DotNetOpenAuth令牌响应

时间:2013-03-05 15:22:53

标签: .net oauth-2.0 dotnetopenauth

我一直在使用DotNetOpenAuth创建自己的资源服务器。一切正常,我可以检索令牌罚款。但是,我现在开始构建一个调用我的资源服务器的客户端,并且DotNetOpenAuth返回的响应有一个小问题。我希望DotNetOpenAuth返回一个代表访问令牌的JSON字符串。它这样做,但有一个小警告:JSON字符串以十六进制数字为前缀,后缀为零:

HTTP/1.1 200 OK
Cache-Control: no-cache, no-store, max-age=0, must-revalidate
Pragma: no-cache
Transfer-Encoding: chunked
Content-Type: application/json; charset=utf-8
Server: Microsoft-IIS/8.0
X-AspNetMvc-Version: 4.0
X-AspNet-Version: 4.0.30319
X-SourceFiles: =?UTF-8?B?RDpcUGVyc29vbmxpamtlIHByb2plY3RlblxpY2hlY2ttb3ZpZXMtZG90bmV0XHNyY1xXZWJBcGlcdG9rZW5zXA==?=
X-Powered-By: ASP.NET
Date: Mon, 04 Mar 2013 13:04:12 GMT

3d2
{"access_token":"gAAAADrFpM2DRiBdqVBPdEq_ISvdfZb6CaRMZr7vWcn2AuKGs2TXyNlzLaUX8xtLQfxFdbTYBIK-LF8cfEwvV8gUKC0lpcodb9OWm9sUmu_IIApmMPIBQDgT1LtkEjOsv_gQdmwN906Pd1KczI2O3Pt1DqzhL_Rpub9zJQmh6EKDp4_EJAEAAIAAAACTvB0tYmrRNExdGQhGBrHgYnlgt7Rw-ilB2wLScW1YgOHE6MOY0WrfKG9aFLUAcmADYSrX55n9mfC9NKDXJBARc5ev-hnWTnApw7yq51c1KwbKv7bxoEVzar8eAAFrJi_OBQjlcaN8IFfnryu1VK_C1o-U2gLgdnBZzFcCDhgNseRFjUCmYXssEvjUswg0Oy3c_F_IXpP85kL6QCYmpGwV1juTuiMwMuZOCbcPMAssM70JMi7Ai7zT7hxCCZ5SLgeyLjBqPX7bXnhRIO24mkZ9pN5pCzorjOX_8rqdrPwR6WkPy0tc69oyBTak8L6nJYWzxfuAVhZGEowHCx3KNWfG_R_w23N7Y3c9HoIfO6RSYpnfieGLKhxHxd1_jsczGtM","token_type":"bearer","expires_in":3600,"refresh_token":"q5NN!IAAAANCHUJ5tukpT_UzgkRGCTM4Oy1qgw8GP5wn8HDS2jN1isQAAAAFfLe6KZMht1mmbIbF6RihvMZvjrwtaoZRZbaavPbte9CtjLWB_isHOroLv669rq1PmTppmVyo1Om3HVvp2AC16SDe7l02POHIYbPs_Cox6kekHc74_8pLP8SAGcrXy1EzjAPKc_UksMTp8aqaAnrU3ulx2TYYrRMyYb6pW7awO6_aiHtLixrF6dVA1-6DWvKuCSeJW0oZCm45Op1-wht8qAWkK3B70C6dZU6dmsggleA","scope":"movie list user comment"}
0 

如果我查看官方规范(http://tools.ietf.org/html/draft-ietf-oauth-v2-31#section-4.1.4),它没有说明和前缀和/或后缀。输出是否正确,或者这是DotNetOpenAuth中的错误?令我印象深刻的是没有Content-length标题的响应。这让我相信3d2字符串实际上可能是内容长度。我相信这是如此,因为十六进制中的3d2是十进制的978,这正是3d2和0之间的JSON字符串的长度。

有什么方法可以配置DotNetOpenAuth来返回常规的Content-length头而不输出pre-andfix?

要完成,我使用以下代码(使用依赖注入)在.NET 4.0上的ASP.NET MVC 4应用程序中运行我的授权服务器:

public sealed class TokensController : Controller
{
    private readonly AuthorizationServer authorizationServer;

    public TokensController(AuthorizationServer authorizationServer)
    {
        this.authorizationServer = authorizationServer;
    }

    public ActionResult Create()
    {
        var outgoingWebResponse = this.authorizationServer.HandleTokenRequest(this.Request);
        var asActionResult = outgoingWebResponse.AsActionResult();
        return asActionResult;
    }
} 

1 个答案:

答案 0 :(得分:0)

问题出在DotNetOpenAuth库中,其中Content-length标头未随请求一起发送。这导致添加表示请求长度的十六进制数。报告此错误后,已由DotNetOpenAuth库的作者修复。