JwtSecurityToken的理解和异常

Fre*_*rik 8 .net asp.net jwt asp.net-core

我是相当新的JwtSecurityTokens,我试着去了解它,并furhtermore整个不同的方面claimsidentity和claimprincipal,但这是另一个故事。

我尝试使用以下代码在C#中生成令牌:

private const string SECRET_KEY = "abcdef";
private static readonly SymmetricSecurityKey SIGNING_KEY = new SymmetricSecurityKey(Encoding.UTF8.GetBytes(SECRET_KEY));

    public static string GenerateToken(string someName)
    {
        var token = new JwtSecurityToken(
            claims: new Claim[]
            {
                new Claim(ClaimTypes.Name, someName), 
            },
            notBefore: new DateTimeOffset(DateTime.Now).DateTime,
            expires: new DateTimeOffset(DateTime.Now.AddMinutes(60)).DateTime,
            signingCredentials: new SigningCredentials(SIGNING_KEY, SecurityAlgorithms.HmacSha256)
        );

        return new JwtSecurityTokenHandler().WriteToken(token);
    }
Run Code Online (Sandbox Code Playgroud)

我遵循了有关YouTube的教程,但是不确定我是否了解JwtSecurityToken中的不同部分。另外,当我通过控制器执行代码以尝试返回令牌时,它返回一个错误,提示:“ IDX10603:解密失败。尝试的密钥:'[PII被隐藏]'”。

任何帮助表示赞赏。

Cha*_*era 11

您应该为您的密钥添加足够的字符。当你在这里设置你的密钥时,

//your SECRET_KEY = "abcdef"
new SymmetricSecurityKey(Encoding.UTF8.GetBytes(SECRET_KEY));
Run Code Online (Sandbox Code Playgroud)

将其更改为

new SymmetricSecurityKey(Encoding.UTF8.GetBytes("somethingyouwantwhichissecurewillworkk"));
Run Code Online (Sandbox Code Playgroud)

这应该有效。


Ale*_*bov 8

算法HS256要求SecurityKey.KeySize大于128位,并且密钥只有48位。通过添加至少10个符号来扩展它。至于“ PII隐藏”部分,这是GDPR合规性工作的一部分,以隐藏日志中的任何堆栈或变量信息。您应该通过以下方式启用其他详细信息:

IdentityModelEventSource.ShowPII = true;
Run Code Online (Sandbox Code Playgroud)