.NETCORE 开发登录接口MFA谷歌多因子身份验证

news/2024/5/19 20:57:16 标签: .netcore

1.maf帮助类 

 public class GoogleAuthenticator
    {
        private readonly static DateTime _epoch = new DateTime(1970, 1, 1, 0, 0, 0, DateTimeKind.Utc);
        private TimeSpan DefaultClockDriftTolerance { get; set; }

        public GoogleAuthenticator()
        {
            DefaultClockDriftTolerance = TimeSpan.FromSeconds(30);
        }

        /// <summary>
        /// Generate a setup code for a Google Authenticator user to scan
        /// </summary>
        /// <param name="issuer">Issuer ID (the name of the system, i.e. 'MyApp'), can be omitted but not recommended https://github.com/google/google-authenticator/wiki/Key-Uri-Format </param>
        /// <param name="accountTitleNoSpaces">Account Title (no spaces)</param>
        /// <param name="accountSecretKey">Account Secret Key</param>
        /// <param name="QRPixelsPerModule">Number of pixels per QR Module (2 pixels give ~ 100x100px QRCode)</param>
        /// <returns>SetupCode object</returns>
        public SetupCode GenerateSetupCode(string issuer, string accountTitleNoSpaces, string accountSecretKey, int QRPixelsPerModule)
        {
            byte[] key = Encoding.UTF8.GetBytes(accountSecretKey);
            return GenerateSetupCode(issuer, accountTitleNoSpaces, key, QRPixelsPerModule);
        }

        /// <summary>
        /// Generate a setup code for a Google Authenticator user to scan
        /// </summary>
        /// <param name="issuer">Issuer ID (the name of the system, i.e. 'MyApp'), can be omitted but not recommended https://github.com/google/google-authenticator/wiki/Key-Uri-Format </param>
        /// <param name="accountTitleNoSpaces">Account Title (no spaces)</param>
        /// <param name="accountSecretKey">Account Secret Key as byte[]</param>
        /// <param name="QRPixelsPerModule">Number of pixels per QR Module (2 = ~120x120px QRCode)</param>
        /// <returns>SetupCode object</returns>
        public SetupCode GenerateSetupCode(string issuer, string accountTitleNoSpaces, byte[] accountSecretKey, int QRPixelsPerModule)
        {
            if (accountTitleNoSpaces == null) { throw new NullReferenceException("Account Title is null"); }
            accountTitleNoSpaces = RemoveWhitespace(accountTitleNoSpaces);
            string encodedSecretKey = Base32Encoding.ToString(accountSecretKey);
            string provisionUrl = null;
            provisionUrl = String.Format("otpauth://totp/{2}:{0}?secret={1}&issuer={2}", accountTitleNoSpaces, encodedSecretKey.Replace("=", ""), UrlEncode(issuer));



            using (QRCodeGenerator qrGenerator = new QRCodeGenerator())
            using (QRCodeData qrCodeData = qrGenerator.CreateQrCode(provisionUrl, QRCodeGenerator.ECCLevel.M))
            using (QRCode qrCode = new QRCode(qrCodeData))
            using (Bitmap qrCodeImage = qrCode.GetGraphic(QRPixelsPerModule))
            using (MemoryStream ms = new MemoryStream())
            {
                qrCodeImage.Save(ms, System.Drawing.Imaging.ImageFormat.Png);

                return new SetupCode(accountTitleNoSpaces, encodedSecretKey, String.Format("data:image/png;base64,{0}", Convert.ToBase64String(ms.ToArray())));
            }

        }

        private static string RemoveWhitespace(string str)
        {
            return new string(str.Where(c => !Char.IsWhiteSpace(c)).ToArray());
        }

        private string UrlEncode(string value)
        {
            StringBuilder result = new StringBuilder();
            string validChars = "abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789-_.~";

            foreach (char symbol in value)
            {
                if (validChars.IndexOf(symbol) != -1)
                {
                    result.Append(symbol);
                }
                else
                {
                    result.Append('%' + String.Format("{0:X2}", (int)symbol));
                }
            }

            return result.ToString().Replace(" ", "%20");
        }

        public string GeneratePINAtInterval(string accountSecretKey, long counter, int digits = 6)
        {
            return GenerateHashedCode(accountSecretKey, counter, digits);
        }

        internal string GenerateHashedCode(string secret, long iterationNumber, int digits = 6)
        {
            byte[] key = Encoding.UTF8.GetBytes(secret);
            return GenerateHashedCode(key, iterationNumber, digits);
        }

        internal string GenerateHashedCode(byte[] key, long iterationNumber, int digits = 6)
        {
            byte[] counter = BitConverter.GetBytes(iterationNumber);

            if (BitConverter.IsLittleEndian)
            {
                Array.Reverse(counter);
            }

            HMACSHA1 hmac = new HMACSHA1(key);

            byte[] hash = hmac.ComputeHash(counter);

            int offset = hash[hash.Length - 1] & 0xf;

            // Convert the 4 bytes into an integer, ignoring the sign.
            int binary =
              ((hash[offset] & 0x7f) << 24)
              | (hash[offset + 1] << 16)
              | (hash[offset + 2] << 8)
              | (hash[offset + 3]);

            int password = binary % (int)Math.Pow(10, digits);
            return password.ToString(new string('0', digits));
        }

        private long GetCurrentCounter()
        {
            return GetCurrentCounter(DateTime.UtcNow, _epoch, 30);
        }

        private long GetCurrentCounter(DateTime now, DateTime epoch, int timeStep)
        {
            return (long)(now - epoch).TotalSeconds / timeStep;
        }

        public bool ValidateTwoFactorPIN(string accountSecretKey, string twoFactorCodeFromClient)
        {
            return ValidateTwoFactorPIN(accountSecretKey, twoFactorCodeFromClient, DefaultClockDriftTolerance);
        }

        public bool ValidateTwoFactorPIN(string accountSecretKey, string twoFactorCodeFromClient, TimeSpan timeTolerance)
        {
            var codes = GetCurrentPINs(accountSecretKey, timeTolerance);
            return codes.Any(c => c == twoFactorCodeFromClient);
        }

        public string[] GetCurrentPINs(string accountSecretKey, TimeSpan timeTolerance)
        {
            List<string> codes = new List<string>();
            long iterationCounter = GetCurrentCounter();
            int iterationOffset = 0;

            if (timeTolerance.TotalSeconds > 30)
            {
                iterationOffset = Convert.ToInt32(timeTolerance.TotalSeconds / 30.00);
            }

            long iterationStart = iterationCounter - iterationOffset;
            long iterationEnd = iterationCounter + iterationOffset;

            for (long counter = iterationStart; counter <= iterationEnd; counter++)
            {
                codes.Add(GeneratePINAtInterval(accountSecretKey, counter));
            }

            return codes.ToArray();
        }
    }

2.nugget安装GoogleAuthenticator;

3.

开启mfa时候请求以下接口

 public async Task<ActionResult<Result>> GoogleImg()
        {
            try
            {
                Dictionary<string, string> dic = new Dictionary<string, string>();
                var UserId = HttpContext.Session.GetString("UserId");
                if (UserId != "")
                {

                    var userinfo = _userAirware.Query(u => u.UserId == Convert.ToInt32(UserId)).Result.FirstOrDefault();
                    if (userinfo != null)
                    {
                        if (userinfo.IsSuccess == 0)
                        {
                            GoogleAuthenticator tfa = new GoogleAuthenticator();
                            var guid = Guid.NewGuid().ToString();
                            SetupCode setupInfo = tfa.GenerateSetupCode("FS Airware", userinfo.UserEmail, guid, 3);
                            //更新guid到当前登录用户
                            userinfo.GoogleAuthkey = guid;
                            await ???.Update(userinfo);
                            QRImageUrl = setupInfo.QrCodeSetupImageUrl;
                            ManualEntryKey = setupInfo.ManualEntryKey;
                            //dic.Add("isverify", "true");
                            dic.Add("img", QRImageUrl);
                            return ApiResultHelper.renderSuccess(dic, "Login succeeded");
                        }
                        return ApiResultHelper.renderError("ENABLED");
                    }
                }

                return ApiResultHelper.renderError("非法请求!");
            }
            catch (Exception e)
            {
                return ApiResultHelper.renderError();
            }
        }

4.验证接口

 public async Task<ActionResult<Result>> GoogleVerify(string checkcode)
        {
            var UserId = HttpContext.Session.GetString("UserId");
            Dictionary<string, string> dic1 = new Dictionary<string, string>();
            //判断当前用户是否登录成功
            if (UserId != "")
            {
                var userinfo = _userAirware.Query(u => u.UserId == Convert.ToInt32(UserId)).Result.FirstOrDefault();
                if (userinfo != null)
                {
                    if (userinfo.IsVerify == 0)
                    {
                        GoogleAuthenticator gat = new GoogleAuthenticator();
                        var result = gat.ValidateTwoFactorPIN(userinfo.GoogleAuthkey, checkcode);
                        if (result)
                        {
                            Dictionary<string, string> clims = new Dictionary<string, string>
                            {
                                {"ProjectName",userinfo.UserFirstName }
                            };
                            await ???.Update(userinfo);
                            string token = _jwt.GetToken(clims);
                            dic1.Add("isverify", "true");
                            dic1.Add("token", token);
                            dic1.Add("userid", userinfo.UserId + "");
                            dic1.Add("name", userinfo.UserFirstName);
                            return ApiResultHelper.renderSuccess(dic1);
                        }
                        else
                        {
                            return ApiResultHelper.renderError(false);
                        }
                    }
                }
            }
            return ApiResultHelper.renderError("非法访问!");
        }


http://www.niftyadmin.cn/n/5358263.html

相关文章

一品威客登陆接口逆向

文章目录 目标网站抓包分析Signature 分析分析参数U分析参数P分析参数l.j分析函数f.a signature代码实现 目标网站 aHR0cHM6Ly93d3cuZXB3ay5jb20vbG9naW4uaHRtbA抓包分析 先抓一个登陆的包&#xff0c;payload里面没有需要分析的数据 需要分析的数据在请求头里面&#xff0c;我…

Python学习(内置日期函数 )——timedelta()应用案例

在Python中&#xff0c;内置有丰富的日期操作函数&#xff0c;下面是timedelta()函数详细介绍及应用。 在Python中&#xff0c;timedelta 是一个表示时间差的类&#xff0c;它属于 datetime 模块。timedelta 对象表示两个日期或时间之间的差异。 当你想要表示一段时间&#x…

c# datatable 通过反射转成泛型list

在C#中&#xff0c;可以使用反射来将DataTable转换为泛型列表。下面是一个示例代码&#xff0c;展示了如何使用反射来实现这个转换过程&#xff1a; using System; using System.Collections.Generic; using System.Data;public class DataConverter {public List<T> Co…

LeetCode--171

171. Excel 表列序号 给你一个字符串 columnTitle &#xff0c;表示 Excel 表格中的列名称。返回 该列名称对应的列序号 。 例如&#xff1a; A -> 1 B -> 2 C -> 3 ... Z -> 26 AA -> 27 AB -> 28 ... 示例 1: 输入: columnTitle "A" 输出:…

虚拟机VM创建LINUX共享文件夹

由于大部分人常用和熟悉的系统是Windows系统&#xff0c;所以在Linux下进行操作很多时候会感到不太方便&#xff0c;就比如程序代码开发时大多数情况下都是在Windows下进行的&#xff0c;所以比较熟悉Windows下的开发环境。要进行Linux开发的时候&#xff0c;多数情况下都是借助…

相邀,一起看林曦水墨画展吧

在岁暮年初&#xff0c;有一件好事&#xff0c;林曦老师的画展&#xff1a;《一纪佳兴林曦水墨作品展》已经开展啦&#xff5e;&#xff5e;来约你&#xff0c;我们结伴&#xff0c;一起去看呀    今年是我画年历的第十二年&#xff0c;如果从第一年就开始用这个年历&#…

全流程机器视觉工程开发(四)PaddleDetection C++工程化应用部署到本地DLL以供软件调用

前言 我们之前跑了一个yolo的模型&#xff0c;然后我们通过PaddleDetection的库对这个模型进行了一定程度的调用&#xff0c;但是那个调用还是基于命令的调用&#xff0c;这样的库首先第一个不能部署到客户的电脑上&#xff0c;第二个用起来也非常不方便&#xff0c;那么我们可…

C# 递归执行顺序

为了方便进一步理解递归&#xff0c;写了一个数字输出 class Program {static void Main(string[] args){int number 5;RecursiveDecrease(number);}static void RecursiveDecrease(int n){if (n > 0){Console.WriteLine("Before recursive call do : " n);Rec…