« AWS SDK for .NET » : différence entre les versions

De Banane Atomic
Aller à la navigationAller à la recherche
Aucun résumé des modifications
Ligne 4 : Ligne 4 :
* [https://aws.amazon.com/blogs/modernizing-with-aws/how-to-load-net-configuration-from-aws-secrets-manager/ Load .NET configuration from Secrets Manager]
* [https://aws.amazon.com/blogs/modernizing-with-aws/how-to-load-net-configuration-from-aws-secrets-manager/ Load .NET configuration from Secrets Manager]


= [https://docs.aws.amazon.com/sdk-for-net/v3/developer-guide/creds-idc.html#idc-config-sdk Configure the SDK to use IAM Identity Center] =
= [https://docs.aws.amazon.com/sdkref/latest/guide/file-format.html#file-format-creds Credentials] =
<filebox fn='∼/.aws/config' lang='ini'>
<filebox fn='∼/.aws/credentials' lang='ini'>
[default]
[default]
sso_session = my-sso
aws_access_key_id=...
sso_account_id = 111122223333
aws_secret_access_key=...
sso_role_name = SampleRole
aws_session_token=...
region = us-east-1
output = json


[sso-session my-sso]
[profile1]
sso_region = us-east-1
key=value
sso_start_url = https://provided-domain.awsapps.com/start
sso_registration_scopes = sso:account:access
</filebox>
</filebox>



Version du 26 février 2024 à 13:51

Secrets Manager

Credentials

∼/.aws/credentials
[default]
aws_access_key_id=...
aws_secret_access_key=...
aws_session_token=...

[profile1]
key=value

Cognito

Program.cs
builder.Services.AddCognitoIdentity();
builder.Services.AddAuthentication(options =>
{
    options.DefaultAuthenticateScheme = JwtBearerDefaults.AuthenticationScheme;
    options.DefaultChallengeScheme = JwtBearerDefaults.AuthenticationScheme;
})
.AddJwtBearer(options =>
{
    options.Authority = builder.Configuration["AWSCognito:Authority"];
    options.Audience = builder.Configuration["AWSCognito:UserPoolClientId"];
    options.TokenValidationParameters = new TokenValidationParameters
    {
        ValidateIssuerSigningKey = true,
        ValidateAudience = true
    };
    options.TokenValidationParameters.AudienceValidator = (audiences, securityToken, validationParameters) =>
    {
        // Cognito tokens doesn't have "aud" claim. Instead the audience is set in "client_id"
        var jsonWebToken = (Microsoft.IdentityModel.JsonWebTokens.JsonWebToken)securityToken;
        if (!jsonWebToken.Claims.Any(f => f.Type == "aud"))
            return false;
        return validationParameters.ValidAudience.Contains(jsonWebToken.Claims.First(f => f.Type == "aud").Value);
    };
});