【问题标题】:OWIN Authentication Server for multiple applications用于多个应用程序的 OWIN 身份验证服务器
【发布时间】:2015-08-29 16:32:41
【问题描述】:

我正在实施一个解决方案,它有一个 MVC 客户端(让我们在 localhost:4077/ 调用这个 CLIENT)和一个 WebAPI 服务(在 localhost:4078/ 调用 API)

我已经在 API 中实现了 OWIN OAuth,但想知道 OWIN 是否可以在单独的解决方案中实现(让我们在 localhost:4079/token 将其称为 AUTH)来为 CLIENT 生成令牌,然后 CLIENT 通过这个到 API(作为 Bearer 授权令牌)

我查询此问题的原因是客户端可能会访问其他 WebAPI 服务,并且我想在客户端和所有 API 服务之间使用 OWIN。

问题是我不确定 AUTH 服务生成的令牌是否可用于授权客户端和所有 API 服务上的所有请求。

有没有人实现过类似的东西,如果有,你能提供一个例子吗,我对 OWIN 和 OAUTH 很陌生,所以任何帮助都将不胜感激

【问题讨论】:

标签: asp.net-web-api oauth asp.net-mvc-5 owin


【解决方案1】:

将授权服务器与资源服务器分开非常简单:如果您使用 IIS 并且在两个应用程序/服务器上配置了相同的机器密钥,它甚至可以在没有任何额外代码的情况下工作。

如果您需要选择访问令牌可以访问哪些端点,则使用 OWIN OAuth2 服务器实现支持多个资源服务器会有点困难。如果您不关心这一点,只需使用相同的机器密钥配置所有资源服务器,您就可以使用相同的令牌访问所有 API。

要更好地控制可与访问令牌一起使用的端点,您应该查看AspNet.Security.OpenIdConnect.Server - OWIN/Katana 附带的 OAuth2 服务器的一个分支 - 它本机支持这种情况:@987654321 @。

设置起来相对容易:

在您的授权服务器应用程序中添加一个新的中间件颁发令牌(在Startup.cs 中):

app.UseOpenIdConnectServer(new OpenIdConnectServerOptions
{
    Provider = new AuthorizationProvider()
});

在不同的 API 服务器(Startup.cs)中添加新的中间件验证访问令牌:

app.UseJwtBearerAuthentication(new JwtBearerAuthenticationOptions
{
    // AllowedAudiences MUST contain the absolute URL of your API.
    AllowedAudiences = new[] { "http://localhost:11111/" },

    // X509CertificateSecurityTokenProvider MUST be initialized with an issuer corresponding to the absolute URL of the authorization server.
    IssuerSecurityTokenProviders = new[] { new X509CertificateSecurityTokenProvider("http://localhost:50000/", certificate) }
});

app.UseJwtBearerAuthentication(new JwtBearerAuthenticationOptions
{
    // AllowedAudiences MUST contain the absolute URL of your API.
    AllowedAudiences = new[] { "http://localhost:22222/" },

    // X509CertificateSecurityTokenProvider MUST be initialized with an issuer corresponding to the absolute URL of the authorization server.
    IssuerSecurityTokenProviders = new[] { new X509CertificateSecurityTokenProvider("http://localhost:50000/", certificate) }
});

最后,在您的客户端应用中添加一个新的 OpenID Connect 客户端中间件(Startup.cs):

app.UseOpenIdConnectAuthentication(new OpenIdConnectAuthenticationOptions
{
    // Some essential parameters have been omitted for brevity.
    // See https://github.com/aspnet-contrib/AspNet.Security.OpenIdConnect.Server/blob/dev/samples/Mvc/Mvc.Client/Startup.cs for more information

    // Authority MUST correspond to the absolute URL of the authorization server.
    Authority = "http://localhost:50000/",

    // Resource represents the different endpoints the
    // access token should be issued for (values must be space-delimited).
    // In this case, the access token will be requested for both APIs.
    Resource = "http://localhost:11111/ http://localhost:22222/",
});

您可以查看此示例以获取更多信息:https://github.com/aspnet-contrib/AspNet.Security.OpenIdConnect.Server/blob/dev/samples/Mvc/

它不使用多个资源服务器,但使用我提到的不同步骤来调整它应该不难。如果您需要帮助,请随时联系我。

【讨论】:

  • 谢谢,我试过了,效果很好,我还看到了 Taiseer Joudah (bitoftech.net/2014/09/24/…) 的一组文章,需要按照第 1 部分中的文章进行操作(我跳过了角度步骤对我来说是不相关的)并设法通过身份验证服务和两个 WebAPI 项目进行设置,该项目访问通过承载身份验证标头的安全控制器
  • 不错!出于好奇,您更喜欢我建议的解决方案还是 Taiseer Joudah 的方法,即使用 Katana 内置的 OAuth2 授权服务器并进行一些调整?
  • 啊,你让我当场!我喜欢这两种方法,但老实说,Taiseer Joudah 的方法实现起来更简单,只需要为每个额外的 WebAPI 服务添加两行代码到 Startup.cs
  • 没问题。如果您看到可以简化的部分,请随时联系我 ;)
  • 我意识到我的回答不够清楚:我更新它提到可以使用机器密钥来实现对所有 API 使用相同的访问令牌。如果您想选择您的访问令牌将能够访问哪些端点(即访问令牌可用于调用“API 1”,但不能用于“API 2”......或两者兼而有之),我的其余答案仍然适用如果你愿意的话)。 Taiseer Joudah 的方法只支持第一种情况。
猜你喜欢
  • 2014-10-11
  • 1970-01-01
  • 1970-01-01
  • 1970-01-01
  • 1970-01-01
  • 2019-08-19
  • 2019-01-29
  • 2013-06-28
  • 1970-01-01
相关资源
最近更新 更多