.NET Core 7 API中JWT在jwt.io显示‘Invalid Signature’求助
.NET Core 7 API中JWT令牌签名无效问题排查
我在.NET Core 7 API解决方案中实现JWT令牌的生成与验证功能,但在jwt.io调试工具中查看令牌详情时,出现了Invalid Signature(无效签名)错误。
已尝试的解决方案:
- 使用Base64编码的密钥作为密钥
- 勾选/取消勾选‘secret base64 encoded’复选框
- 在Appsettings.json文件中将JWT密钥转换为Base64格式
恳请各位帮忙指出问题所在,提前致谢 :)
代码片段
创建JWT令牌方法
private string CreateJWTToken(User user) { List<Claim> claims = new List<Claim>{ new Claim(ClaimTypes.Name, user.UserName) // new Claim(ClaimTypes.Role,"AssignSomeRole"), }; var SymmetricKey = new SymmetricSecurityKey( Encoding.UTF8.GetBytes(_configuration.GetSection("JWT:secret").Value!)); var SigningCredentials = new SigningCredentials(SymmetricKey, SecurityAlgorithms.HmacSha256Signature); var JwtTokenForUser = new JwtSecurityToken( issuer: "http://localhost:5255", audience: "", claims: claims, null, expires: DateTime.Now.AddDays(1), signingCredentials: SigningCredentials ); var jwt = new JwtSecurityTokenHandler().WriteToken(JwtTokenForUser); return jwt; }
Program.cs中的配置
builder.Services.AddAuthentication(JwtBearerDefaults.AuthenticationScheme).AddJwtBearer(options => { options.TokenValidationParameters = new TokenValidationParameters { ValidateIssuerSigningKey = true, IssuerSigningKey = new SymmetricSecurityKey( Encoding.UTF8.GetBytes( builder.Configuration.GetSection("JWT:secret").Value!)) }; });
AppSettings.json配置
"JWT": { "secret": "trytrytrytrytrytrytrytrytrytrytrytrytrytrytrytry", "issuer": "http://localhost:5255", "audience": "http://localhost:5255" }
内容的提问来源于stack exchange,提问作者Catalyst
相关产品推荐
相关产品推荐

