7
7
using System . Threading . Tasks ;
8
8
using Microsoft . Extensions . Logging ;
9
9
using Serilog . Sinks . SystemConsole . Themes ;
10
+ using System . IdentityModel . Tokens . Jwt ;
11
+ using System . Security . Claims ;
12
+ using IdentityModel ;
13
+ using Microsoft . IdentityModel . Tokens ;
14
+ using IdentityModel . Client ;
10
15
11
16
namespace ConsoleClientWithBrowser
12
17
{
@@ -29,17 +34,62 @@ public static async Task Main()
29
34
await SignIn ( ) ;
30
35
}
31
36
37
+ private static string rsaKey =
38
+ "{" +
39
+ "\" d\" :\" GmiaucNIzdvsEzGjZjd43SDToy1pz-Ph-shsOUXXh-dsYNGftITGerp8bO1iryXh_zUEo8oDK3r1y4klTonQ6bLsWw4ogjLPmL3yiqsoSjJa1G2Ymh_RY_sFZLLXAcrmpbzdWIAkgkHSZTaliL6g57vA7gxvd8L4s82wgGer_JmURI0ECbaCg98JVS0Srtf9GeTRHoX4foLWKc1Vq6NHthzqRMLZe-aRBNU9IMvXNd7kCcIbHCM3GTD_8cFj135nBPP2HOgC_ZXI1txsEf-djqJj8W5vaM7ViKU28IDv1gZGH3CatoysYx6jv1XJVvb2PH8RbFKbJmeyUm3Wvo-rgQ\" ," +
40
+ "\" dp\" :\" YNjVBTCIwZD65WCht5ve06vnBLP_Po1NtL_4lkholmPzJ5jbLYBU8f5foNp8DVJBdFQW7wcLmx85-NC5Pl1ZeyA-Ecbw4fDraa5Z4wUKlF0LT6VV79rfOF19y8kwf6MigyrDqMLcH_CRnRGg5NfDsijlZXffINGuxg6wWzhiqqE\" ," +
41
+ "\" dq\" :\" LfMDQbvTFNngkZjKkN2CBh5_MBG6Yrmfy4kWA8IC2HQqID5FtreiY2MTAwoDcoINfh3S5CItpuq94tlB2t-VUv8wunhbngHiB5xUprwGAAnwJ3DL39D2m43i_3YP-UO1TgZQUAOh7Jrd4foatpatTvBtY3F1DrCrUKE5Kkn770M\" ," +
42
+ "\" e\" :\" AQAB\" ," +
43
+ "\" kid\" :\" ZzAjSnraU3bkWGnnAqLapYGpTyNfLbjbzgAPbbW2GEA\" ," +
44
+ "\" kty\" :\" RSA\" ," +
45
+ "\" n\" :\" wWwQFtSzeRjjerpEM5Rmqz_DsNaZ9S1Bw6UbZkDLowuuTCjBWUax0vBMMxdy6XjEEK4Oq9lKMvx9JzjmeJf1knoqSNrox3Ka0rnxXpNAz6sATvme8p9mTXyp0cX4lF4U2J54xa2_S9NF5QWvpXvBeC4GAJx7QaSw4zrUkrc6XyaAiFnLhQEwKJCwUw4NOqIuYvYp_IXhw-5Ti_icDlZS-282PcccnBeOcX7vc21pozibIdmZJKqXNsL1Ibx5Nkx1F1jLnekJAmdaACDjYRLL_6n3W4wUp19UvzB1lGtXcJKLLkqB6YDiZNu16OSiSprfmrRXvYmvD8m6Fnl5aetgKw\" ," +
46
+ "\" p\" :\" 7enorp9Pm9XSHaCvQyENcvdU99WCPbnp8vc0KnY_0g9UdX4ZDH07JwKu6DQEwfmUA1qspC-e_KFWTl3x0-I2eJRnHjLOoLrTjrVSBRhBMGEH5PvtZTTThnIY2LReH-6EhceGvcsJ_MhNDUEZLykiH1OnKhmRuvSdhi8oiETqtPE\" ," +
47
+ "\" q\" :\" 0CBLGi_kRPLqI8yfVkpBbA9zkCAshgrWWn9hsq6a7Zl2LcLaLBRUxH0q1jWnXgeJh9o5v8sYGXwhbrmuypw7kJ0uA3OgEzSsNvX5Ay3R9sNel-3Mqm8Me5OfWWvmTEBOci8RwHstdR-7b9ZT13jk-dsZI7OlV_uBja1ny9Nz9ts\" ," +
48
+ "\" qi\" :\" pG6J4dcUDrDndMxa-ee1yG4KjZqqyCQcmPAfqklI2LmnpRIjcK78scclvpboI3JQyg6RCEKVMwAhVtQM6cBcIO3JrHgqeYDblp5wXHjto70HVW6Z8kBruNx1AH9E8LzNvSRL-JVTFzBkJuNgzKQfD0G77tQRgJ-Ri7qu3_9o1M4\" " +
49
+ "}" ;
50
+
51
+ private static string CreateClientToken ( SigningCredentials credential , string clientId , string audience )
52
+ {
53
+ var now = DateTime . UtcNow ;
54
+
55
+ var token = new JwtSecurityToken (
56
+ clientId ,
57
+ audience ,
58
+ new List < Claim > ( )
59
+ {
60
+ new Claim ( JwtClaimTypes . JwtId , Guid . NewGuid ( ) . ToString ( ) ) ,
61
+ new Claim ( JwtClaimTypes . Subject , clientId ) ,
62
+ new Claim ( JwtClaimTypes . IssuedAt , now . ToEpochTime ( ) . ToString ( ) , ClaimValueTypes . Integer64 )
63
+ } ,
64
+ now ,
65
+ now . AddMinutes ( 1 ) ,
66
+ credential
67
+ ) ;
68
+
69
+ var tokenHandler = new JwtSecurityTokenHandler ( ) ;
70
+ return tokenHandler . WriteToken ( token ) ;
71
+ }
72
+
32
73
private static async Task SignIn ( )
33
74
{
34
75
// create a redirect URI using an available port on the loopback address.
35
76
// requires the OP to allow random ports on 127.0.0.1 - otherwise set a static port
36
77
var browser = new SystemBrowser ( ) ;
37
- string redirectUri = string . Format ( $ "http://127.0.0.1:{ browser . Port } ") ;
78
+ var redirectUri = string . Format ( $ "http://127.0.0.1:{ browser . Port } ") ;
79
+ var authority = "https://demo.duendesoftware.com" ;
80
+
81
+ var jwk = new JsonWebKey ( rsaKey ) ;
82
+ var credential = new SigningCredentials ( jwk , "RS256" ) ;
38
83
39
84
var options = new OidcClientOptions
40
85
{
41
- Authority = "https://demo.duendesoftware.com" ,
42
- ClientId = "interactive.public.short" ,
86
+ Authority = authority ,
87
+ ClientId = "interactive.confidential.short.jwt" ,
88
+ GetClientAssertionAsync = ( ) => Task . FromResult ( new ClientAssertion
89
+ {
90
+ Type = OidcConstants . ClientAssertionTypes . JwtBearer ,
91
+ Value = CreateClientToken ( credential , "interactive.confidential.short.jwt" , authority )
92
+ } ) ,
43
93
RedirectUri = redirectUri ,
44
94
Scope = "openid profile api offline_access" ,
45
95
FilterClaims = false ,
0 commit comments