【发布时间】:2020-11-29 23:01:10
【问题描述】:
我正在使用 Azure 函数将新开发堆栈上的 dontcore Web API 转换为无服务器。
我认为我的应用程序应该使用 Identity 来存储用户凭据和其他详细信息。他应该通过身份数据库进行身份验证并使用 JWT 令牌生成。
我正在尝试获取一些示例,这些示例可能有助于了解如何在 Azure 函数中实现 JWT。
JWT 令牌生成过程
public UserResponce AuthendicateUser(string username, string password)
{
bool valid_user= ValidateUser(username,password);
if (vlaid_user)
{
// authentication successful so generate jwt token
var tokenHandler = new JwtSecurityTokenHandler();
var key = Encoding.ASCII.GetBytes(_jwtIssuerOptions.Value.JwtKey);
var tokenDescriptor = new SecurityTokenDescriptor
{
Subject = new ClaimsIdentity(new Claim[]
{
new Claim(ClaimTypes.Name, "1"),
new Claim(ClaimTypes.GivenName, username),
new Claim(ClaimTypes.Role, UserRoleEnum.superadmin.ToString()),
new Claim("hospitalid", "1")
}),
Expires = DateTime.UtcNow.AddMinutes(_jwtIssuerOptions.Value.JwtExpireMinutes),
IssuedAt = DateTime.UtcNow,
NotBefore = DateTime.UtcNow,
Audience = _jwtIssuerOptions.Value.JwtAuidence,
Issuer = _jwtIssuerOptions.Value.JwtIssuer,
SigningCredentials = new SigningCredentials(new SymmetricSecurityKey(key), SecurityAlgorithms.HmacSha256Signature)
};
var token = tokenHandler.CreateToken(tokenDescriptor);
string newJwttoken = tokenHandler.WriteToken(token);
return new UserResponce
{
//HospitalId = user.HospitalId.Value,
Token = newJwttoken,
UserId = 1,
UserName = username,
Expires = DateTime.UtcNow.AddMinutes(_jwtIssuerOptions.Value.JwtExpireMinutes),
};
}
else
{
return null;
}
}
使用像 Bellow 代码这样的函数,其中用户、身份值获取 Nulls
var user = req.HttpContext.User;
var identity = claimsPrincipal.Identity;
功能代码
[FunctionName("Get_User")]
public async Task<IActionResult> GetUser(
[HttpTrigger(AuthorizationLevel.Anonymous, "get", Route = Globals.UserRoute+"/getuser")] HttpRequest req, ILogger log, ClaimsPrincipal claimsPrincipal)
{
log.LogInformation("C# HTTP trigger function processed a request started");
string requestBody = await new StreamReader(req.Body).ReadToEndAsync();
AuthendicateModel data = JsonConvert.DeserializeObject<AuthendicateModel>(requestBody);
var user = req.HttpContext.User;
var identity = claimsPrincipal.Identity;
var details = _userService.Username();
log.LogInformation("C# HTTP trigger function processed a request.");
return new OkObjectResult(new ApiResponse(HttpStatusCode.OK, details, ResponseMessageEnum.Success.ToString()));
}
【问题讨论】:
-
您还有其他顾虑吗?如果您没有其他顾虑,您能否接受它作为答案(meta.stackexchange.com/questions/5234/…)?
标签: azure .net-core jwt azure-functions claims-based-identity