Moved the authentication code to its own dedicated class. Minor code cleanup.
This commit is contained in:
Binary file not shown.
@@ -0,0 +1,57 @@
|
|||||||
|
using System;
|
||||||
|
using System.Security.Cryptography;
|
||||||
|
using Microsoft.AspNetCore.Cryptography.KeyDerivation;
|
||||||
|
|
||||||
|
namespace SecureCore
|
||||||
|
{
|
||||||
|
public class Authentication
|
||||||
|
{
|
||||||
|
private static int Iterations { get; set; } = 100000;
|
||||||
|
private static KeyDerivationPrf KeyType { get; } = KeyDerivationPrf.HMACSHA512;
|
||||||
|
private static int KeySize { get; } = 512 / 8;
|
||||||
|
private static int SaltSize { get; } = 128 / 8; //128 bit salt
|
||||||
|
private static int SessionKeySize { get; } = 32; //32 bytes
|
||||||
|
|
||||||
|
public static string CreateSessionId()
|
||||||
|
{
|
||||||
|
var sessionId = new byte[SessionKeySize];
|
||||||
|
|
||||||
|
GetRandomBytes(ref sessionId);
|
||||||
|
|
||||||
|
return Convert.ToBase64String(sessionId);
|
||||||
|
}
|
||||||
|
|
||||||
|
public static (string Hash, string Salt) HashPassword(string password)
|
||||||
|
{
|
||||||
|
var salt = new byte[SaltSize];
|
||||||
|
|
||||||
|
GetRandomBytes(ref salt);
|
||||||
|
|
||||||
|
return (GetPasswordHash(password, salt), Convert.ToBase64String(salt));
|
||||||
|
}
|
||||||
|
|
||||||
|
public static bool PasswordIsValid(string password, string salt, string passwordHash)
|
||||||
|
{
|
||||||
|
var saltBytes = Convert.FromBase64String(salt);
|
||||||
|
|
||||||
|
return passwordHash == GetPasswordHash(password, saltBytes);
|
||||||
|
}
|
||||||
|
|
||||||
|
private static string GetPasswordHash(string password, byte[] salt)
|
||||||
|
{
|
||||||
|
return Convert.ToBase64String(KeyDerivation.Pbkdf2(password, salt, KeyType, Iterations, KeySize));
|
||||||
|
}
|
||||||
|
|
||||||
|
private static void GetRandomBytes(ref byte[] bytes)
|
||||||
|
{
|
||||||
|
using var rng = RandomNumberGenerator.Create();
|
||||||
|
rng.GetBytes(bytes);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
public class LoginInfo
|
||||||
|
{
|
||||||
|
public string UserName { get; set; }
|
||||||
|
public string Password { get; set; }
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,22 @@
|
|||||||
|
using Microsoft.AspNetCore.Mvc;
|
||||||
|
using System;
|
||||||
|
using System.Collections.Generic;
|
||||||
|
using System.Linq;
|
||||||
|
using System.Threading.Tasks;
|
||||||
|
|
||||||
|
namespace SecureCore.Controllers
|
||||||
|
{
|
||||||
|
[Route("[controller]")]
|
||||||
|
[ApiController]
|
||||||
|
public class AuthController : Controller
|
||||||
|
{
|
||||||
|
[HttpPost("login")]
|
||||||
|
[AcceptVerbs("POST")]
|
||||||
|
public IActionResult Login(LoginInfo info)
|
||||||
|
{
|
||||||
|
var (hash, salt) = Authentication.HashPassword(info.Password);
|
||||||
|
|
||||||
|
return Ok($"Session Key: {Authentication.CreateSessionId()}{Environment.NewLine}Password Hash: {hash}{Environment.NewLine}Salt: {salt}{Environment.NewLine}");
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -34,65 +34,19 @@ namespace SecureCore.Controllers
|
|||||||
return Ok(DataService.GetById(id));
|
return Ok(DataService.GetById(id));
|
||||||
}
|
}
|
||||||
|
|
||||||
[HttpPost("login")]
|
//[HttpPost("login")]
|
||||||
[AcceptVerbs("POST")]
|
//[AcceptVerbs("POST")]
|
||||||
public IActionResult Login(LoginInfo info)
|
//public IActionResult Login(LoginInfo info)
|
||||||
{
|
//{
|
||||||
var hash = Auth.HashPassword(info.Password);
|
// var (Hash, Salt) = Auth.HashPassword(info.Password);
|
||||||
var h2 = Auth.HashPassword("Nonesense", "vRWp9TP1nQDLGtDZrd2yuw==");
|
|
||||||
|
|
||||||
return Ok($"Session Key: {Auth.CreateSessionId()}{Environment.NewLine}Password Hash: {hash.Hash}{Environment.NewLine}Salt: {hash.Salt}{Environment.NewLine}{h2 == "+IGLf8scewY2LOObXqfF5IkIbhcEuPrMFc12d78jH6ZyBEMQI+Z9zixWgkQANeV3VYvURBEXIVI0/TPZrnML3w=="}");
|
// return Ok($"Session Key: {Auth.CreateSessionId()}{Environment.NewLine}Password Hash: {Hash}{Environment.NewLine}Salt: {Salt}{Environment.NewLine}");
|
||||||
}
|
//}
|
||||||
}
|
}
|
||||||
|
|
||||||
public class LoginInfo
|
public class AuthenticatedUser
|
||||||
{
|
{
|
||||||
public string UserName { get; set; }
|
public string UserName { get; set; }
|
||||||
public string Password { get; set; }
|
public string SessionToken { get; set; }
|
||||||
}
|
|
||||||
|
|
||||||
public static class Auth
|
|
||||||
{
|
|
||||||
private static int Iterations { get; set; } = 100000;
|
|
||||||
private static KeyDerivationPrf KeyType { get; } = KeyDerivationPrf.HMACSHA512;
|
|
||||||
private static int KeySize { get; } = 512 / 8;
|
|
||||||
private static int SaltSize { get; } = 128 / 8; //128 bit salt
|
|
||||||
private static int SessionKeySize { get; } = 32; //32 bytes
|
|
||||||
|
|
||||||
public static string CreateSessionId()
|
|
||||||
{
|
|
||||||
var sessionId = new byte[SessionKeySize];
|
|
||||||
|
|
||||||
GetRandomBytes(ref sessionId);
|
|
||||||
|
|
||||||
return Convert.ToBase64String(sessionId);
|
|
||||||
}
|
|
||||||
|
|
||||||
public static (string Hash, string Salt) HashPassword(string password)
|
|
||||||
{
|
|
||||||
var salt = new byte[SaltSize];
|
|
||||||
|
|
||||||
GetRandomBytes(ref salt);
|
|
||||||
|
|
||||||
return (GetPasswordHash(password, salt), Convert.ToBase64String(salt));
|
|
||||||
}
|
|
||||||
|
|
||||||
public static string HashPassword(string password, string hash)
|
|
||||||
{
|
|
||||||
var salt = Convert.FromBase64String(hash);
|
|
||||||
|
|
||||||
return GetPasswordHash(password, salt);
|
|
||||||
}
|
|
||||||
|
|
||||||
private static string GetPasswordHash(string password, byte[] salt)
|
|
||||||
{
|
|
||||||
return Convert.ToBase64String(KeyDerivation.Pbkdf2(password, salt, KeyType, Iterations, KeySize));
|
|
||||||
}
|
|
||||||
|
|
||||||
private static void GetRandomBytes(ref byte[] bytes)
|
|
||||||
{
|
|
||||||
using var rng = RandomNumberGenerator.Create();
|
|
||||||
rng.GetBytes(bytes);
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -1,7 +1,7 @@
|
|||||||
<?xml version="1.0" encoding="utf-8"?>
|
<?xml version="1.0" encoding="utf-8"?>
|
||||||
<Project ToolsVersion="Current" xmlns="http://schemas.microsoft.com/developer/msbuild/2003">
|
<Project ToolsVersion="Current" xmlns="http://schemas.microsoft.com/developer/msbuild/2003">
|
||||||
<PropertyGroup>
|
<PropertyGroup>
|
||||||
<Controller_SelectedScaffolderID>MvcControllerWithActionsScaffolder</Controller_SelectedScaffolderID>
|
<Controller_SelectedScaffolderID>MvcControllerEmptyScaffolder</Controller_SelectedScaffolderID>
|
||||||
<Controller_SelectedScaffolderCategoryPath>root/Common/MVC/Controller</Controller_SelectedScaffolderCategoryPath>
|
<Controller_SelectedScaffolderCategoryPath>root/Common/MVC/Controller</Controller_SelectedScaffolderCategoryPath>
|
||||||
<NameOfLastUsedPublishProfile>FolderProfile</NameOfLastUsedPublishProfile>
|
<NameOfLastUsedPublishProfile>FolderProfile</NameOfLastUsedPublishProfile>
|
||||||
</PropertyGroup>
|
</PropertyGroup>
|
||||||
|
|||||||
Binary file not shown.
Binary file not shown.
@@ -1 +1 @@
|
|||||||
7632b3c3dac860a5ca892b30d9c2c673c6b08242
|
fe49541232d842c53eb06770dc71b931991ff712
|
||||||
|
|||||||
Binary file not shown.
Binary file not shown.
Binary file not shown.
Reference in New Issue
Block a user