1. 项目代码:MasterChief.DotNet.ProjectTemplate.WebApi
  2. 示例代码:https://github.com/YanZhiwei/MasterChief.ProjectTemplate.WebApiSample
  3. Nuget : Install-Package MasterChief.DotNet.ProjectTemplate.WebApi
  4. 实现WebApi开发中诸如授权验证,缓存,参数验证,异常处理等,方便快速构建项目而无需过多关心技术细节;
  5. 欢迎Star,欢迎Issues;

目录

Created by gh-md-toc

授权

  1. 授权接口,通过该接口自定义授权实现,项目默认实现基于Jwt授权

    /// <summary>
    /// WebApi 授权接口
    /// </summary>
    public interface IApiAuthorize
    {
    /// <summary>
    /// 检查请求签名合法性
    /// </summary>
    /// <param name="signature">加密签名字符串</param>
    /// <param name="timestamp">时间戳</param>
    /// <param name="nonce">随机数</param>
    /// <param name="appConfig">应用接入配置信息</param>
    /// <returns>CheckResult</returns>
    CheckResult CheckRequestSignature(string signature, string timestamp, string nonce, AppConfig appConfig); /// <summary>
    /// 创建合法用户获取访问令牌接口数据
    /// </summary>
    /// <param name="identityUser">IdentityUser</param>
    /// <param name="appConfig">AppConfig</param>
    /// <returns>IdentityToken</returns>
    ApiResult<IdentityToken> CreateIdentityToken(IdentityUser identityUser, AppConfig appConfig);
    }
  2. 基于Jwt授权实现

    /// <summary>
    /// 基于Jwt 授权实现
    /// </summary>
    public sealed class JwtApiAuthorize : IApiAuthorize
    {
    /// <summary>
    /// 检查请求签名合法性
    /// </summary>
    /// <param name="signature">加密签名字符串</param>
    /// <param name="timestamp">时间戳</param>
    /// <param name="nonce">随机数</param>
    /// <param name="appConfig">应用接入配置信息</param>
    /// <returns>CheckResult</returns>
    public CheckResult CheckRequestSignature(string signature, string timestamp, string nonce, AppConfig appConfig)
    {
    ValidateOperator.Begin()
    .NotNullOrEmpty(signature, "加密签名字符串")
    .NotNullOrEmpty(timestamp, "时间戳")
    .NotNullOrEmpty(nonce, "随机数")
    .NotNull(appConfig, "AppConfig");
    var appSecret = appConfig.AppSecret;
    var signatureExpired = appConfig.SignatureExpiredMinutes;
    string[] data = {appSecret, timestamp, nonce};
    Array.Sort(data);
    var signatureText = string.Join("", data);
    signatureText = Md5Encryptor.Encrypt(signatureText); if (!signature.CompareIgnoreCase(signatureText) && CheckHelper.IsNumber(timestamp))
    return CheckResult.Success();
    var timestampMillis =
    UnixEpochHelper.DateTimeFromUnixTimestampMillis(timestamp.ToDoubleOrDefault());
    var minutes = DateTime.UtcNow.Subtract(timestampMillis).TotalMinutes; return minutes > signatureExpired ? CheckResult.Fail("签名时间戳失效") : CheckResult.Success();
    } /// <summary>
    /// 创建合法用户获取访问令牌接口数据
    /// </summary>
    /// <param name="identityUser">IdentityUser</param>
    /// <param name="appConfig">AppConfig</param>
    /// <returns>IdentityToken</returns>
    public ApiResult<IdentityToken> CreateIdentityToken(IdentityUser identityUser, AppConfig appConfig)
    {
    ValidateOperator.Begin()
    .NotNull(identityUser, "IdentityUser")
    .NotNull(appConfig, "AppConfig");
    var payload = new Dictionary<string, object>
    {
    {"iss", identityUser.UserId},
    {"iat", UnixEpochHelper.GetCurrentUnixTimestamp().TotalSeconds}
    };
    var identityToken = new IdentityToken
    {
    AccessToken = CreateIdentityToken(appConfig.SharedKey, payload),
    ExpiresIn = appConfig.TokenExpiredDay * 24 * 3600
    };
    return ApiResult<IdentityToken>.Success(identityToken);
    } /// <summary>
    /// 创建Token
    /// </summary>
    /// <param name="secret">密钥</param>
    /// <param name="payload">负载数据</param>
    /// <returns>Token令牌</returns>
    public static string CreateIdentityToken(string secret, Dictionary<string, object> payload)
    {
    ValidateOperator.Begin().NotNull(payload, "负载数据").NotNullOrEmpty(secret, "密钥");
    IJwtAlgorithm algorithm = new HMACSHA256Algorithm();
    IJsonSerializer serializer = new JsonNetSerializer();
    IBase64UrlEncoder urlEncoder = new JwtBase64UrlEncoder();
    IJwtEncoder encoder = new JwtEncoder(algorithm, serializer, urlEncoder);
    return encoder.Encode(payload, secret);
    }
    }

鉴权

  1. Token令牌鉴定接口,通过该接口可以自定义扩展实现方式,项目默认实现基于Jwt鉴权

    /// <summary>
    /// webApi 验证系统基本接口
    /// </summary>
    public interface IApiAuthenticate
    {
    #region Methods /// <summary>
    /// 验证Token令牌是否合法
    /// </summary>
    /// <param name="token">令牌</param>
    /// <param name="appConfig">AppConfig</param>
    /// <returns>CheckResult</returns>
    ApiResult<string> CheckIdentityToken(string token, AppConfig appConfig); #endregion Methods
    }
  2. 基于Jwt鉴权实现

    /// <summary>
    /// 基于Jwt 授权验证实现
    /// </summary>
    public sealed class JwtApiAuthenticate : IApiAuthenticate
    {
    /// <summary>
    /// 检查Token是否合法
    /// </summary>
    /// <param name="token">用户令牌</param>
    /// <param name="appConfig">AppConfig</param>
    /// <returns></returns>
    public ApiResult<string> CheckIdentityToken(string token, AppConfig appConfig)
    {
    ValidateOperator.Begin()
    .NotNullOrEmpty(token, "Token")
    .NotNull(appConfig, "AppConfig");
    try
    {
    var tokenText = ParseTokens(token, appConfig.SharedKey);
    if (string.IsNullOrEmpty(tokenText))
    return ApiResult<string>.Fail("用户令牌Token为空"); dynamic root = JObject.Parse(tokenText);
    string userid = root.iss;
    double iat = root.iat;
    var validTokenExpired =
    new TimeSpan((int) (UnixEpochHelper.GetCurrentUnixTimestamp().TotalSeconds - iat))
    .TotalDays > appConfig.TokenExpiredDay;
    return validTokenExpired
    ? ApiResult<string>.Fail($"用户ID{userid}令牌失效")
    : ApiResult<string>.Success(userid);
    }
    catch (FormatException)
    {
    return ApiResult<string>.Fail("用户令牌非法");
    }
    catch (SignatureVerificationException)
    {
    return ApiResult<string>.Fail("用户令牌非法");
    }
    } /// <summary>
    /// 转换Token
    /// </summary>
    /// <param name="token">令牌</param>
    /// <param name="secret">密钥</param>
    /// <returns>Token以及负载数据</returns>
    private string ParseTokens(string token, string secret)
    {
    ValidateOperator.Begin()
    .NotNullOrEmpty(token, "令牌")
    .NotNullOrEmpty(secret, "密钥"); IJsonSerializer serializer = new JsonNetSerializer();
    IDateTimeProvider provider = new UtcDateTimeProvider();
    IJwtValidator validator = new JwtValidator(serializer, provider);
    IBase64UrlEncoder urlEncoder = new JwtBase64UrlEncoder();
    IJwtDecoder decoder = new JwtDecoder(serializer, validator, urlEncoder);
    return decoder.Decode(token, secret, true);
    }
    }

授权与鉴权使用

  1. 授权使用,通过Controller构造函数方式,代码如下

    /// <summary>
    /// Api授权
    /// </summary>
    public abstract class AuthorizeController : ApiBaseController
    {
    #region Constructors /// <summary>
    /// 构造函数
    /// </summary>
    /// <param name="apiAuthorize">IApiAuthorize</param>
    /// <param name="appCfgService">IAppConfigService</param>
    protected AuthorizeController(IApiAuthorize apiAuthorize, IAppConfigService appCfgService)
    {
    ValidateOperator.Begin()
    .NotNull(apiAuthorize, "IApiAuthorize")
    .NotNull(appCfgService, "IAppConfigService");
    ApiAuthorize = apiAuthorize;
    AppCfgService = appCfgService;
    } #endregion Constructors #region Fields /// <summary>
    /// 授权接口
    /// </summary>
    protected readonly IApiAuthorize ApiAuthorize; /// <summary>
    /// 请求通道配置信息,可以从文件或者数据库获取
    /// </summary>
    protected readonly IAppConfigService AppCfgService; #endregion Fields #region Methods /// <summary>
    /// 创建合法用户的Token
    /// </summary>
    /// <param name="userId">用户Id</param>
    /// <param name="passWord">用户密码</param>
    /// <param name="signature">加密签名字符串</param>
    /// <param name="timestamp">时间戳</param>
    /// <param name="nonce">随机数</param>
    /// <param name="appid">应用接入ID</param>
    /// <returns>OperatedResult</returns>
    protected virtual ApiResult<IdentityToken> CreateIdentityToken(string userId, string passWord,
    string signature, string timestamp,
    string nonce, Guid appid)
    {
    #region 参数检查 var checkResult = CheckRequest(userId, passWord, signature, timestamp, nonce, appid); if (!checkResult.State)
    return ApiResult<IdentityToken>.Fail(checkResult.Message); #endregion #region 用户鉴权 var getIdentityUser = GetIdentityUser(userId, passWord); if (!getIdentityUser.State) return ApiResult<IdentityToken>.Fail(getIdentityUser.Message); #endregion #region 请求通道检查 var getAppConfig = AppCfgService.Get(appid); if (!getAppConfig.State) return ApiResult<IdentityToken>.Fail(getAppConfig.Message);
    var appConfig = getAppConfig.Data; #endregion #region 检查请求签名检查 var checkSignatureResult = ApiAuthorize.CheckRequestSignature(signature, timestamp, nonce, appConfig);
    if (!checkSignatureResult.State) return ApiResult<IdentityToken>.Fail(checkSignatureResult.Message); #endregion #region 生成基于Jwt Token var getTokenResult = ApiAuthorize.CreateIdentityToken(getIdentityUser.Data, getAppConfig.Data);
    if (!getTokenResult.State) return ApiResult<IdentityToken>.Fail(getTokenResult.Message); return ApiResult<IdentityToken>.Success(getTokenResult.Data); #endregion
    } /// <summary>
    /// 检查用户的合法性
    /// </summary>
    /// <param name="userId">用户Id</param>
    /// <param name="passWord">用户密码</param>
    /// <returns>UserInfo</returns>
    protected abstract CheckResult<IdentityUser> GetIdentityUser(string userId, string passWord); private CheckResult CheckRequest(string userId, string passWord, string signature, string timestamp,
    string nonce, Guid appid)
    {
    if (string.IsNullOrEmpty(userId) || string.IsNullOrEmpty(passWord))
    return CheckResult.Fail("用户名或密码为空"); if (string.IsNullOrEmpty(signature))
    return CheckResult.Fail("请求签名为空"); if (string.IsNullOrEmpty(timestamp))
    return CheckResult.Fail("时间戳为空"); if (string.IsNullOrEmpty(nonce))
    return CheckResult.Fail("随机数为空"); if (appid == Guid.Empty)
    return CheckResult.Fail("应用接入ID非法"); return CheckResult.Success();
    } #endregion Methods
    }
  2. 鉴权使用,通过AuthorizationFilterAttribute形式,标注请求是否需要鉴权

    /// <summary>
    /// WebApi 授权验证实现
    /// </summary>
    [AttributeUsage(AttributeTargets.Method)]
    public abstract class AuthenticateAttribute : AuthorizationFilterAttribute
    {
    #region Constructors /// <summary>
    /// 构造函数
    /// </summary>
    /// <param name="apiAuthenticate">IApiAuthenticate</param>
    /// <param name="appCfgService">appCfgService</param>
    protected AuthenticateAttribute(IApiAuthenticate apiAuthenticate, IAppConfigService appCfgService)
    {
    ValidateOperator.Begin()
    .NotNull(apiAuthenticate, "IApiAuthenticate")
    .NotNull(appCfgService, "IAppConfigService");
    ApiAuthenticate = apiAuthenticate;
    AppCfgService = appCfgService;
    } #endregion Constructors #region Fields /// <summary>
    /// 授权验证接口
    /// </summary>
    protected readonly IApiAuthenticate ApiAuthenticate; /// <summary>
    /// 请求通道配置信息,可以从文件或者数据库获取
    /// </summary>
    protected readonly IAppConfigService AppCfgService; #endregion Fields #region Methods /// <summary>
    /// 验证Token令牌是否合法
    /// </summary>
    /// <param name="token">令牌</param>
    /// <param name="appid">应用ID</param>
    /// <returns>CheckResult</returns>
    protected virtual ApiResult<string> CheckIdentityToken(string token, Guid appid)
    {
    #region 请求参数检查 var checkResult = CheckRequest(token, appid); if (!checkResult.State)
    return ApiResult<string>.Fail(checkResult.Message); #endregion #region 请求通道检查 var getAppConfig = AppCfgService.Get(appid); if (!getAppConfig.State) return ApiResult<string>.Fail(getAppConfig.Message);
    var appConfig = getAppConfig.Data; #endregion return ApiAuthenticate.CheckIdentityToken(token, appConfig);
    } private CheckResult CheckRequest(string token, Guid appid)
    {
    if (string.IsNullOrEmpty(token))
    return CheckResult.Fail("用户令牌为空");
    return Guid.Empty == appid ? CheckResult.Fail("应用ID非法") : CheckResult.Success();
    } #endregion Methods
    }

基于请求缓存处理

  1. 通过ICacheProvider接口,可以扩展缓存数据方式;

  2. 通过配置DependsOnIdentity参数,可以配置是否依赖Token令牌进行缓存;

  3. 通过配置CacheMinutes参数,可以指定具体接口缓存时间,当设置0的时候不启用缓存;

  4. 通过实现ControllerCacheAttribute,可以在不同项目快速达到接口缓存功能;

    public class RequestCacheAttribute : ControllerCacheAttribute
    {
    public RequestCacheAttribute(int cacheMinutes) : this(cacheMinutes, true, new LocalCacheProvider())
    {
    } public RequestCacheAttribute(int cacheMinutes, bool dependsOnIdentity, ICacheProvider cacheProvider) : base(
    cacheMinutes, dependsOnIdentity, cacheProvider)
    {
    } protected override bool CheckedResponseAvailable(HttpActionContext context, string responseText)
    {
    return !string.IsNullOrEmpty(responseText) && context != null;
    } protected override string GetIdentityToken(HttpActionContext actionContext)
    {
    return actionContext.Request.GetUriOrHeaderValue("Access_token").ToStringOrDefault(string.Empty);
    }
    }

异常处理

  1. 通过实现ControllerExceptionAttribute,可以轻松简单构建接口请求时候异常发生,并通过HttpRequestRaw requestRaw参数,可以获取非常详尽的请求信息;

    public sealed class ExceptionLogAttribute : ControllerExceptionAttribute
    {
    public override void OnActionExceptioning(HttpActionExecutedContext actionExecutedContext, string actionName,
    HttpStatusCode statusCode,
    HttpRequestRaw requestRaw)
    {
    var response = new HttpResponseMessage
    {
    Content = new StringContent("发生故障,请稍后重试!"),
    StatusCode = statusCode
    };
    actionExecutedContext.Response = response;
    }
    }

参数验证

  1. 通过实现ValidateModelAttribute,以及DataAnnotations快速构建请求参数验证

  2. 请求参数只需要DataAnnotations标注即可;

    public sealed class ArticleRequest
    {
    [Required(ErrorMessage = "缺少文章ID")]
    public int Id
    {
    get;
    set;
    } }
  3. 项目实现ValidateModelAttribute,可以自定义构建参数处理方式

    /// <summary>
    /// 请求参数
    /// </summary>
    public sealed class ValidateRequestAttribute : ValidateModelAttribute
    {
    public override void OnParameterIsNulling(HttpActionContext actionContext)
    {
    actionContext.Response =
    actionContext.Request.CreateResponse(HttpStatusCode.BadRequest, OperatedResult<string>.Fail("请求参数非法。"));
    } public override void OnParameterInvaliding(HttpActionContext actionContext, ValidationFailedResult result)
    {
    var message = result.Data.FirstOrDefault()?.Message;
    actionContext.Response =
    actionContext.Request.CreateResponse(HttpStatusCode.BadRequest, OperatedResult<string>.Fail(message));
    }
    }

[开源]快速构建一个WebApi项目的更多相关文章

  1. springboot:快速构建一个springboot项目

    前言: springboot作为springcloud的基础,springboot的热度一直很高,所以就有了这个springboot系列,花些时间来了解和学习为自己做技术储备,以备不时之需[手动滑稽] ...

  2. 快速构建一个vue项目

    首先介绍一下命令行构建一个vue项目步骤: 1.下载安装node.js(直接运行安装包根据步骤安装完),打开命令行输入:node -v ,出现版本号即安装成功. 2.命令行界面输入:cnpm inst ...

  3. 快速构建一个springboot项目(一)

     前言: springcloud是新一代的微服务框架而springboot作为springcloud的基础,很有必要对springboot深入学习一下. springboot能做什么? (1)spri ...

  4. 【springBoot】之快速构建一个web项目

    基于maven,首先看pom文件 <parent> <groupId>org.springframework.boot</groupId> <artifact ...

  5. 快速构建一个简单的单页vue应用

    技术栈 vue-cli webpack vux,vux-loader less,less-loader vue-jsonp vue-scroller ES6 vue-cli:一个vue脚手架工具,利用 ...

  6. 利用 vue-cli 构建一个 Vue 项目

    一.项目初始构建 现在如果要构建一个 Vue 的项目,最方便的方式,莫过于使用官方的 vue-cli . 首先,咱们先来全局安装 vue-cli ,打开命令行工具,输入以下命令: $ npm inst ...

  7. Eclipse的maven构建一个web项目,以构建SpringMVC项目为例

    http://www.cnblogs.com/javaTest/archive/2012/04/28/2589574.html springmvc demo实例教程源代码下载:http://zuida ...

  8. 【jQuery插件】用jQuery Masonry快速构建一个pinterest网站布局(转)

    [jQuery插件]用jQuery Masonry快速构建一个pinterest网站布局 时间:2011年03月21日作者:愚人码头查看次数:29,744 views评论次数:25条评论 前段时间领导 ...

  9. jenkins构建一个maven项目[五]

    标签(linux): jenkins 笔者Q:972581034 交流群:605799367.有任何疑问可与笔者或加群交流 构建一个maven项目,即为构建java项目.模拟实验之前先把实验代码推送到 ...

随机推荐

  1. VMware workstation pro 15 安装Ubuntu(图文教程)

    今天分享一下虚拟机安装Ubuntu的过程,在开始安装之前,需要下载VMware workstation pro和Ubuntu镜像,两者我都用的最新版,由于VMware workstation pro ...

  2. RSP小组——消消乐

    RSP小组--消消乐 团队所有博客总结 1.团队第一周作业 2.团队第二周作业 3.RSP小组--团队冲刺博客一 4.RSP小组--团队冲刺博客二 5.RSP小组--团队冲刺博客三 6.RSP小组-- ...

  3. Create and test an approval workflow with Microsoft Flow

    https://docs.microsoft.com/zh-cn/flow/getting-started https://docs.microsoft.com/en-us/flow/modern-a ...

  4. RDD算子

    RDD算子 #常用Transformation(即转换,延迟加载) #通过并行化scala集合创建RDD val rdd1 = sc.parallelize(Array(1,2,3,4,5,6,7,8 ...

  5. SQL Server数据库可能遇到的报错

    1.操作附加操作时报错: 可能的解决方法: 退出数据库,换Windows身份验证登录,就可以了 2.插入语句报错: 1) 2)

  6. swust oj 1051

    输出利用先序遍历创建的二叉树中的指定结点的孩子结点 1000(ms) 10000(kb) 2432 / 5430 利用先序递归遍历算法创建二叉树并输出该二叉树中指定结点的儿子结点.约定二叉树结点数据为 ...

  7. idea导入maven项目,找不到jar包,出现红色波浪线【转】

    参考链接 点击跳转

  8. SSIS - 5.优先约束

      一.优先约束和执行逻辑 任务和容器是SSIS中的可执行文件,一个优先约束连接着两个可执行文件:优先的可执行文件和约束的可执行文件,如下图. 它的执行逻辑如下图: 1)先执行优先可执行文件 2)判断 ...

  9. Data Center手册(3): Load Balancer

    Load Balancer的类型 DNS Round-Robin 这是一种很常见的分流的方式,具体配置如下: name server有一个zone文件,对于同一个domain,有多个IP www.ex ...

  10. 使用Kubeadm(1.13+)快速搭建Kubernetes集群

    Kubeadm是管理集群生命周期的重要工具,从创建到配置再到升级,Kubeadm处理现有硬件上的生产集群的引导,并以最佳实践方式配置核心Kubernetes组件,以便为新节点提供安全而简单的连接流程并 ...