Read user info from jwt token payload

master
D4VID 1 year ago
parent 2a19bbbd88
commit eea5850859

@ -1,4 +1,3 @@
using System.Net.Http.Headers;
using System.Security.Claims; using System.Security.Claims;
using System.Text.Json; using System.Text.Json;
using Microsoft.AspNetCore.Authentication; using Microsoft.AspNetCore.Authentication;
@ -26,24 +25,20 @@ builder.Services.AddAuthentication(options => {
options.CallbackPath = authConfig["CallbackPath"]!; options.CallbackPath = authConfig["CallbackPath"]!;
options.AuthorizationEndpoint = authConfig["AuthorizationEndpoint"]!; options.AuthorizationEndpoint = authConfig["AuthorizationEndpoint"]!;
options.TokenEndpoint = authConfig["TokenEndpoint"]!; options.TokenEndpoint = authConfig["TokenEndpoint"]!;
options.UserInformationEndpoint = authConfig["UserInformationEndpoint"]!;
options.SignInScheme = "Cookie"; options.SignInScheme = "Cookie";
options.Backchannel = new HttpClient(new OriginHandler("http://localhost:5255")); options.Backchannel = new HttpClient(new OriginHandler("http://localhost:5255"));
options.ClaimActions.MapJsonKey(ClaimTypes.NameIdentifier, "userId"); options.ClaimActions.MapJsonKey(ClaimTypes.NameIdentifier, "sub");
options.Events = new OAuthEvents { options.Events = new OAuthEvents {
OnCreatingTicket = async context => { OnCreatingTicket = context => {
var request = new HttpRequestMessage(HttpMethod.Get, context.Options.UserInformationEndpoint); var payloadBase64 = context.AccessToken!.Split('.')[1];
request.Headers.Accept.Add(new MediaTypeWithQualityHeaderValue("application/json")); var payloadJson = Base64UrlTextEncoder.Decode(payloadBase64);
request.Headers.Authorization = new AuthenticationHeaderValue("Bearer", context.AccessToken); var payload = JsonDocument.Parse(payloadJson);
var response = await context.Backchannel.SendAsync(request); context.RunClaimActions(payload.RootElement);
response.EnsureSuccessStatusCode();
return Task.CompletedTask;
var user = JsonDocument.Parse(await response.Content.ReadAsStringAsync());
context.RunClaimActions(user.RootElement);
} }
}; };
}); });

@ -10,9 +10,8 @@
"OAuth": { "OAuth": {
"ClientId": "5c2bbd1ed84a4a62ac74d7fcecc1788c", "ClientId": "5c2bbd1ed84a4a62ac74d7fcecc1788c",
"ClientSecret": "99b50d898268854b83f7a7cf30d9281b3a7b887941aeb489daf35361120af987e9f5f9457f016e553d9837511e552e1200686fbf67b5aa7ff2726b6f35b00219", "ClientSecret": "99b50d898268854b83f7a7cf30d9281b3a7b887941aeb489daf35361120af987e9f5f9457f016e553d9837511e552e1200686fbf67b5aa7ff2726b6f35b00219",
"AuthorizationEndpoint": "http://localhost:5255/api/v1/oauth/authorize", "AuthorizationEndpoint": "http://localhost:8080/oauth/authorize",
"TokenEndpoint": "http://localhost:5255/api/v1/oauth/token", "TokenEndpoint": "http://localhost:8080/api/v1/oauth/token",
"UserInformationEndpoint": "http://localhost:5255/api/v1/oauth/user",
"CallbackPath": "/oauth-cb" "CallbackPath": "/oauth-cb"
} }
} }

Loading…
Cancel
Save