从JWT代币获取声明、权限和角色



我正在.NET 6应用程序中实现/refresh令牌端点。控制器从标头中获取JWT令牌,对其进行解码并发布新令牌。

角色和权限的Itemvalue类型为Newtonsoft.Json.Linq.JArray.

我做得正确吗?还是有更好的解决方案?

var handler = new JwtSecurityTokenHandler();
var oldTokenDecoded = handler.ReadJwtToken(oldToken);

List<string> rolesDecoded = new List<string>();
List<string> permissionsDecoded = new List<string>();
string UsernameDecoded = "";
string UserIDDecoded = "";
foreach(var item in oldTokenDecoded.Payload)
{
if(item.Key == "role")
{
rolesDecoded = JsonConvert.DeserializeObject<List<string>>(item.Value.ToString());
}
if(item.Key == "permissions")
{
permissionsDecoded = JsonConvert.DeserializeObject<List<string>>(item.Value.ToString());
}
if(item.Key == "Username")
{
UsernameDecoded = item.Value.ToString();
}
if(item.Key == "UserID")
{
UserIDDecoded = item.Value.ToString();
}

}

var jwtToken = JWTBearer.CreateToken(
signingKey: "token",
expireAt: DateTime.UtcNow.AddDays(1),
claims: new[] { ("Username", UsernameDecoded), ("UserID", UserIDDecoded) },
roles: rolesDecoded,
permissions: permissionsDecoded);```

使用.Claims迭代索赔,而不是您当前的方法:

List<string> roles = new List<string>();
List<string> permissions = new List<string>();
string username;
string userId;
foreach(var item in oldTokenDecoded.Claims)
{
switch (item.Type)
{
case "role":
roles.Add(item.Value);
break;
case "permission":
permissions.Add(item.Value);
break;
case "Username":
username = item.Value;
break;
case "UserID":
userId = item.Value;
break;
// etc
}
}

最新更新