当前位置: 首页 > news >正文

.NETCORE 开发登录接口MFA谷歌多因子身份验证

1.maf帮助类 

 public class GoogleAuthenticator{private readonly static DateTime _epoch = new DateTime(1970, 1, 1, 0, 0, 0, DateTimeKind.Utc);private TimeSpan DefaultClockDriftTolerance { get; set; }public GoogleAuthenticator(){DefaultClockDriftTolerance = TimeSpan.FromSeconds(30);}/// <summary>/// Generate a setup code for a Google Authenticator user to scan/// </summary>/// <param name="issuer">Issuer ID (the name of the system, i.e. 'MyApp'), can be omitted but not recommended https://github.com/google/google-authenticator/wiki/Key-Uri-Format </param>/// <param name="accountTitleNoSpaces">Account Title (no spaces)</param>/// <param name="accountSecretKey">Account Secret Key</param>/// <param name="QRPixelsPerModule">Number of pixels per QR Module (2 pixels give ~ 100x100px QRCode)</param>/// <returns>SetupCode object</returns>public SetupCode GenerateSetupCode(string issuer, string accountTitleNoSpaces, string accountSecretKey, int QRPixelsPerModule){byte[] key = Encoding.UTF8.GetBytes(accountSecretKey);return GenerateSetupCode(issuer, accountTitleNoSpaces, key, QRPixelsPerModule);}/// <summary>/// Generate a setup code for a Google Authenticator user to scan/// </summary>/// <param name="issuer">Issuer ID (the name of the system, i.e. 'MyApp'), can be omitted but not recommended https://github.com/google/google-authenticator/wiki/Key-Uri-Format </param>/// <param name="accountTitleNoSpaces">Account Title (no spaces)</param>/// <param name="accountSecretKey">Account Secret Key as byte[]</param>/// <param name="QRPixelsPerModule">Number of pixels per QR Module (2 = ~120x120px QRCode)</param>/// <returns>SetupCode object</returns>public SetupCode GenerateSetupCode(string issuer, string accountTitleNoSpaces, byte[] accountSecretKey, int QRPixelsPerModule){if (accountTitleNoSpaces == null) { throw new NullReferenceException("Account Title is null"); }accountTitleNoSpaces = RemoveWhitespace(accountTitleNoSpaces);string encodedSecretKey = Base32Encoding.ToString(accountSecretKey);string provisionUrl = null;provisionUrl = String.Format("otpauth://totp/{2}:{0}?secret={1}&issuer={2}", accountTitleNoSpaces, encodedSecretKey.Replace("=", ""), UrlEncode(issuer));using (QRCodeGenerator qrGenerator = new QRCodeGenerator())using (QRCodeData qrCodeData = qrGenerator.CreateQrCode(provisionUrl, QRCodeGenerator.ECCLevel.M))using (QRCode qrCode = new QRCode(qrCodeData))using (Bitmap qrCodeImage = qrCode.GetGraphic(QRPixelsPerModule))using (MemoryStream ms = new MemoryStream()){qrCodeImage.Save(ms, System.Drawing.Imaging.ImageFormat.Png);return new SetupCode(accountTitleNoSpaces, encodedSecretKey, String.Format("data:image/png;base64,{0}", Convert.ToBase64String(ms.ToArray())));}}private static string RemoveWhitespace(string str){return new string(str.Where(c => !Char.IsWhiteSpace(c)).ToArray());}private string UrlEncode(string value){StringBuilder result = new StringBuilder();string validChars = "abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789-_.~";foreach (char symbol in value){if (validChars.IndexOf(symbol) != -1){result.Append(symbol);}else{result.Append('%' + String.Format("{0:X2}", (int)symbol));}}return result.ToString().Replace(" ", "%20");}public string GeneratePINAtInterval(string accountSecretKey, long counter, int digits = 6){return GenerateHashedCode(accountSecretKey, counter, digits);}internal string GenerateHashedCode(string secret, long iterationNumber, int digits = 6){byte[] key = Encoding.UTF8.GetBytes(secret);return GenerateHashedCode(key, iterationNumber, digits);}internal string GenerateHashedCode(byte[] key, long iterationNumber, int digits = 6){byte[] counter = BitConverter.GetBytes(iterationNumber);if (BitConverter.IsLittleEndian){Array.Reverse(counter);}HMACSHA1 hmac = new HMACSHA1(key);byte[] hash = hmac.ComputeHash(counter);int offset = hash[hash.Length - 1] & 0xf;// Convert the 4 bytes into an integer, ignoring the sign.int binary =((hash[offset] & 0x7f) << 24)| (hash[offset + 1] << 16)| (hash[offset + 2] << 8)| (hash[offset + 3]);int password = binary % (int)Math.Pow(10, digits);return password.ToString(new string('0', digits));}private long GetCurrentCounter(){return GetCurrentCounter(DateTime.UtcNow, _epoch, 30);}private long GetCurrentCounter(DateTime now, DateTime epoch, int timeStep){return (long)(now - epoch).TotalSeconds / timeStep;}public bool ValidateTwoFactorPIN(string accountSecretKey, string twoFactorCodeFromClient){return ValidateTwoFactorPIN(accountSecretKey, twoFactorCodeFromClient, DefaultClockDriftTolerance);}public bool ValidateTwoFactorPIN(string accountSecretKey, string twoFactorCodeFromClient, TimeSpan timeTolerance){var codes = GetCurrentPINs(accountSecretKey, timeTolerance);return codes.Any(c => c == twoFactorCodeFromClient);}public string[] GetCurrentPINs(string accountSecretKey, TimeSpan timeTolerance){List<string> codes = new List<string>();long iterationCounter = GetCurrentCounter();int iterationOffset = 0;if (timeTolerance.TotalSeconds > 30){iterationOffset = Convert.ToInt32(timeTolerance.TotalSeconds / 30.00);}long iterationStart = iterationCounter - iterationOffset;long iterationEnd = iterationCounter + iterationOffset;for (long counter = iterationStart; counter <= iterationEnd; counter++){codes.Add(GeneratePINAtInterval(accountSecretKey, counter));}return codes.ToArray();}}

2.nugget安装GoogleAuthenticator;

3.

开启mfa时候请求以下接口

 public async Task<ActionResult<Result>> GoogleImg(){try{Dictionary<string, string> dic = new Dictionary<string, string>();var UserId = HttpContext.Session.GetString("UserId");if (UserId != ""){var userinfo = _userAirware.Query(u => u.UserId == Convert.ToInt32(UserId)).Result.FirstOrDefault();if (userinfo != null){if (userinfo.IsSuccess == 0){GoogleAuthenticator tfa = new GoogleAuthenticator();var guid = Guid.NewGuid().ToString();SetupCode setupInfo = tfa.GenerateSetupCode("FS Airware", userinfo.UserEmail, guid, 3);//更新guid到当前登录用户userinfo.GoogleAuthkey = guid;await ???.Update(userinfo);QRImageUrl = setupInfo.QrCodeSetupImageUrl;ManualEntryKey = setupInfo.ManualEntryKey;//dic.Add("isverify", "true");dic.Add("img", QRImageUrl);return ApiResultHelper.renderSuccess(dic, "Login succeeded");}return ApiResultHelper.renderError("ENABLED");}}return ApiResultHelper.renderError("非法请求!");}catch (Exception e){return ApiResultHelper.renderError();}}

4.验证接口

 public async Task<ActionResult<Result>> GoogleVerify(string checkcode){var UserId = HttpContext.Session.GetString("UserId");Dictionary<string, string> dic1 = new Dictionary<string, string>();//判断当前用户是否登录成功if (UserId != ""){var userinfo = _userAirware.Query(u => u.UserId == Convert.ToInt32(UserId)).Result.FirstOrDefault();if (userinfo != null){if (userinfo.IsVerify == 0){GoogleAuthenticator gat = new GoogleAuthenticator();var result = gat.ValidateTwoFactorPIN(userinfo.GoogleAuthkey, checkcode);if (result){Dictionary<string, string> clims = new Dictionary<string, string>{{"ProjectName",userinfo.UserFirstName }};await ???.Update(userinfo);string token = _jwt.GetToken(clims);dic1.Add("isverify", "true");dic1.Add("token", token);dic1.Add("userid", userinfo.UserId + "");dic1.Add("name", userinfo.UserFirstName);return ApiResultHelper.renderSuccess(dic1);}else{return ApiResultHelper.renderError(false);}}}}return ApiResultHelper.renderError("非法访问!");}

相关文章:

  • 电脑硬盘恢复方法分享,轻松完成数据恢复!
  • Backtrader 文档学习-Broker
  • 如何在Raspberry Pi上启用SSH并结合cpolar内网穿透实现公网远程访问本地树莓派
  • 正则表达式与文本三剑客
  • SVM(支持向量机)原理与应用
  • Sentinel 知识总结
  • vue3开发,axios发送请求是携带params参数的避坑
  • Android 12.0 应用中监听系统收到的通知
  • 代码随想录算法训练营第36天 | 435.无重叠区间 + 763.划分字母区间 + 56.合并区间
  • 投标书撰写注意事项
  • HiveSQL题——数据炸裂和数据合并
  • 海外短剧系统国际短剧源码h5多语言版app挂载tiktok油管ins
  • Linux系统-学习
  • LaTeX 文本对齐:ragged2e 宏包
  • 【大厂AI课学习笔记】1.3 人工智能产业发展(4)——泛在的人工智能
  • [LeetCode] Wiggle Sort
  • ECMAScript 6 学习之路 ( 四 ) String 字符串扩展
  • iOS编译提示和导航提示
  • Javascripit类型转换比较那点事儿,双等号(==)
  • Solarized Scheme
  • Spring Security中异常上抛机制及对于转型处理的一些感悟
  • 不用申请服务号就可以开发微信支付/支付宝/QQ钱包支付!附:直接可用的代码+demo...
  • 当SetTimeout遇到了字符串
  • 等保2.0 | 几维安全发布等保检测、等保加固专版 加速企业等保合规
  • 分布式熔断降级平台aegis
  • 关于Java中分层中遇到的一些问题
  • 基于Volley网络库实现加载多种网络图片(包括GIF动态图片、圆形图片、普通图片)...
  • 技术发展面试
  • 爬虫进阶 -- 神级程序员:让你的爬虫就像人类的用户行为!
  • 深度解析利用ES6进行Promise封装总结
  • 微信小程序:实现悬浮返回和分享按钮
  • 智能合约开发环境搭建及Hello World合约
  • postgresql行列转换函数
  • ​【原创】基于SSM的酒店预约管理系统(酒店管理系统毕业设计)
  • #14vue3生成表单并跳转到外部地址的方式
  • (22)C#传智:复习,多态虚方法抽象类接口,静态类,String与StringBuilder,集合泛型List与Dictionary,文件类,结构与类的区别
  • (32位汇编 五)mov/add/sub/and/or/xor/not
  • (delphi11最新学习资料) Object Pascal 学习笔记---第2章第五节(日期和时间)
  • (PHP)设置修改 Apache 文件根目录 (Document Root)(转帖)
  • (安全基本功)磁盘MBR,分区表,活动分区,引导扇区。。。详解与区别
  • (规划)24届春招和25届暑假实习路线准备规划
  • (九)One-Wire总线-DS18B20
  • (循环依赖问题)学习spring的第九天
  • (一)spring cloud微服务分布式云架构 - Spring Cloud简介
  • (转)创业的注意事项
  • (转)大道至简,职场上做人做事做管理
  • .net web项目 调用webService
  • .NET/C# 阻止屏幕关闭,阻止系统进入睡眠状态
  • .NET下ASPX编程的几个小问题
  • 。Net下Windows服务程序开发疑惑
  • [ 隧道技术 ] 反弹shell的集中常见方式(四)python反弹shell
  • [100天算法】-二叉树剪枝(day 48)
  • [2008][note]腔内级联拉曼发射的,二极管泵浦多频调Q laser——
  • [20150904]exp slow.txt
  • [Angular] 笔记 8:list/detail 页面以及@Input