeHash(Encoding.UTF8.GetBytes(string.Concat(jwtArr[0], ".", jwtArr[1])))));
  100. if (!success)
  101. {
  102. return success;//签名不正确直接返回
  103. }
  104. //其次验证是否在有效期内(也应该必须)
  105. var now = ToUnixEpochDate(DateTime.UtcNow);
  106. success = success && (now >= long.Parse(payLoad["nbf"].ToString()) && now < long.Parse(payLoad["exp"].ToString()));
  107. //不需要自定义验证不传或者传递null即可
  108. if (validatePayLoad == null)
  109. return true;
  110. //再其次 进行自定义的验证
  111. success = success && validatePayLoad(payLoad);
  112. return success;
  113. }
  114. /// <summary>
  115. /// 时间转换
  116. /// </summary>
  117. /// <param name="date"></param>
  118. /// <returns></returns>
  119. private long ToUnixEpochDate(DateTime date)
  120. {
  121. return (long)Math.Round((date.ToUniversalTime() - new DateTimeOffset(1970, 1, 1, 0, 0, 0, TimeSpan.Zero)).TotalSeconds);
  122. }
  123. /// <summary>
  124. /// 校验token状态
  125. /// </summary>
  126. /// <param name="encodeJwt"></param>
  127. /// <param name="validatePayLoad"></param>
  128. /// <param name="action"></param>
  129. /// <returns></returns>
  130. public TokenType ValiTokenState(string encodeJwt, Func<Dictionary<string, string>, bool> validatePayLoad, Action<Dictionary<string, string>> action)
  131. {
  132. var jwtArr = encodeJwt.Split('.');
  133. if (jwtArr.Length < 3)//数据格式都不对直接pass
  134. {
  135. return TokenType.Fail;
  136. }
  137. var header = JsonConvert.DeserializeObject<Dictionary<string, string>>(Base64UrlEncoder.Decode(jwtArr[0]));
  138. var payLoad = JsonConvert.DeserializeObject<Dictionary<string, string>>(Base64UrlEncoder.Decode(jwtArr[1]));
  139. var hs256 = new HMACSHA256(Encoding.ASCII.GetBytes(_options.Value.IssuerSigningKey));
  140. //验证签名是否正确(把用户传递的签名部分取出来和服务器生成的签名匹配即可)
  141. if (!string.Equals(jwtArr[2], Base64UrlEncoder.Encode(hs256.ComputeHash(Encoding.UTF8.GetBytes(string.Concat(jwtArr[0], ".", jwtArr[1]))))))
  142. {
  143. return TokenType.Fail;
  144. }
  145. //其次验证是否在有效期内(必须验证)
  146. var now = ToUnixEpochDate(DateTime.UtcNow);
  147. if (!(now >= long.Parse(payLoad["nbf"].ToString()) && now < long.Parse(payLoad["exp"].ToString())))
  148. {
  149. return TokenType.Expired;
  150. }
  151. //不需要自定义验证不传或者传递null即可
  152. if (validatePayLoad == null)
  153. {
  154. action(payLoad);
  155. return TokenType.Ok;
  156. }
  157. //再其次 进行自定义的验证
  158. if (!validatePayLoad(payLoad))
  159. {
  160. return TokenType.Fail;
  161. }
  162. //可能需要获取jwt摘要里边的数据,封装一下方便使用
  163. action(payLoad);
  164. return TokenType.Ok;
  165. }
  166. }
  167. }