aboutsummaryrefslogtreecommitdiffstats
path: root/Software/Visual_Studio/Web/Tango.MachineService/App_Start/WebApiConfig.cs
blob: 73265328c7566d165188b854e03ba595e05abf51 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
using Newtonsoft.Json;
using System;
using System.Collections.Generic;
using System.Linq;
using System.Web.Http;
using Tango.Web.Formatters;

namespace Tango.MachineService
{
    public static class WebApiConfig
    {
        public static void Register(HttpConfiguration config)
        {
            // Web API configuration and services

            // Web API routes
            config.MapHttpAttributeRoutes();

            config.Routes.MapHttpRoute(
            name: "API Default",
            routeTemplate: "api/{controller}/{action}/{id}",
            defaults: new { id = RouteParameter.Optional });

            config.Formatters.Insert(0, new ProtoBufFormatter());
            //config.Formatters.Insert(1, new JsonNetFormatter(new JsonSerializerSettings()
            //{
            //    PreserveReferencesHandling = PreserveReferencesHandling.All,
            //}));
        }
    }
}
ght .si { color: #3333bb; background-color: #fff0f0 } /* Literal.String.Interpol */ .highlight .sx { color: #22bb22; background-color: #f0fff0 } /* Literal.String.Other */ .highlight .sr { color: #008800; background-color: #fff0ff } /* Literal.String.Regex */ .highlight .s1 { color: #dd2200; background-color: #fff0f0 } /* Literal.String.Single */ .highlight .ss { color: #aa6600; background-color: #fff0f0 } /* Literal.String.Symbol */ .highlight .bp { color: #003388 } /* Name.Builtin.Pseudo */ .highlight .fm { color: #0066bb; font-weight: bold } /* Name.Function.Magic */ .highlight .vc { color: #336699 } /* Name.Variable.Class */ .highlight .vg { color: #dd7700 } /* Name.Variable.Global */ .highlight .vi { color: #3333bb } /* Name.Variable.Instance */ .highlight .vm { color: #336699 } /* Name.Variable.Magic */ .highlight .il { color: #0000DD; font-weight: bold } /* Literal.Number.Integer.Long */
using JWT;
using JWT.Algorithms;
using JWT.Builder;
using JWT.Serializers;
using Newtonsoft.Json;
using System;
using System.Collections.Generic;
using System.Linq;
using System.Security.Claims;
using System.Text;
using System.Threading.Tasks;

namespace Tango.Web.Security
{
    public class WebToken
    {
        public DateTime Issued { get; protected set; }
        public DateTime? Expiration { get; protected set; }
        public String AccessToken { get; protected set; }
        public String RefreshToken { get; protected set; }

        public WebToken()
        {

        }

        public static WebToken CreateNew(String secret, DateTime? expiration = null)
        {
            DateTime issued = DateTime.UtcNow;

            var builder = new JwtBuilder()
                 .WithAlgorithm(new HMACSHA256Algorithm())
                 .WithSecret(secret)
                 .IssuedAt(issued);

            if (expiration != null)
            {
                builder = builder.ExpirationTime(expiration.Value);
            }

            String refreshToken = Guid.NewGuid().ToString();

            builder = builder.AddClaim("object", null);
            builder = builder.AddClaim("refresh-token", refreshToken);

            return new WebToken()
            {
                AccessToken = builder.Build(),
                RefreshToken = refreshToken,
                Expiration = expiration,
                Issued = issued,
            };
        }

        public static void Validate(String secret, String token)
        {
            var json = new JwtBuilder()
                 .WithSecret(secret)
                 .MustVerifySignature()
                 .Decode(token);
        }

        public void Validate(String secret)
        {
            var json = new JwtBuilder()
                        .WithSecret(secret)
                        .MustVerifySignature()
                        .Decode(AccessToken);
        }

        public WebToken Renew(String secret)
        {
            var newToken = CreateNew(secret, DateTime.UtcNow.Add(Expiration.Value - Issued));
            newToken.RefreshToken = RefreshToken;
            return newToken;
        }

        public static WebToken FromToken(String token)
        {
            WebToken webToken = new WebToken();

            var payload = new JwtBuilder()
                  .WithValidator(null)
                  .Decode<IDictionary<string, object>>(token);

            webToken.AccessToken = token;

            if (payload.ContainsKey("exp"))
            {
                long exp = long.Parse(payload["exp"].ToString());
                webToken.Expiration = ConvertEpochToDateTime(exp);
            }

            if (payload.ContainsKey("iat"))
            {
                long iat = long.Parse(payload["iat"].ToString());
                webToken.Issued = ConvertEpochToDateTime(iat);
            }

            if (payload.ContainsKey("refresh-token"))
            {
                webToken.RefreshToken = payload["refresh-token"].ToString();
            }

            return webToken;
        }

        protected static DateTime ConvertEpochToDateTime(long seconds)
        {
            var epoch = new DateTime(1970, 1, 1, 0, 0, 0, DateTimeKind.Utc);
            return epoch.AddSeconds(seconds);
        }
    }

    public class WebToken<T> : WebToken where T : class
    {
        public T Object { get; protected set; }

        private WebToken()
        {

        }

        public static WebToken<T> CreateNew(String secret, T obj = null, DateTime? expiration = null)
        {
            DateTime issued = DateTime.UtcNow;

            var builder = new JwtBuilder()
                 .WithAlgorithm(new HMACSHA256Algorithm())
                 .WithSecret(secret)
                 .IssuedAt(issued);

            if (expiration != null)
            {
                builder = builder.ExpirationTime(expiration.Value);
            }

            String refreshToken = Guid.NewGuid().ToString();

            builder = builder.AddClaim("object", obj);
            builder = builder.AddClaim("refresh-token", refreshToken);

            return new WebToken<T>()
            {
                AccessToken = builder.Build(),
                RefreshToken = refreshToken,
                Expiration = expiration,
                Issued = issued,
                Object = obj,
            };
        }

        public static new WebToken<T> FromToken(String token)
        {
            WebToken<T> webToken = new WebToken<T>();

            var payload = new JwtBuilder()
                  .WithValidator(null)
                  .Decode<IDictionary<string, object>>(token);

            webToken.AccessToken = token;

            if (payload.ContainsKey("exp"))
            {
                long exp = long.Parse(payload["exp"].ToString());
                webToken.Expiration = ConvertEpochToDateTime(exp);
            }

            if (payload.ContainsKey("iat"))
            {
                long iat = long.Parse(payload["iat"].ToString());
                webToken.Issued = ConvertEpochToDateTime(iat);
            }

            if (payload.ContainsKey("refresh-token"))
            {
                webToken.RefreshToken = payload["refresh-token"].ToString();
            }

            webToken.Object = JsonConvert.DeserializeObject<T>(payload["object"].ToString());

            return webToken;
        }

        public new WebToken<T> Renew(String secret)
        {
            var newToken = WebToken<T>.CreateNew(secret, Object, DateTime.UtcNow.Add(Expiration.Value - Issued));
            newToken.RefreshToken = RefreshToken;
            return newToken;
        }
    }
}