Startup.cs 6.6 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153
  1. using System;
  2. using System.Collections.Generic;
  3. using System.ServiceModel;
  4. using Microsoft.AspNetCore.Builder;
  5. using Microsoft.AspNetCore.Hosting;
  6. using Microsoft.AspNetCore.Http;
  7. using Microsoft.AspNetCore.Http.Features;
  8. using Microsoft.AspNetCore.Rewrite;
  9. using Microsoft.AspNetCore.StaticFiles;
  10. using Microsoft.Extensions.Configuration;
  11. using Microsoft.Extensions.DependencyInjection;
  12. using Microsoft.Extensions.FileProviders;
  13. using Microsoft.Extensions.Hosting;
  14. using System.Text;
  15. using Microsoft.IdentityModel.Tokens;
  16. using System.Linq;
  17. using Microsoft.AspNetCore.Server.Kestrel.Core;
  18. namespace MySystem
  19. {
  20. public class Startup
  21. {
  22. public Startup(IConfiguration configuration)
  23. {
  24. Configuration = configuration;
  25. }
  26. public IConfiguration Configuration { get; }
  27. // This method gets called by the runtime. Use this method to add services to the container.s
  28. public void ConfigureServices(IServiceCollection services)
  29. {
  30. services.AddControllersWithViews();
  31. services.AddRouting(options =>
  32. {
  33. options.LowercaseUrls = true;
  34. });
  35. services.AddSingleton<IHttpContextAccessor, HttpContextAccessor>();
  36. services.Configure<Setting>(Configuration.GetSection("Setting"));
  37. // 测试完成后必须注释掉
  38. // services.AddCors(option => option.AddPolicy("cors", policy => policy.AllowAnyHeader().AllowAnyMethod().AllowCredentials().SetIsOriginAllowed(_ => true)));//是否允许跨域
  39. // 测试完成后必须注释掉
  40. services.Configure<KestrelServerOptions>(x => x.AllowSynchronousIO = true).Configure<IISServerOptions>(x => x.AllowSynchronousIO = true);
  41. services.AddMvc(options =>
  42. {
  43. options.EnableEndpointRouting = false;
  44. options.Filters.Add(typeof(GlobalExceptions));
  45. });
  46. services.AddSession(options =>
  47. {
  48. // 设置 Session 过期时间
  49. options.IdleTimeout = TimeSpan.FromHours(1);
  50. options.Cookie.HttpOnly = true;
  51. });
  52. services.Configure<FormOptions>(x =>
  53. {
  54. x.MultipartBodyLengthLimit = 50 * 1024 * 1024;//不到300M
  55. });
  56. //生成密钥
  57. var symmetricKeyAsBase64 = Configuration["Setting:JwtSecret"];
  58. var keyByteArray = Encoding.ASCII.GetBytes(symmetricKeyAsBase64);
  59. var signingKey = new SymmetricSecurityKey(keyByteArray);
  60. //认证参数
  61. services.AddAuthentication("Bearer").AddJwtBearer(o =>
  62. {
  63. o.TokenValidationParameters = new TokenValidationParameters
  64. {
  65. ValidateIssuerSigningKey = true,//是否验证签名,不验证的画可以篡改数据,不安全
  66. IssuerSigningKey = signingKey,//解密的密钥
  67. ValidateIssuer = true,//是否验证发行人,就是验证载荷中的Iss是否对应ValidIssuer参数
  68. // ValidIssuer = Configuration["Setting:JwtIss"],//发行人
  69. IssuerValidator = (m, n, z) =>
  70. {
  71. return n.Issuer;
  72. },
  73. ValidateAudience = true,//是否验证订阅人,就是验证载荷中的Aud是否对应ValidAudience参数
  74. // ValidAudience = Configuration["Setting:JwtAud"],//订阅人
  75. AudienceValidator = (m, n, z) =>
  76. {
  77. // if(n.Issuer.StartsWith("new_"))
  78. // {
  79. string check = RedisDbconn.Instance.Get<string>("utoken:" + n.Issuer);
  80. return m != null && m.FirstOrDefault().Equals(check);
  81. // }
  82. // else
  83. // {
  84. // string check = RedisDbconn.Instance.Get<string>("utoken:" + n.Issuer);
  85. // return m != null && m.FirstOrDefault().Equals(check);
  86. // }
  87. },
  88. ValidateLifetime = true,//是否验证过期时间,过期了就拒绝访问
  89. ClockSkew = TimeSpan.Zero,//这个是缓冲过期时间,也就是说,即使我们配置了过期时间,这里也要考虑进去,过期时间+缓冲,默认好像是7分钟,你可以直接设置为0
  90. RequireExpirationTime = true,
  91. };
  92. });
  93. //services.AddHttpContextAccessor();
  94. // 必须打开
  95. // services.AddHostedService<SycnStartService>();
  96. // 必须打开
  97. MySystemLib.SystemPublicFuction.appcheck = "success";
  98. }
  99. // This method gets called by the runtime. Use this method to configure the HTTP request pipeline.
  100. public void Configure(IApplicationBuilder app, IWebHostEnvironment env)
  101. {
  102. if (env.IsDevelopment())
  103. {
  104. app.UseDeveloperExceptionPage();
  105. }
  106. else
  107. {
  108. app.UseHsts();
  109. }
  110. Library.function.WritePage("/", "WebRootPath.txt", env.WebRootPath);
  111. app.UseStaticFiles();
  112. app.UseStaticFiles(new StaticFileOptions
  113. {
  114. FileProvider = new PhysicalFileProvider(AppContext.BaseDirectory + "/static"),
  115. RequestPath = "/static"
  116. });
  117. // app.UseStaticFiles(new StaticFileOptions
  118. // {
  119. // FileProvider = new PhysicalFileProvider(AppContext.BaseDirectory + "/" + Configuration["Setting:Database"]),
  120. // RequestPath = "/" + Configuration["Setting:Database"]
  121. // });
  122. app.UseStaticFiles(new StaticFileOptions
  123. {
  124. ContentTypeProvider = new FileExtensionContentTypeProvider(new Dictionary<string, string>
  125. {
  126. { ".apk", "application/vnd.android.package-archive" }
  127. })
  128. });
  129. app.UseCors("cors");
  130. app.UseAuthentication();
  131. app.UseRouting();
  132. app.UseAuthorization();
  133. app.UseSession();
  134. app.UseEndpoints(endpoints =>
  135. {
  136. endpoints.MapControllerRoute(
  137. name: "default",
  138. pattern: "{controller=Home}/{action=Index}/{Id?}");
  139. });
  140. }
  141. }
  142. }