Auth.cs 8.4 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237
  1. using System;
  2. using System.Collections.Generic;
  3. using System.Text;
  4. using System.Net;
  5. using System.Web;
  6. using System.Globalization;
  7. using System.Security.Cryptography;
  8. namespace FastReport.Cloud.OAuth
  9. {
  10. /// <summary>
  11. /// API for OAuth protocol.
  12. /// </summary>
  13. public class Auth
  14. {
  15. #region Constants
  16. private const string UnreservedChars = "abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789.~_-";
  17. #endregion // Constants
  18. #region Private Methods
  19. private string GenerateTimestamp()
  20. {
  21. DateTime startPoint = new DateTime(1970, 1, 1, 0, 0, 0, 0);
  22. TimeSpan span = DateTime.UtcNow - startPoint;
  23. return Convert.ToInt64(span.TotalSeconds).ToString();
  24. }
  25. private string GenerateNonce()
  26. {
  27. Random rand = new Random();
  28. return rand.Next().ToString();
  29. }
  30. private List<RequestParameter> GetOAuthRequestParameters(string query)
  31. {
  32. List<RequestParameter> result = new List<RequestParameter>();
  33. if (query.StartsWith("?"))
  34. {
  35. query = query.Remove(0, 1);
  36. }
  37. if (!string.IsNullOrEmpty(query))
  38. {
  39. string[] parameters = query.Split('&');
  40. foreach (string parameter in parameters)
  41. {
  42. if (!string.IsNullOrEmpty(parameter) && !parameter.StartsWith("oauth_"))
  43. {
  44. if (parameter.IndexOf('=') >= 0)
  45. {
  46. string[] p = parameter.Split('=');
  47. result.Add(new RequestParameter(p[0], p[1]));
  48. }
  49. else
  50. {
  51. result.Add(new RequestParameter(parameter, ""));
  52. }
  53. }
  54. }
  55. }
  56. return result;
  57. }
  58. private string UrlEncode(string str)
  59. {
  60. string result = "";
  61. if (!string.IsNullOrEmpty(str))
  62. {
  63. StringBuilder sb = new StringBuilder(str.Length);
  64. for (int i = 0; i < str.Length; i++)
  65. {
  66. if (UnreservedChars.IndexOf(str[i]) >= 0)
  67. {
  68. sb.Append(str[i]);
  69. }
  70. else
  71. {
  72. byte[] bytes = Encoding.UTF8.GetBytes(str[i].ToString());
  73. for (int j = 0; j < bytes.Length; j++)
  74. {
  75. sb.AppendFormat(CultureInfo.InvariantCulture, "%{0:X2}", bytes[j]);
  76. }
  77. }
  78. }
  79. result = sb.ToString();
  80. }
  81. return result;
  82. }
  83. private string GenerateSignatureBase(Uri uri, ConsumerContext consumer, Token token, string httpMethod, string timestamp, string nonce, out string normUrl, out string normParameters)
  84. {
  85. normUrl = "";
  86. normParameters = "";
  87. List<RequestParameter> parameters = GetOAuthRequestParameters(uri.Query);
  88. parameters.Add(new RequestParameter("oauth_version", "1.0"));
  89. parameters.Add(new RequestParameter("oauth_nonce", nonce));
  90. parameters.Add(new RequestParameter("oauth_timestamp", timestamp));
  91. parameters.Add(new RequestParameter("oauth_signature_method", consumer.SignatureMethod));
  92. parameters.Add(new RequestParameter("oauth_consumer_key", consumer.ConsumerKey));
  93. if (!string.IsNullOrEmpty(token.TokenKey))
  94. {
  95. parameters.Add(new RequestParameter("oauth_token", token.TokenKey));
  96. }
  97. parameters.Sort(new RequestParameterComparer());
  98. normParameters = NormalizeParameters(parameters);
  99. normUrl = string.Format("{0}://{1}", uri.Scheme, uri.Host);
  100. if (!((uri.Scheme == "http" && uri.Port == 80) || (uri.Scheme == "https" && uri.Port == 443)))
  101. {
  102. normUrl += ":" + uri.Port;
  103. }
  104. normUrl += uri.AbsolutePath;
  105. StringBuilder signatureBase = new StringBuilder();
  106. signatureBase.AppendFormat("{0}&", httpMethod);
  107. signatureBase.AppendFormat("{0}&", UrlEncode(normUrl));
  108. signatureBase.AppendFormat("{0}", UrlEncode(normParameters));
  109. return signatureBase.ToString();
  110. }
  111. private string GenerateHashSignature(string signatureBase, HashAlgorithm alg)
  112. {
  113. string result = "";
  114. if (!string.IsNullOrEmpty(signatureBase))
  115. {
  116. byte[] buff = Encoding.UTF8.GetBytes(signatureBase);
  117. byte[] hash = alg.ComputeHash(buff);
  118. result = Convert.ToBase64String(hash);
  119. }
  120. return result;
  121. }
  122. private string GenerateSignature(Uri uri, ConsumerContext consumer, Token token, string httpMethod, string timestamp, string nonce, out string normUrl, out string normParameters)
  123. {
  124. normUrl = "";
  125. normParameters = "";
  126. string result = "";
  127. StringBuilder sb = new StringBuilder();
  128. switch (consumer.SignatureMethod)
  129. {
  130. case SignatureMethod.Plaintext:
  131. sb.AppendFormat("{0}&{1}", consumer.ConsumerSecret, token.TokenSecret);
  132. result = sb.ToString();
  133. break;
  134. case SignatureMethod.HmacSha1:
  135. string signatureBase = GenerateSignatureBase(uri, consumer, token, httpMethod, timestamp, nonce, out normUrl, out normParameters);
  136. using (HMACSHA1 func = new HMACSHA1())
  137. {
  138. func.Key = Encoding.UTF8.GetBytes(string.Format("{0}&{1}", UrlEncode(consumer.ConsumerSecret), UrlEncode(token.TokenSecret)));
  139. result = GenerateHashSignature(signatureBase, func);
  140. }
  141. break;
  142. default:
  143. throw new ArgumentException("Unknown signature method", "signatureMethod");
  144. }
  145. return result;
  146. }
  147. private string NormalizeParameters(List<RequestParameter> parameters)
  148. {
  149. StringBuilder np = new StringBuilder();
  150. foreach (RequestParameter p in parameters)
  151. {
  152. np.AppendFormat("{0}={1}", p.Name, p.Value);
  153. np.Append("&");
  154. }
  155. np.Remove(np.Length - 1, 1);
  156. return np.ToString();
  157. }
  158. #endregion // Private Methods
  159. #region Public Methods
  160. /// <summary>
  161. /// Builds signed URL.
  162. /// </summary>
  163. /// <param name="baseTokenUrl">The base token URL.</param>
  164. /// <param name="method">The HTTP method.</param>
  165. /// <param name="consumer">The consumer context.</param>
  166. /// <param name="token">The request token.</param>
  167. /// <returns>Signed URL.</returns>
  168. public string BuildSignedUrl(string baseTokenUrl, string method, ConsumerContext consumer, Token token)
  169. {
  170. string normUrl = "";
  171. string normParameters = "";
  172. string nonce = GenerateNonce();
  173. string timestamp = GenerateTimestamp();
  174. string signature = GenerateSignature(new Uri(baseTokenUrl), consumer, token, method, timestamp, nonce, out normUrl, out normParameters);
  175. signature = HttpUtils.UrlEncode(signature);
  176. StringBuilder sb = new StringBuilder(normUrl);
  177. sb.AppendFormat("?");
  178. sb.AppendFormat(normParameters);
  179. sb.AppendFormat("&oauth_signature={0}", signature);
  180. return sb.ToString();
  181. }
  182. #endregion // Public Methods
  183. }
  184. /// <summary>
  185. /// Represents the signature method.
  186. /// </summary>
  187. public static class SignatureMethod
  188. {
  189. #region Constants
  190. /// <summary>
  191. /// Signature method PLAINTEXT.
  192. /// </summary>
  193. public const string Plaintext = "PLAINTEXT";
  194. /// <summary>
  195. /// Signature method HMAC-SHA1.
  196. /// </summary>
  197. public const string HmacSha1 = "HMAC-SHA1";
  198. /// <summary>
  199. /// Signature method RSA-SHA1.
  200. /// </summary>
  201. public const string RsaSha1 = "RSA-SHA1";
  202. #endregion // Constants
  203. }
  204. }