Fre*_*rik 8 .net asp.net jwt asp.net-core
我是相当新的JwtSecurityTokens,我试着去了解它,并furhtermore整个不同的方面claimsidentity和claimprincipal,但这是另一个故事。
我尝试使用以下代码在C#中生成令牌:
private const string SECRET_KEY = "abcdef";
private static readonly SymmetricSecurityKey SIGNING_KEY = new SymmetricSecurityKey(Encoding.UTF8.GetBytes(SECRET_KEY));
public static string GenerateToken(string someName)
{
var token = new JwtSecurityToken(
claims: new Claim[]
{
new Claim(ClaimTypes.Name, someName),
},
notBefore: new DateTimeOffset(DateTime.Now).DateTime,
expires: new DateTimeOffset(DateTime.Now.AddMinutes(60)).DateTime,
signingCredentials: new SigningCredentials(SIGNING_KEY, SecurityAlgorithms.HmacSha256)
);
return new JwtSecurityTokenHandler().WriteToken(token);
}
Run Code Online (Sandbox Code Playgroud)
我遵循了有关YouTube的教程,但是不确定我是否了解JwtSecurityToken中的不同部分。另外,当我通过控制器执行代码以尝试返回令牌时,它返回一个错误,提示:“ IDX10603:解密失败。尝试的密钥:'[PII被隐藏]'”。
任何帮助表示赞赏。
Cha*_*era 11
您应该为您的密钥添加足够的字符。当你在这里设置你的密钥时,
//your SECRET_KEY = "abcdef"
new SymmetricSecurityKey(Encoding.UTF8.GetBytes(SECRET_KEY));
Run Code Online (Sandbox Code Playgroud)
将其更改为
new SymmetricSecurityKey(Encoding.UTF8.GetBytes("somethingyouwantwhichissecurewillworkk"));
Run Code Online (Sandbox Code Playgroud)
这应该有效。
算法HS256要求SecurityKey.KeySize大于128位,并且密钥只有48位。通过添加至少10个符号来扩展它。至于“ PII隐藏”部分,这是GDPR合规性工作的一部分,以隐藏日志中的任何堆栈或变量信息。您应该通过以下方式启用其他详细信息:
IdentityModelEventSource.ShowPII = true;
Run Code Online (Sandbox Code Playgroud)
| 归档时间: |
|
| 查看次数: |
2253 次 |
| 最近记录: |