使用OpenIddict应用Properties属性的最佳实践咨询
OpenIddict应用元数据存储与代码优化指导
核心场景说明
在OpenIddict应用中使用Properties字段存储应用元数据(而非自定义实体),当前代码可正常运行,但希望优化实现的规范性,尤其是重定向URL的处理逻辑。
具体优化点
1. 重定向URL处理:增强合法性验证与鲁棒性
当前通过空格分割URL并直接构造Uri的方式存在空白项、无效URL风险,优化后:
// 分割时自动移除空白项与首尾空格 var redirectUrls = appDto.RedirectUrls.Split(" ", StringSplitOptions.RemoveEmptyEntries | StringSplitOptions.TrimEntries); foreach (var url in redirectUrls) { // 验证URL是否为合法绝对地址 if (Uri.TryCreate(url, UriKind.Absolute, out var validUri)) { data.RedirectUris.Add(validUri); } else { throw new ArgumentException($"无效的重定向URL: {url}"); } }
优化说明:使用StringSplitOptions避免空字符串干扰,通过Uri.TryCreate确保存入的URL都是有效的绝对地址,提前拦截非法输入。
2. Properties存储与读取:简化逻辑并提升效率
存储优化
将原有的JsonElement序列化改为直接存储JSON字符串,更直观:
data.Properties["IdentityConfig"] = JsonSerializer.Serialize(new AppIdentityProperties { ClientSystemId = appDto.ClientSystemId, CustomerAccountId = appDto.CustomerAccountId });
读取优化
用TryGetValue替代两次集合遍历,提升效率:
if (properties.TryGetValue("IdentityConfig", out var configJson)) { var identityConfig = JsonSerializer.Deserialize<AppIdentityProperties>(configJson); if (identityConfig is not null) { identity.AddClaim(StaticData.Claims.ClientSystem, identityConfig.ClientSystemId.ToString()) .AddClaim(StaticData.Claims.CustomerAccount, identityConfig.CustomerAccountId.ToString()); } }
优化说明:减少序列化层级,避免不必要的集合遍历,代码逻辑更简洁。
3. ClientId生成:提升随机性与合规性
原有用SHA512加密Guid的方式冗余,改为生成高安全随机的Base64Url编码字符串:
using var rng = RandomNumberGenerator.Create(); var clientIdBytes = new byte[32]; rng.GetBytes(clientIdBytes); var clientId = Base64UrlEncoder.Encode(clientIdBytes);
优化说明:使用RandomNumberGenerator生成的随机字节比Guid更具随机性,Base64Url编码符合OAuth客户端ID的URL友好要求。
4. 空值与异常处理:增强代码严谨性
获取应用ID时,增加格式有效性验证:
var appId = await _appManager.GetIdAsync(app); if (string.IsNullOrEmpty(appId) || !Guid.TryParse(appId, out var resultId)) { throw new InvalidOperationException("无法获取有效的应用ID"); } CreateOpenIddictAppResponseDto result = new() { Id = resultId, ClientId = clientId, ClientSecret = clientSecret, RedirectUrls = string.Join(" ", await _appManager.GetRedirectUrisAsync(app)) };
优化说明:不仅判断空值,还验证ID是否为有效Guid,避免无效数据流入下游。
5. Claims设置:明确Token存储目标
在添加自定义声明时,直接指定存储目标为AccessToken,避免逻辑混淆:
identity.AddClaim(StaticData.Claims.ClientSystem, identityConfig.ClientSystemId.ToString(), Destinations.AccessToken) .AddClaim(StaticData.Claims.CustomerAccount, identityConfig.CustomerAccountId.ToString(), Destinations.AccessToken);
优化说明:自定义业务声明无需存入IdentityToken,直接指定目标Token类型,逻辑更清晰。
内容的提问来源于stack exchange,提问作者tappetyclick
相关产品推荐
相关产品推荐

