| | 1 | | // Copyright (c) Microsoft Corporation. All rights reserved. |
| | 2 | | // Licensed under the MIT License. |
| | 3 | |
|
| | 4 | | using System; |
| | 5 | | using System.Collections.Generic; |
| | 6 | | using System.Globalization; |
| | 7 | | using System.Net; |
| | 8 | | using System.Security.Cryptography; |
| | 9 | | using System.Text; |
| | 10 | |
|
| | 11 | | namespace Azure.Iot.Hub.Service.Authentication |
| | 12 | | { |
| | 13 | | /// <summary> |
| | 14 | | /// Builds the shared access signature based on the access policy passed. |
| | 15 | | /// </summary> |
| | 16 | | internal class SharedAccessSignatureBuilder |
| | 17 | | { |
| 164 | 18 | | internal string SharedAccessPolicy { get; set; } |
| | 19 | |
|
| 164 | 20 | | internal string SharedAccessKey { get; set; } |
| | 21 | |
|
| 164 | 22 | | internal string HostName { get; set; } |
| | 23 | |
|
| 164 | 24 | | internal TimeSpan TimeToLive { get; set; } |
| | 25 | |
|
| | 26 | | internal string ToSignature() |
| | 27 | | { |
| 82 | 28 | | return BuildSignature(SharedAccessPolicy, SharedAccessKey, HostName, TimeToLive); |
| | 29 | | } |
| | 30 | |
|
| | 31 | | private static string BuildSignature(string sharedAccessPolicy, string sharedAccessKey, string hostName, TimeSpa |
| | 32 | | { |
| 82 | 33 | | string expiresOn = BuildExpiresOn(timeToLive); |
| 82 | 34 | | string audience = WebUtility.UrlEncode(hostName); |
| 82 | 35 | | var fields = new List<string> |
| 82 | 36 | | { |
| 82 | 37 | | audience, |
| 82 | 38 | | expiresOn |
| 82 | 39 | | }; |
| | 40 | |
|
| | 41 | | // Example string to be signed: |
| | 42 | | // dh://myiothub.azure-devices.net/a/b/c?myvalue1=a |
| | 43 | | // <Value for ExpiresOn> |
| | 44 | |
|
| 82 | 45 | | string signature = Sign(string.Join("\n", fields), sharedAccessKey); |
| | 46 | |
|
| | 47 | | // Example returned string: |
| | 48 | | // SharedAccessSignature sr=ENCODED(dh://myiothub.azure-devices.net/a/b/c?myvalue1=a)&sig=<Signature>&se=<Ex |
| | 49 | |
|
| 82 | 50 | | var buffer = new StringBuilder(); |
| 82 | 51 | | buffer.Append($"{SharedAccessSignatureConstants.SharedAccessSignatureIdentifier} " + |
| 82 | 52 | | $"{SharedAccessSignatureConstants.AudienceFieldName}={audience}" + |
| 82 | 53 | | $"&{SharedAccessSignatureConstants.SignatureFieldName}={WebUtility.UrlEncode(signature)}" + |
| 82 | 54 | | $"&{SharedAccessSignatureConstants.ExpiryFieldName}={WebUtility.UrlEncode(expiresOn)}"); |
| | 55 | |
|
| 82 | 56 | | if (!string.IsNullOrWhiteSpace(sharedAccessPolicy)) |
| | 57 | | { |
| 82 | 58 | | buffer.Append($"&{SharedAccessSignatureConstants.KeyNameFieldName}={WebUtility.UrlEncode(sharedAccessPol |
| | 59 | | } |
| | 60 | |
|
| 82 | 61 | | return buffer.ToString(); |
| | 62 | | } |
| | 63 | |
|
| | 64 | | private static string BuildExpiresOn(TimeSpan timeToLive) |
| | 65 | | { |
| 82 | 66 | | DateTimeOffset expiresOn = DateTimeOffset.UtcNow.Add(timeToLive); |
| 82 | 67 | | TimeSpan secondsFromBaseTime = expiresOn.Subtract(SharedAccessSignatureConstants.s_epochTime); |
| 82 | 68 | | long seconds = Convert.ToInt64(secondsFromBaseTime.TotalSeconds, CultureInfo.InvariantCulture); |
| 82 | 69 | | return Convert.ToString(seconds, CultureInfo.InvariantCulture); |
| | 70 | | } |
| | 71 | |
|
| | 72 | | private static string Sign(string requestString, string key) |
| | 73 | | { |
| 82 | 74 | | using (var hmac = new HMACSHA256(Convert.FromBase64String(key))) |
| | 75 | | { |
| 82 | 76 | | return Convert.ToBase64String(hmac.ComputeHash(Encoding.UTF8.GetBytes(requestString))); |
| | 77 | | } |
| 82 | 78 | | } |
| | 79 | | } |
| | 80 | | } |