【问题标题】:Thinktecture Identity server v3 - Facebook Assertion FlowThinktecture Identity server v3 - Facebook 断言流程
【发布时间】:2015-02-12 16:46:22
【问题描述】:

是否可以在 Thinktecture Identity Server v3 中使用 Facebook 配置 OAuth2 AssertionFlow?

leastprivilege.com 上有一篇关于为 Microsoft OAuth 和 AuthorizationServer 实现 AssertionFlow 的帖子,但我需要与 Facebook 集成,此外,AuthorizationServer 被标记为已弃用,不再维护。

【问题讨论】:

    标签: oauth-2.0 facebook-authentication thinktecture-ident-server


    【解决方案1】:

    IdentityServer v3 还支持断言流。示例 wiki 上有两个示例(称为“自定义授权”):

    https://github.com/thinktecture/Thinktecture.IdentityServer.v3.Samples/tree/master/source

    【讨论】:

    • 不幸的是,我仍然不知道如何使它与 FB 一起使用。我在本机客户端有 fb 用户访问令牌,但我不知道如何处理它。我可以使用自定义流程将其发送到 IdentityServer,但下一步是什么?我可以在 IdentityServer 中用它做什么? Facebook 目前是否支持断言流?
    • 您需要验证 idsrv 中的 FB 令牌 - 并实质上将其转换为代表系统中用户的声明主体。
    • 在 idsrv 端拥有 facebook 访问令牌,我检查其有效性(使用 fb api)并获取 fb userId。然后我可以对照我的数据库检查它,生成我自己的访问令牌并将其发送给客户端。感谢您的帮助!
    • @moody19871987 你有任何代码可以分享吗?我面临着和你一样的挑战。您可以发布您的 ICustomGrantValidator 实现吗?
    【解决方案2】:

    为了回应@NathanAldenSr 的评论,我发布了一些我的工作解决方案的代码。

    服务器端 - 自定义验证器:

        public class FacebookCustomGrantValidator: ICustomGrantValidator
        {
            private readonly IUserService userService;
            private const string _FACEBOOK_PROVIDER_NAME = "facebook";
            // ...
    
            async Task<CustomGrantValidationResult>  ICustomGrantValidator.ValidateAsync(ValidatedTokenRequest request)
            {
                // check assetion type (you can have more than one in your app)
                if (request.GrantType != "assertion_fb")
                    return await Task.FromResult<CustomGrantValidationResult>(null);
    
                // I assume that fb access token has been sent as a response form value (with 'assertion' key)
                var fbAccessToken = request.Raw.Get("assertion");
                if (string.IsNullOrWhiteSpace(assertion))
                    return await Task.FromResult<CustomGrantValidationResult>(new CustomGrantValidationResult
                    {
                        ErrorMessage = "Missing assertion."
                    });
    
                AuthenticateResult authebticationResult = null;
    
                // if fb access token is invalid you won't be able to create Facebook client 
                var client = new Facebook.FacebookClient(fbAccessToken);
                dynamic response = client.Get("me", new { fields = "email, first_name, last_name" });
    
                // create idsrv identity for the user
                authebticationResult = await userService.AuthenticateExternalAsync(new ExternalIdentity()
                {
                    Provider = _FACEBOOK_PROVIDER_NAME,
                    ProviderId = response.id,
                    Claims = new List<Claim>
                    {
                        new Claim("Email", response.email),
                        new Claim("FirstName", response.first_name),
                        new Claim("LastName", response.last_name)
                        // ... and so on...
                    }
                },
                new SignInMessage());
    
                return new CustomGrantValidationResult
                {
                    Principal = authebticationResult.User
                };
            }
        }
    

    您可以使用 Thinktecture 提供的 OAuth2Client 轻松测试它(在 Thinktexture.IdentityModel Client Library nuget 包中)。

    string fbAccessToken = "facebook_access_token_you_aquired_while_logging_in";
    string assertionType = "assertion_fb";
    
    var client = new OAuth2Client(
                       new Uri("your_auth_server_url"),
                       "idsrv_client_id",
                       "idsrv_client_secret");
    
    string idsrvAccessToken = client.RequestAssertionAsync(assetionType, fbAccessToken,).Result;
    

    【讨论】:

      猜你喜欢
      • 1970-01-01
      • 2015-04-08
      • 1970-01-01
      • 1970-01-01
      • 2015-05-29
      • 1970-01-01
      • 2013-12-13
      • 2014-05-28
      • 1970-01-01
      相关资源
      最近更新 更多