【发布时间】:2018-11-03 02:44:37
【问题描述】:
我正在尝试为我的应用程序实施服务集成身份验证 - 管理员同意。以下是我创建 jwt 的方式:
class Program
{
static void Main(string[] args)
{
#region Test
string integratorKey = "integratorKey ";
string userId = "userId ";
string serverAddress = "serverAddress";
string scope = "signature";
string key = @"C:\Users\Tester\Desktop\privatekey.txt";
// JWT Header
// The header specfies the token type and the signature algorithm
var jwtHeader = new JwtHeader
{
{ "typ ", "JWT "},
{ "alg", "RS256"},
};
// JWT Body
// The body specfies the account and user id granting consen
var jwtPayload = new JwtPayload
{
{ "iss ", integratorKey},
{ "sub", userId},
{ "iat", DateTimeOffset.UtcNow.ToUnixTimeSeconds()},
{ "exp", DateTimeOffset.UtcNow.AddHours(1).ToUnixTimeSeconds()},
{ "aud", serverAddress},
{ "scope", scope}
};
// JWT Signature
// The body contains the result of signing the base64url-encoded header and body
string pemKey = File.ReadAllText(key);
var rsa = CreateRSAKeyFromPem(pemKey);
RsaSecurityKey rsaKey = new RsaSecurityKey(rsa);
var jwtSecurityToken = new JwtSecurityToken(jwtHeader, jwtPayload);
jwtSecurityToken.SigningKey = rsaKey;
// Token to String so you can use it in your client
var jwtHandler = new JwtSecurityTokenHandler();
var tokenString = jwtHandler.WriteToken(jwtSecurityToken);
#endregion
}
public static RSA CreateRSAKeyFromPem(string key)
{
TextReader reader = new StringReader(key);
PemReader pemReader = new PemReader(reader);
object result = pemReader.ReadObject();
if (result is AsymmetricCipherKeyPair)
{
AsymmetricCipherKeyPair keyPair = (AsymmetricCipherKeyPair)result;
return DotNetUtilities.ToRSA((RsaPrivateCrtKeyParameters)keyPair.Private);
}
else if (result is RsaKeyParameters)
{
RsaKeyParameters keyParameters = (RsaKeyParameters)result;
return DotNetUtilities.ToRSA(keyParameters);
}
throw new Exception("Unepxected PEM type");
}
}
我已经在 jwt.io 上验证了此代码生成的令牌,一切看起来都不错。但是,当我尝试使用 Postman 将生成的 jwt 交换为访问代码时,我总是会得到“invalid_grant”,这是我在 postman 中提出请求的方式:
POST https://account-d.docusign.com/oauth/token
-Headers: Content-Type application/x-www-form-urlencoded
-Body: grant_type urn:ietf:params:oauth:grant-type:jwt-bearer assertion [Generated jwt]
我什至试过把
Headers: Authorization Basic b64encoded(integratorKey:secretKey)
也一样,但仍然没有运气。
你能指出我在这里做错了什么吗?谢谢:)
【问题讨论】:
标签: .net jwt docusignapi