|
1 |
| -using Microsoft.IdentityModel.Tokens; |
| 1 | +using Microsoft.Extensions.DependencyInjection; |
| 2 | +using Microsoft.IdentityModel.Tokens; |
| 3 | +using SenseNet.Configuration; |
2 | 4 | using System;
|
3 | 5 | using System.IdentityModel.Tokens.Jwt;
|
4 | 6 | using System.Net.Http;
|
5 | 7 | using System.Net.Http.Headers;
|
6 | 8 | using System.Security.Claims;
|
7 | 9 | using System.Threading.Tasks;
|
8 | 10 |
|
9 |
| -namespace SnWebApplication.Api.Sql.TokenAuth.TokenValidator |
10 |
| -{ |
11 |
| - public class SenseNetJwtSecurityTokenHandler : ISecurityTokenValidator |
| 11 | +namespace SenseNet.Services.Core.Authentication; |
| 12 | + |
| 13 | +public class SenseNetJwtSecurityTokenHandler : TokenHandler |
| 14 | +{ |
| 15 | + private readonly string _validateTokenUrl; |
| 16 | + private readonly JwtSecurityTokenHandler _defaultHandler; |
| 17 | + private readonly IHttpClientFactory _httpClientFactory; |
| 18 | + |
| 19 | + public SenseNetJwtSecurityTokenHandler(string validateTokenUrl) |
12 | 20 | {
|
13 |
| - private readonly string _validateTokenUrl; |
14 |
| - private readonly JwtSecurityTokenHandler _defaultHandler; |
| 21 | + _httpClientFactory = Providers.Instance.Services.GetRequiredService<IHttpClientFactory>(); |
| 22 | + _validateTokenUrl = validateTokenUrl ?? throw new ArgumentNullException(nameof(validateTokenUrl)); |
| 23 | + _defaultHandler = new JwtSecurityTokenHandler(); |
| 24 | + } |
15 | 25 |
|
16 |
| - public bool CanValidateToken => true; |
17 |
| - public int MaximumTokenSizeInBytes { get; set; } = TokenValidationParameters.DefaultMaximumTokenSizeInBytes; |
| 26 | + public override int MaximumTokenSizeInBytes |
| 27 | + { |
| 28 | + get => base.MaximumTokenSizeInBytes; |
| 29 | + set => base.MaximumTokenSizeInBytes = value; |
| 30 | + } |
18 | 31 |
|
19 |
| - public SenseNetJwtSecurityTokenHandler(string validateTokenUrl) |
20 |
| - { |
21 |
| - _validateTokenUrl = validateTokenUrl ?? throw new ArgumentNullException(nameof(validateTokenUrl)); |
22 |
| - _defaultHandler = new JwtSecurityTokenHandler(); |
23 |
| - } |
| 32 | + public override SecurityToken ReadToken(string token) |
| 33 | + { |
| 34 | + if (string.IsNullOrWhiteSpace(token)) |
| 35 | + throw new ArgumentNullException(nameof(token)); |
24 | 36 |
|
25 |
| - public bool CanReadToken(string securityToken) => |
26 |
| - _defaultHandler.CanReadToken(securityToken); |
| 37 | + return _defaultHandler.ReadJwtToken(token); |
| 38 | + } |
| 39 | + |
| 40 | + public override async Task<TokenValidationResult> ValidateTokenAsync(string token, TokenValidationParameters validationParameters) |
| 41 | + { |
| 42 | + await ValidateTokenAsync(token); |
27 | 43 |
|
28 |
| - private async Task ValidateTokenAsync(string token) |
| 44 | + try |
29 | 45 | {
|
30 |
| - if (string.IsNullOrWhiteSpace(token)) |
31 |
| - return; |
| 46 | + var jwtToken = ReadToken(token) as JwtSecurityToken; |
32 | 47 |
|
33 |
| - using var httpClient = new HttpClient(); |
| 48 | + return new TokenValidationResult |
| 49 | + { |
| 50 | + ClaimsIdentity = new ClaimsIdentity(jwtToken.Claims, "Custom"), |
| 51 | + SecurityToken = jwtToken, |
| 52 | + IsValid = true |
| 53 | + }; |
| 54 | + } |
| 55 | + catch (Exception ex) |
| 56 | + { |
| 57 | + return new TokenValidationResult |
| 58 | + { |
| 59 | + Exception = ex |
| 60 | + }; |
| 61 | + } |
| 62 | + } |
34 | 63 |
|
35 |
| - httpClient.DefaultRequestHeaders.Clear(); |
36 |
| - httpClient.DefaultRequestHeaders |
37 |
| - .Accept |
38 |
| - .Add(new MediaTypeWithQualityHeaderValue("application/json")); |
39 |
| - httpClient.DefaultRequestHeaders.Authorization = new AuthenticationHeaderValue("Bearer", token); |
| 64 | + public override async Task<TokenValidationResult> ValidateTokenAsync(SecurityToken token, TokenValidationParameters validationParameters) |
| 65 | + { |
| 66 | + ArgumentNullException.ThrowIfNull(token); |
40 | 67 |
|
41 |
| - var response = await httpClient.GetAsync(_validateTokenUrl); |
42 |
| - if (!response.IsSuccessStatusCode) |
43 |
| - throw new SecurityTokenValidationException("Invalid token."); |
| 68 | + var jwtToken = token as JwtSecurityToken ?? throw new ArgumentException("The token must be of type JwtSecurityToken."); |
44 | 69 |
|
45 |
| - var result = bool.Parse(await response.Content.ReadAsStringAsync()); |
46 |
| - if (!result) |
47 |
| - throw new SecurityTokenValidationException("Invalid token."); |
48 |
| - } |
| 70 | + await ValidateTokenAsync(jwtToken.RawData); |
49 | 71 |
|
50 |
| - public ClaimsPrincipal ValidateToken(string securityToken, TokenValidationParameters validationParameters, out SecurityToken validatedToken) |
| 72 | + return new TokenValidationResult |
51 | 73 | {
|
52 |
| - ValidateTokenAsync(securityToken).GetAwaiter().GetResult(); |
| 74 | + ClaimsIdentity = new ClaimsIdentity(jwtToken.Claims, "Custom"), |
| 75 | + SecurityToken = jwtToken, |
| 76 | + IsValid = true |
| 77 | + }; |
| 78 | + } |
53 | 79 |
|
54 |
| - var jwtToken = _defaultHandler.ReadJwtToken(securityToken); |
| 80 | + private async Task ValidateTokenAsync(string token) |
| 81 | + { |
| 82 | + if (string.IsNullOrWhiteSpace(token)) |
| 83 | + return; |
55 | 84 |
|
56 |
| - var identity = new ClaimsIdentity(jwtToken.Claims, "Custom"); |
57 |
| - var principal = new ClaimsPrincipal(identity); |
| 85 | + using var httpClient = _httpClientFactory.CreateClient(); |
58 | 86 |
|
59 |
| - validatedToken = jwtToken; |
| 87 | + httpClient.DefaultRequestHeaders.Clear(); |
| 88 | + httpClient.DefaultRequestHeaders |
| 89 | + .Accept |
| 90 | + .Add(new MediaTypeWithQualityHeaderValue("application/json")); |
| 91 | + httpClient.DefaultRequestHeaders.Authorization = new AuthenticationHeaderValue("Bearer", token); |
60 | 92 |
|
61 |
| - return principal; |
62 |
| - } |
| 93 | + var response = await httpClient.GetAsync(_validateTokenUrl); |
| 94 | + if (!response.IsSuccessStatusCode) |
| 95 | + throw new SecurityTokenValidationException("Invalid token."); |
| 96 | + |
| 97 | + var result = bool.Parse(await response.Content.ReadAsStringAsync()); |
| 98 | + if (!result) |
| 99 | + throw new SecurityTokenValidationException("Invalid token."); |
63 | 100 | }
|
64 | 101 | }
|
0 commit comments