【问题标题】:How to generate signature for Oauth1.0 for here api c#如何为此处的 api c# 生成 Oauth1.0 的签名
【发布时间】:2021-07-12 19:19:41
【问题描述】:

我想将不记名令牌的访问令牌请求发送到此处的 api。(https://developer.here.com/tutorials/how-to-authenticate-with-here-oauth/) 他们展示了使用节点的示例。但我在 c# 中尝试了同样的方法。但我收到了 400 个错误请求。我的代码如下:

var url = "https://account.api.here.com/oauth2/token";

            String id = "key id";
            String secret = "key secret";

            var httpWebRequest = (HttpWebRequest)WebRequest.Create(url);
            httpWebRequest.Method = "POST";

            var timeStamp = ((int)(DateTime.UtcNow - new DateTime(1970, 1, 1)).TotalSeconds).ToString();
            var nonce = Convert.ToBase64String(Encoding.UTF8.GetBytes(timeStamp));

            var signatureBaseString = Escape(httpWebRequest.Method.ToUpper()) + "&";
            signatureBaseString += url.ToLower() + "&";
            signatureBaseString +=
                "oauth_consumer_key=" + id + "&" +
                "oauth_nonce=" + nonce + "&" +
                "oauth_signature_method=" + "HMAC-SHA1" + "&" +
                "oauth_timestamp=" + timeStamp + "&" +
                "oauth_version=" + "1.0";

            var key = secret;

            var signatureEncoding = new ASCIIEncoding();
            var keyBytes = signatureEncoding.GetBytes(key);
            var signatureBaseBytes = signatureEncoding.GetBytes(signatureBaseString);
            string signatureString;
            using (var hmacsha1 = new HMACSHA1(keyBytes))
            {
                var hashBytes = hmacsha1.ComputeHash(signatureBaseBytes);
                signatureString = Convert.ToBase64String(hashBytes);
            }
            string SimpleQuote(string s) => '"' + s + '"';

            var header =
            "Content-Type=application/x-www-form-urlencoded" + "," +
            "Authorization=OAuth" + "," +
            "oauth_consumer_key=" + SimpleQuote(id) + "," +
            "oauth_nonce=" + SimpleQuote(nonce) + "," +
            "oauth_signature_method=" + SimpleQuote("HMAC-SHA1") + "," +
            "oauth_timestamp=" + SimpleQuote(timeStamp) + "," +
            "oauth_version=" + SimpleQuote("1.0") + "," +
            "oauth_signature= " + SimpleQuote(signatureString);

            httpWebRequest.Headers.Add(HttpRequestHeader.Authorization, header);

            string postData = "grant_type=client_credentials";
            ASCIIEncoding encoding = new ASCIIEncoding();
            byte[] byte1 = encoding.GetBytes(postData);

            httpWebRequest.ContentLength = byte1.Length;

            var newStream = httpWebRequest.GetRequestStream(); // get a ref to the request body so it can be modified
            newStream.Write(byte1, 0, byte1.Length);
            newStream.Close();

            var response = httpWebRequest.GetResponse();

可能是我以错误的方式生成签名。但我只有密钥 id 和秘密,我设法实现了这一点。请帮我指出我犯的错误。

【问题讨论】:

    标签: c# asp.net authentication here-api oauth-1.0a


    【解决方案1】:

    请看下面的文章好吗? Getting (401) UnAuthorized error on some requests not all, but most 尝试使用不同的库,例如 HttpClient 或 RestClient。

    【讨论】:

      猜你喜欢
      • 1970-01-01
      • 2012-09-10
      • 1970-01-01
      • 2014-04-06
      • 2019-11-30
      • 2011-03-27
      • 1970-01-01
      • 1970-01-01
      • 2016-06-01
      相关资源
      最近更新 更多