TokenHelper.cs 8.0 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189
  1. using Microsoft.Extensions.Options;
  2. using Microsoft.IdentityModel.Tokens;
  3. using Newtonsoft.Json;
  4. using System;
  5. using System.Collections.Generic;
  6. using System.IdentityModel.Tokens.Jwt;
  7. using System.Linq;
  8. using System.Security.Claims;
  9. using System.Security.Cryptography;
  10. using System.Text;
  11. using System.Threading.Tasks;
  12. namespace Utils.Jwt
  13. {
  14. /// <summary>
  15. /// Token生成类
  16. /// </summary>
  17. public class TokenHelper : ITokenHelper
  18. {
  19. private readonly IOptions<JWTConfig> _options;
  20. private NLog.Logger logger;
  21. public TokenHelper(IOptions<JWTConfig> options)
  22. {
  23. _options = options;
  24. logger = NLog.Web.NLogBuilder.ConfigureNLog("nlog.config").GetCurrentClassLogger();
  25. }
  26. /// <summary>
  27. /// 根据一个对象通过反射提供负载生成token
  28. /// </summary>
  29. /// <typeparam name="T"></typeparam>
  30. /// <param name="user"></param>
  31. /// <returns></returns>
  32. public TnToken CreateToken<T>(T user) where T : class
  33. {
  34. //携带的负载部分,类似一个键值对
  35. List<Claim> claims = new List<Claim>();
  36. //这里我们用反射把model数据提供给它
  37. foreach (var item in user.GetType().GetProperties())
  38. {
  39. object obj = item.GetValue(user);
  40. string value = "";
  41. if (obj != null)
  42. value = obj.ToString();
  43. claims.Add(new Claim(item.Name, value));
  44. }
  45. //创建token
  46. return CreateTokenString(claims);
  47. }
  48. /// <summary>
  49. /// 根据键值对提供负载生成token
  50. /// </summary>
  51. /// <param name="keyValuePairs"></param>
  52. /// <returns></returns>
  53. public TnToken CreateToken(Dictionary<string, string> keyValuePairs)
  54. {
  55. //携带的负载部分,类似一个键值对
  56. List<Claim> claims = new List<Claim>();
  57. //这里我们通过键值对把数据提供给它
  58. foreach (var item in keyValuePairs)
  59. {
  60. claims.Add(new Claim(item.Key, item.Value));
  61. }
  62. //创建token
  63. return CreateTokenString(claims);
  64. }
  65. /// <summary>
  66. /// 生成token
  67. /// </summary>
  68. /// <param name="claims">List的 Claim对象</param>
  69. /// <returns></returns>
  70. private TnToken CreateTokenString(List<Claim> claims)
  71. {
  72. var now = DateTime.Now;
  73. var expires = now.Add(TimeSpan.FromMinutes(_options.Value.AccessTokenExpiresMinutes));
  74. var token = new JwtSecurityToken(
  75. issuer: _options.Value.Issuer,//Token发布者
  76. audience: _options.Value.Audience,//Token接受者
  77. claims: claims,//携带的负载
  78. notBefore: now,//当前时间token生成时间
  79. expires: expires,//过期时间
  80. signingCredentials: new SigningCredentials(new SymmetricSecurityKey(Encoding.UTF8.GetBytes(_options.Value.IssuerSigningKey)), SecurityAlgorithms.HmacSha256));
  81. return new TnToken { TokenStr = new JwtSecurityTokenHandler().WriteToken(token), Expires = expires };
  82. }
  83. /// <summary>
  84. /// 验证身份 验证签名的有效性
  85. /// </summary>
  86. /// <param name="encodeJwt"></param>
  87. /// <param name="validatePayLoad">自定义各类验证; 是否包含那种申明,或者申明的值, </param>
  88. public bool ValiToken(string encodeJwt, Func<Dictionary<string, string>, bool> validatePayLoad = null)
  89. {
  90. var success = true;
  91. var jwtArr = encodeJwt.Split('.');
  92. if (jwtArr.Length < 3)//数据格式都不对直接pass
  93. {
  94. return false;
  95. }
  96. var header = JsonConvert.DeserializeObject<Dictionary<string, string>>(Base64UrlEncoder.Decode(jwtArr[0]));
  97. //logger.Info($"header:{header}");
  98. var payLoad = JsonConvert.DeserializeObject<Dictionary<string, string>>(Base64UrlEncoder.Decode(jwtArr[1]));
  99. //logger.Info($"payLoad:{payLoad}");
  100. //配置文件中取出来的签名秘钥
  101. var hs256 = new HMACSHA256(Encoding.ASCII.GetBytes(_options.Value.IssuerSigningKey));
  102. //验证签名是否正确(把用户传递的签名部分取出来和服务器生成的签名匹配即可)
  103. success = success && string.Equals(jwtArr[2], Base64UrlEncoder.Encode(hs256.ComputeHash(Encoding.UTF8.GetBytes(string.Concat(jwtArr[0], ".", jwtArr[1])))));
  104. if (!success)
  105. {
  106. return success;//签名不正确直接返回
  107. }
  108. //其次验证是否在有效期内(也应该必须)
  109. var now = ToUnixEpochDate(DateTime.UtcNow);
  110. success = success && (now >= long.Parse(payLoad["nbf"].ToString()) && now < long.Parse(payLoad["exp"].ToString()));
  111. //不需要自定义验证不传或者传递null即可
  112. if (validatePayLoad == null)
  113. return true;
  114. //再其次 进行自定义的验证
  115. success = success && validatePayLoad(payLoad);
  116. return success;
  117. }
  118. /// <summary>
  119. /// 时间转换
  120. /// </summary>
  121. /// <param name="date"></param>
  122. /// <returns></returns>
  123. private long ToUnixEpochDate(DateTime date)
  124. {
  125. return (long)Math.Round((date.ToUniversalTime() - new DateTimeOffset(1970, 1, 1, 0, 0, 0, TimeSpan.Zero)).TotalSeconds);
  126. }
  127. /// <summary>
  128. /// 校验token状态
  129. /// </summary>
  130. /// <param name="encodeJwt"></param>
  131. /// <param name="validatePayLoad"></param>
  132. /// <param name="action"></param>
  133. /// <returns></returns>
  134. public TokenType ValiTokenState(string encodeJwt, Func<Dictionary<string, string>, bool> validatePayLoad, Action<Dictionary<string, string>> action)
  135. {
  136. var jwtArr = encodeJwt.Split('.');
  137. if (jwtArr.Length < 3)//数据格式都不对直接pass
  138. {
  139. return TokenType.Fail;
  140. }
  141. var header = JsonConvert.DeserializeObject<Dictionary<string, string>>(Base64UrlEncoder.Decode(jwtArr[0]));
  142. //logger.Info($"header:{Base64UrlEncoder.Decode(jwtArr[0])}");
  143. var payLoad = JsonConvert.DeserializeObject<Dictionary<string, string>>(Base64UrlEncoder.Decode(jwtArr[1]));
  144. //logger.Info($"payLoad:{Base64UrlEncoder.Decode(jwtArr[1])}");
  145. var hs256 = new HMACSHA256(Encoding.ASCII.GetBytes(_options.Value.IssuerSigningKey));
  146. //logger.Info($"jwtArr[2]:{jwtArr[2]}");
  147. var str = Base64UrlEncoder.Encode(hs256.ComputeHash(Encoding.UTF8.GetBytes(string.Concat(jwtArr[0], ".", jwtArr[1]))));
  148. //logger.Info($"str:{str}");
  149. //验证签名是否正确(把用户传递的签名部分取出来和服务器生成的签名匹配即可)
  150. if (!string.Equals(jwtArr[2], str))
  151. {
  152. //logger.Info($"TokenType:{TokenType.Fail}");
  153. return TokenType.Fail;
  154. }
  155. //其次验证是否在有效期内(必须验证)
  156. var now = ToUnixEpochDate(DateTime.UtcNow);
  157. if (!(now >= long.Parse(payLoad["nbf"].ToString()) && now < long.Parse(payLoad["exp"].ToString())))
  158. {
  159. return TokenType.Expired;
  160. }
  161. //不需要自定义验证不传或者传递null即可
  162. if (validatePayLoad == null)
  163. {
  164. action(payLoad);
  165. return TokenType.Ok;
  166. }
  167. //再其次 进行自定义的验证
  168. if (!validatePayLoad(payLoad))
  169. {
  170. //logger.Info($"validatePayLoad");
  171. return TokenType.Fail;
  172. }
  173. //可能需要获取jwt摘要里边的数据,封装一下方便使用
  174. action(payLoad);
  175. return TokenType.Ok;
  176. }
  177. }
  178. }