﻿
{"id":18791,"date":"2020-11-04T23:37:34","date_gmt":"2020-11-04T23:37:34","guid":{"rendered":"https:\/\/www.gencayyildiz.com\/blog\/?p=18791"},"modified":"2020-11-05T01:03:48","modified_gmt":"2020-11-05T01:03:48","slug":"identityserver4-yazi-serisi-12-merkezi-uyelik-sistemi-claim-ve-authentication-propertyleri-okuma","status":"publish","type":"post","link":"https:\/\/www.gencayyildiz.com\/blog\/identityserver4-yazi-serisi-12-merkezi-uyelik-sistemi-claim-ve-authentication-propertyleri-okuma\/","title":{"rendered":"IdentityServer4 Yaz\u0131 Serisi #12 &#8211; Merkezi \u00dcyelik Sistemi &#8211; Claim ve Authentication Propertyleri Okuma"},"content":{"rendered":"<div id=\"fb-root\"><\/div>\n<p>Merhaba,<\/p>\n<p><a href=\"https:\/\/www.gencayyildiz.com\/blog\/identityserver4-yazi-serisi\/\" rel=\"noopener noreferrer\" target=\"_blank\">IdentityServer4 Yaz\u0131 Serisi<\/a>nin bir \u00f6nceki kaleme ald\u0131\u011f\u0131m\u0131z Merkezi \u00dcyelik Sistemi Temelleri ba\u015fl\u0131kl\u0131 makalemizde client&#8217;\u0131n Auth Server&#8217;dan authorization code almas\u0131n\u0131 ba\u015farm\u0131\u015f ve client \u00fczerinde authorize olan k\u0131s\u0131mlara yetkili bir \u015fekilde eri\u015fimi test etmi\u015ftik. Bu i\u00e7eri\u011fimizde ise Auth Server&#8217;dan elde edilen authorization code \u00fczerinde bulunan ve client&#8217;a g\u00f6nderilen claim&#8217;lerin ve &#8216;Authentication Propertyleri&#8217;nin nas\u0131l okundu\u011funu\/elde edildi\u011fini inceleyece\u011fiz.<\/p>\n<p>\u00d6ncelikle Claim ve Authentication Property terimlerinin ne oldu\u011funu a\u00e7\u0131klayarak ba\u015flayal\u0131m;<\/p>\n<ul>\n<li><strong>Claim Nedir?<\/strong><br \/>\n\u00d6nceden klavyeye alm\u0131\u015f oldu\u011fumuz <a href=\"https:\/\/www.gencayyildiz.com\/blog\/asp-net-core-identity-claim-bazli-kimlik-dogrulama-xvii\/\" rel=\"noopener noreferrer\" target=\"_blank\">Claim Bazl\u0131 Kimlik Do\u011frulama<\/a> ba\u015fl\u0131kl\u0131 yaz\u0131m\u0131zda yahut bu serinin d\u00f6rd\u00fcnc\u00fc makalesi olan <a href=\"https:\/\/www.gencayyildiz.com\/blog\/identityserver4-yazi-serisi-4-cleam-bazli-yetkilendirme\/\" rel=\"noopener noreferrer\" target=\"_blank\">IdentityServer4 Cleam Bazl\u0131 Yetkilendirme<\/a> ba\u015fl\u0131kl\u0131 i\u00e7eri\u011fimizde claim hakk\u0131nda yeterlice hasbihalde bulunmu\u015ftuk. Dolay\u0131s\u0131yla \u015fuana kadar claim&#8217;in ne oldu\u011funu \u00e7ok iyi bilmeniz y\u00fcksek ihtimal oldu\u011fundan dolay\u0131 ne olur ne olmaz diyerek k\u00fc\u00e7\u00fck bir a\u00e7\u0131klama yap\u0131p \u00e7ok fazla tan\u0131ma girmeden ge\u00e7mekte fayda g\u00f6r\u00fcyorum..<\/p>\n<p>Claim; kullan\u0131c\u0131 hakk\u0131nda key &#8211; value tarz\u0131nda tutulan ekstra bilgilerdir.\n<\/li>\n<li><strong>Authentication Property Nedir?<\/strong><br \/>\nAuthorization code i\u00e7erisinde ta\u015f\u0131nan ve access token, id token, refresh token vs. gibi bilgileri tutan propertylerdir.\n<\/li>\n<\/ul>\n<h3 style=\"color:#e83e8c;\">Claim&#8217;lere Eri\u015fim?<\/h3>\n<p>Authorization code i\u00e7erisindeki claim&#8217;lere eri\u015febilmek i\u00e7in controller s\u0131n\u0131flarda <code style=\"color:red;\">User.Claims<\/code> komutunun kullan\u0131lmas\u0131 yeterlidir. Gelen claim&#8217;lere g\u00f6z atarsak e\u011fer;<br \/>\n<a href=\"https:\/\/www.gencayyildiz.com\/blog\/wp-content\/uploads\/2020\/11\/IdentityServer4-Yazi-Serisi-12-Merkezi-Uyelik-Sistemi-Claim-ve-Authentication-Propertyleri-Okuma.png\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.gencayyildiz.com\/blog\/wp-content\/uploads\/2020\/11\/IdentityServer4-Yazi-Serisi-12-Merkezi-Uyelik-Sistemi-Claim-ve-Authentication-Propertyleri-Okuma.png\" alt=\"IdentityServer4 Yaz\u0131 Serisi #12 - Merkezi \u00dcyelik Sistemi - Claim ve Authentication Propertyleri Okuma\" width=\"932\" height=\"285\" class=\"aligncenter size-full wp-image-18808\" srcset=\"https:\/\/www.gencayyildiz.com\/blog\/wp-content\/uploads\/2020\/11\/IdentityServer4-Yazi-Serisi-12-Merkezi-Uyelik-Sistemi-Claim-ve-Authentication-Propertyleri-Okuma.png 932w, https:\/\/www.gencayyildiz.com\/blog\/wp-content\/uploads\/2020\/11\/IdentityServer4-Yazi-Serisi-12-Merkezi-Uyelik-Sistemi-Claim-ve-Authentication-Propertyleri-Okuma-300x92.png 300w, https:\/\/www.gencayyildiz.com\/blog\/wp-content\/uploads\/2020\/11\/IdentityServer4-Yazi-Serisi-12-Merkezi-Uyelik-Sistemi-Claim-ve-Authentication-Propertyleri-Okuma-768x235.png 768w\" sizes=\"auto, (max-width: 932px) 100vw, 932px\" \/><\/a><\/p>\n<ul>\n<li><strong><em style=\"color:purple;\">sid<\/em><\/strong><br \/>\nOpenIdConnect taraf\u0131ndan kullan\u0131c\u0131ya \u00f6zel \u00fcretilen kullan\u0131c\u0131 Id(subid)&#8217;yi ifade eder.<\/li>\n<li><strong><em style=\"color:purple;\">http:\/\/schemas.xmlsoap.org\/ws\/2005\/05\/identity\/claims\/nameidentifier<\/em><\/strong><br \/>\nKullan\u0131n\u0131n Subject Id&#8217;sine<span style=\"font-size:10px;\">(hat\u0131rlarsan\u0131z e\u011fer test user tan\u0131mlarken bildirmi\u015ftik)<\/span> manuel eri\u015fmek gerekti\u011finde bu sabit \u00fczerinden elde edilebilir. Otomatik \u015femad\u0131r. <\/li>\n<li><strong><em style=\"color:purple;\">auth_time<\/em><\/strong><br \/>\nSaniye cinsinden yetki s\u00fcresini ifade eder.<\/li>\n<li><strong><em style=\"color:purple;\">http:\/\/schemas.microsoft.com\/identity\/claims\/identityprovider<\/em><\/strong><br \/>\nHangi sa\u011flay\u0131c\u0131 \u00fczerinden giri\u015f yap\u0131ld\u0131ysa onun bilgisini d\u00f6ner. Misal; Facebook ya da Google \u00fczerinden yetki al\u0131nsayd\u0131 ilgili harici kayna\u011f\u0131n ad\u0131 ge\u00e7iyor olacakt\u0131.\n<\/li>\n<li><strong><em style=\"color:purple;\">http:\/\/schemas.microsoft.com\/claims\/authnmethodsreferences<\/em><\/strong><br \/>\nYetkilendirme s\u00fcrecinde hangi ak\u0131\u015f mekanizmas\u0131n\u0131n kullan\u0131ld\u0131\u011f\u0131n\u0131 ifade eder. &#8216;pwd&#8217;, <a href=\"https:\/\/www.gencayyildiz.com\/blog\/identityserver4-yazi-serisi-10-resource-owner-credentials-grantflow\/\" rel=\"noopener noreferrer\" target=\"_blank\">Resource Owner Credentials Grant(Flow)<\/a>&#8216;a kar\u015f\u0131l\u0131k gelmektedir.\n<\/li>\n<\/ul>\n<p>Evet&#8230; Gelen claim&#8217;ler i\u015fte bu kadar. \u015eimdi muhtemelen <a href=\"https:\/\/www.gencayyildiz.com\/blog\/identityserver4-yazi-serisi-11-merkezi-uyelik-sistemi-temelleri\/\" rel=\"noopener noreferrer\" target=\"_blank\">bir \u00f6nceki<\/a> makalemizde olu\u015fturulan test user&#8217;lar da tan\u0131mlad\u0131\u011f\u0131m\u0131z ve &#8216;IdentityResource&#8217; i\u00e7erisinde <code>new IdentityResources.Profile()<\/code> komutu ile authorization code&#8217;a eklenmesini s\u00f6yledi\u011fimiz claim&#8217;lerin neden gelmedi\u011fini soruyor olabilirsiniz.<\/p>\n<table>\n<thead>\n<tr>\n<th>Test User<\/th>\n<th>IdentityResource<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td><a href=\"https:\/\/www.gencayyildiz.com\/blog\/wp-content\/uploads\/2020\/11\/IdentityServer4-Yazi-Serisi-12-Merkezi-Uyelik-Sistemi-Claim-ve-Authentication-Propertyleri-Okuma-1.jpg\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.gencayyildiz.com\/blog\/wp-content\/uploads\/2020\/11\/IdentityServer4-Yazi-Serisi-12-Merkezi-Uyelik-Sistemi-Claim-ve-Authentication-Propertyleri-Okuma-1.jpg\" alt=\"IdentityServer4 Yaz\u0131 Serisi #12 - Merkezi \u00dcyelik Sistemi - Claim ve Authentication Propertyleri Okuma\" width=\"569\" height=\"212\" class=\"aligncenter size-full wp-image-18820\" srcset=\"https:\/\/www.gencayyildiz.com\/blog\/wp-content\/uploads\/2020\/11\/IdentityServer4-Yazi-Serisi-12-Merkezi-Uyelik-Sistemi-Claim-ve-Authentication-Propertyleri-Okuma-1.jpg 569w, https:\/\/www.gencayyildiz.com\/blog\/wp-content\/uploads\/2020\/11\/IdentityServer4-Yazi-Serisi-12-Merkezi-Uyelik-Sistemi-Claim-ve-Authentication-Propertyleri-Okuma-1-300x112.jpg 300w\" sizes=\"auto, (max-width: 569px) 100vw, 569px\" \/><\/a><\/td>\n<td><a href=\"https:\/\/www.gencayyildiz.com\/blog\/wp-content\/uploads\/2020\/11\/IdentityServer4-Yazi-Serisi-12-Merkezi-Uyelik-Sistemi-Claim-ve-Authentication-Propertyleri-Okuma.jpg\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.gencayyildiz.com\/blog\/wp-content\/uploads\/2020\/11\/IdentityServer4-Yazi-Serisi-12-Merkezi-Uyelik-Sistemi-Claim-ve-Authentication-Propertyleri-Okuma.jpg\" alt=\"\" width=\"521\" height=\"147\" class=\"aligncenter size-full wp-image-18819\" srcset=\"https:\/\/www.gencayyildiz.com\/blog\/wp-content\/uploads\/2020\/11\/IdentityServer4-Yazi-Serisi-12-Merkezi-Uyelik-Sistemi-Claim-ve-Authentication-Propertyleri-Okuma.jpg 521w, https:\/\/www.gencayyildiz.com\/blog\/wp-content\/uploads\/2020\/11\/IdentityServer4-Yazi-Serisi-12-Merkezi-Uyelik-Sistemi-Claim-ve-Authentication-Propertyleri-Okuma-300x85.jpg 300w\" sizes=\"auto, (max-width: 521px) 100vw, 521px\" \/><\/a><\/td>\n<\/tr>\n<tr>\n<td colspan=\"2\">\u0130lgili claim&#8217;lerin eklendi\u011fi noktalardaki g\u00f6rseller&#8230;<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>Bu claim&#8217;lerin <code style=\"color:red;\">User.Claims<\/code>&#8216;e eklenmemesinin sebebi ilgili cookie yahut token de\u011ferinin \u015fi\u015firilmemesidir. \u0130\u015flevsel olarak IdentityServer4 k\u00fct\u00fcphanesi UserInfo Endpoint&#8217;i \u00fczerinden kullan\u0131c\u0131ya dair t\u00fcm claim&#8217;lerin eri\u015filebilir olmas\u0131n\u0131 sa\u011flamaktad\u0131r. Dolay\u0131s\u0131yla ihtiya\u00e7 yahut istek neticesinde ilgili de\u011ferlerin elde edilebilmesi i\u00e7in bahsedilen endpoint&#8217;in kullan\u0131lmas\u0131 inisiyatife ba\u011fl\u0131 olaca\u011f\u0131ndan dolay\u0131 framework geli\u015ftiricileri, default olarak harici claim&#8217;lerin cookie yahut token&#8217;a eklenmesini performans a\u00e7\u0131s\u0131ndan uygun g\u00f6rmemi\u015ftir.<\/p>\n<p>Tabi ki de bu durum, istenildi\u011fi taktirde kullan\u0131c\u0131ya dair t\u00fcm claim&#8217;lerin \u00fcretilecek cookie ya da token de\u011ferine eklenmesini engelleyen bir durum demek de\u011fildir. E\u011fer ki t\u00fcm claim&#8217;lerin otomatik olarak cookie ya da token de\u011ferine eklenmesini istiyorsan\u0131z ilgili client&#8217;\u0131n &#8216;Startup.cs&#8217; dosyas\u0131nda a\u015fa\u011f\u0131daki gibi &#8216;GetClaimsFromUserInfoEndpoint&#8217; konfig\u00fcrasyonunun yap\u0131lmas\u0131 yeterli olacakt\u0131r.<\/p>\n<pre class=\"brush: jscript; title: ; notranslate\" title=\"\">\r\n    public class Startup\r\n    {\r\n        public void ConfigureServices(IServiceCollection services)\r\n        {\r\n            services.AddAuthentication(_ =&gt;\r\n            {\r\n                _.DefaultScheme = &quot;OnlineBankamatikCookie&quot;;\r\n                _.DefaultChallengeScheme = &quot;oidc&quot;;\r\n            })\r\n            .AddCookie(&quot;OnlineBankamatikCookie&quot;)\r\n            .AddOpenIdConnect(&quot;oidc&quot;, _ =&gt;\r\n            {\r\n                _.SignInScheme = &quot;OnlineBankamatikCookie&quot;;\r\n                _.Authority = &quot;https:\/\/localhost:1000&quot;;\r\n                _.ClientId = &quot;OnlineBankamatik&quot;;\r\n                _.ClientSecret = &quot;onlinebankamatik&quot;;\r\n                _.ResponseType = &quot;code id_token&quot;;\r\n                _.GetClaimsFromUserInfoEndpoint = true;\r\n            });\r\n            services.AddControllersWithViews();\r\n        }\r\n    }\r\n<\/pre>\n<p>&#8216;GetClaimsFromUserInfoEndpoint&#8217; propertysine &#8216;true&#8217; de\u011ferini set ederek, olu\u015fturulacak cookie yahut token de\u011ferlerine sistemde tan\u0131mlanm\u0131\u015f olan t\u00fcm claim&#8217;leri eklemi\u015f bulunmaktay\u0131z. Burada mimari, arkaplanda Userinfo Endpoint&#8217;ine t\u00fcm claim&#8217;ler i\u00e7in istek g\u00f6ndererek \u00e7al\u0131\u015fmay\u0131 sergileyecektir.<\/p>\n<blockquote><p>GetClaimsFromUserInfoEndpoint; claim&#8217;lerden, profil i\u00e7in default olarak tan\u0131mlanm\u0131\u015f olan de\u011ferleri getirecektir. <code>name<\/code>, <code>family_name<\/code>, <code>given_name<\/code>, <code>middle_name<\/code>, <code>nickname<\/code>, <code>preferred_username<\/code>, <code>profile<\/code>, <code>picture<\/code>, <code>website<\/code>, <code>gender<\/code>, <code>birthdate<\/code>, <code>zoneinfo<\/code>, <code>locale<\/code>, <code>updated_at<\/code><\/p><\/blockquote>\n<p>Bu ayar l\u00fczumlu l\u00fczumsuz her cookie yahut token \u00fcretiminde kullan\u0131c\u0131ya dair t\u00fcm claim&#8217;leri ekleyecektir. Halbuki bizler bu claim&#8217;lere eri\u015fimi daha iradeli bir \u015fekilde ger\u00e7ekle\u015ftirmek ve ihtiyaca istinaden elde etmek istiyorsak Userinfo Endpoint&#8217;ini kullanmam\u0131z gerekmektedir.<\/p>\n<h3 style=\"color:#e83e8c;\">Authentication Propertylere Eri\u015fim?<\/h3>\n<p>Authentication propertyler; &#8216;Access Token&#8217;, &#8216;ID Token&#8217; ve &#8216;Refresh Token&#8217; olmak \u00fczere temelde \u00fc\u00e7 tanedirler. Auth Server&#8217;dan gelen authentication property&#8217;lere controller s\u0131n\u0131flar\u0131ndan eri\u015febilmek i\u00e7in <code style=\"color:red;\">(await HttpContext.AuthenticateAsync()).Properties.Items<\/code> kod konseptinin kullan\u0131lmas\u0131 yeterli olacakt\u0131r.<\/p>\n<p>\u0130stek neticesinde gelen authentication property&#8217;lere g\u00f6z atarsak e\u011fer;<br \/>\n<a href=\"https:\/\/www.gencayyildiz.com\/blog\/wp-content\/uploads\/2020\/11\/IdentityServer4-Yazi-Serisi-12-Merkezi-Uyelik-Sistemi-Claim-ve-Authentication-Propertyleri-Okuma-2.jpg\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.gencayyildiz.com\/blog\/wp-content\/uploads\/2020\/11\/IdentityServer4-Yazi-Serisi-12-Merkezi-Uyelik-Sistemi-Claim-ve-Authentication-Propertyleri-Okuma-2.jpg\" alt=\"IdentityServer4 Yaz\u0131 Serisi #12 - Merkezi \u00dcyelik Sistemi - Claim ve Authentication Propertyleri Okuma\" width=\"1068\" height=\"254\" class=\"aligncenter size-full wp-image-18844\" srcset=\"https:\/\/www.gencayyildiz.com\/blog\/wp-content\/uploads\/2020\/11\/IdentityServer4-Yazi-Serisi-12-Merkezi-Uyelik-Sistemi-Claim-ve-Authentication-Propertyleri-Okuma-2.jpg 1068w, https:\/\/www.gencayyildiz.com\/blog\/wp-content\/uploads\/2020\/11\/IdentityServer4-Yazi-Serisi-12-Merkezi-Uyelik-Sistemi-Claim-ve-Authentication-Propertyleri-Okuma-2-300x71.jpg 300w, https:\/\/www.gencayyildiz.com\/blog\/wp-content\/uploads\/2020\/11\/IdentityServer4-Yazi-Serisi-12-Merkezi-Uyelik-Sistemi-Claim-ve-Authentication-Propertyleri-Okuma-2-1024x244.jpg 1024w, https:\/\/www.gencayyildiz.com\/blog\/wp-content\/uploads\/2020\/11\/IdentityServer4-Yazi-Serisi-12-Merkezi-Uyelik-Sistemi-Claim-ve-Authentication-Propertyleri-Okuma-2-768x183.jpg 768w\" sizes=\"auto, (max-width: 1068px) 100vw, 1068px\" \/><\/a><br \/>\ng\u00f6r\u00fcld\u00fc\u011f\u00fc \u00fczere belli ba\u015fl\u0131 de\u011ferler gelmi\u015f bulunmakta lakin hi\u00e7biri operasyonel a\u00e7\u0131dan bizim i\u00e7in bir anlam ifade etmemektedir. <em><strong>Hani hoca! Access token, refresh token ve id token nerede?<\/strong><\/em> diye sordu\u011funuzu duyar gibiyim \ud83d\ude42 Evet, b\u00f6ylece authentication property&#8217;ler i\u00e7erisinde ilgili de\u011ferlerin default olarak gelmedi\u011fini ve \u00f6zellikle ad\u0131 ge\u00e7en parametrelere eri\u015febilmek i\u00e7in ekstradan bildirilerde bulunmam\u0131z gerekti\u011fini anlam\u0131\u015f bulunmaktay\u0131z.<\/p>\n<p>\u015eimdi s\u0131ras\u0131yla bu propertylere nas\u0131l eri\u015filebildi\u011fini inceleyelim;<\/p>\n<ul>\n<li><strong>Access Token<\/strong><br \/>\nClient&#8217;\u0131n API&#8217;lere eri\u015fiminde temel yetkiyi sa\u011flayacak olan access token de\u011ferinin elde edilebilmesi i\u00e7in ilgili client&#8217;\u0131n &#8216;Startup.cs&#8217; dosyas\u0131nda &#8216;SaveTokens&#8217; property&#8217;sine &#8216;true&#8217; de\u011feri set edilmelidir. B\u00f6ylece Auth server&#8217;dan ilgili access token de\u011feri client taraf\u0131ndan elde edilmi\u015f olacakt\u0131r.<\/p>\n<pre class=\"brush: jscript; title: ; notranslate\" title=\"\">\r\n            services.AddAuthentication(_ =&gt;\r\n            {\r\n                _.DefaultScheme = &quot;OnlineBankamatikCookie&quot;;\r\n                _.DefaultChallengeScheme = &quot;oidc&quot;;\r\n            })\r\n            .AddCookie(&quot;OnlineBankamatikCookie&quot;)\r\n            .AddOpenIdConnect(&quot;oidc&quot;, _ =&gt;\r\n            {\r\n                .\r\n                .\r\n                .\r\n                _.SaveTokens = true;\r\n            });\r\n<\/pre>\n<p>&#8216;SaveTokens&#8217; \u00f6zelli\u011fi varsay\u0131lan olarak &#8216;false&#8217; de\u011ferine sahiptir. &#8216;true&#8217; de\u011feri set edildikten sonra i\u015flevsel olarak, ba\u015far\u0131l\u0131 bir authorization i\u015fleminin ard\u0131ndan Authentication Propertylere access token de\u011ferini kaydedecektir. Dolay\u0131s\u0131yla bizler bu de\u011feri kullanarak hedef API&#8217;lardan veri transferini sa\u011flayabilece\u011fiz.<\/p>\n<blockquote><p><em style=\"color:purple;\">Identity Server taraf\u0131ndan \u00fcretilen bir access token&#8217;\u0131n default \u00f6mr\u00fc 1 saattir.<\/em><\/p><\/blockquote>\n<p>E\u011fer ki, \u00fcretilecek access token&#8217;\u0131n \u00f6mr\u00fcn\u00fc siz belirlemek istiyorsan\u0131z Auth Server&#8217;da ki &#8216;Config.cs&#8217; dosyas\u0131nda tan\u0131mlanan claim&#8217;lerden ilgilisinde &#8216;AccessTokenLifetime&#8217; \u00f6zelli\u011fini kullanman\u0131z ve saniye cinsinden de\u011fer ataman\u0131z yeterli olacakt\u0131r.<\/p>\n<pre class=\"brush: jscript; title: ; notranslate\" title=\"\">\r\n                new Client\r\n                        {\r\n                            .\r\n                            .\r\n                            .\r\n                            AccessTokenLifetime = 2 * 60 * 60\r\n                        }\r\n<\/pre>\n<p>Velhas\u0131l, bu konfig\u00fcrasyondan sonra uygulamalar\u0131 test ama\u00e7l\u0131 derleyip, \u00e7al\u0131\u015ft\u0131rd\u0131\u011f\u0131m\u0131zda Auth Server&#8217;dan gelen cookie i\u00e7erisinde access token ve id token de\u011ferlerini a\u015fa\u011f\u0131daki gibi g\u00f6rebilmekteyiz.<br \/>\n<a href=\"https:\/\/www.gencayyildiz.com\/blog\/wp-content\/uploads\/2020\/11\/IdentityServer4-Yazi-Serisi-12-Merkezi-Uyelik-Sistemi-Claim-ve-Authentication-Propertyleri-Okuma-3.jpg\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.gencayyildiz.com\/blog\/wp-content\/uploads\/2020\/11\/IdentityServer4-Yazi-Serisi-12-Merkezi-Uyelik-Sistemi-Claim-ve-Authentication-Propertyleri-Okuma-3.jpg\" alt=\"IdentityServer4 Yaz\u0131 Serisi #12 - Merkezi \u00dcyelik Sistemi - Claim ve Authentication Propertyleri Okuma\" width=\"1202\" height=\"315\" class=\"aligncenter size-full wp-image-18848\" srcset=\"https:\/\/www.gencayyildiz.com\/blog\/wp-content\/uploads\/2020\/11\/IdentityServer4-Yazi-Serisi-12-Merkezi-Uyelik-Sistemi-Claim-ve-Authentication-Propertyleri-Okuma-3.jpg 1202w, https:\/\/www.gencayyildiz.com\/blog\/wp-content\/uploads\/2020\/11\/IdentityServer4-Yazi-Serisi-12-Merkezi-Uyelik-Sistemi-Claim-ve-Authentication-Propertyleri-Okuma-3-300x79.jpg 300w, https:\/\/www.gencayyildiz.com\/blog\/wp-content\/uploads\/2020\/11\/IdentityServer4-Yazi-Serisi-12-Merkezi-Uyelik-Sistemi-Claim-ve-Authentication-Propertyleri-Okuma-3-1024x268.jpg 1024w, https:\/\/www.gencayyildiz.com\/blog\/wp-content\/uploads\/2020\/11\/IdentityServer4-Yazi-Serisi-12-Merkezi-Uyelik-Sistemi-Claim-ve-Authentication-Propertyleri-Okuma-3-768x201.jpg 768w\" sizes=\"auto, (max-width: 1202px) 100vw, 1202px\" \/><\/a>\n<\/li>\n<li><strong>ID Token<\/strong><br \/>\nEsas amac\u0131, access token&#8217;\u0131n Auth Server taraf\u0131ndan \u00fcretilmi\u015f bir token olup olmad\u0131\u011f\u0131n\u0131 do\u011frulamakt\u0131r. Identity Server taraf\u0131ndan private key ile imzalanan id token client taraf\u0131ndan elde edilen public key ile do\u011frulanmakta ve b\u00f6ylece Auth Server taraf\u0131ndan ilgili access token do\u011frulanm\u0131\u015f olmaktad\u0131r.<\/p>\n<p>Id Token&#8217;a eri\u015fim sa\u011flanabilmesi i\u00e7in access token&#8217;\u0131n eri\u015fim konfig\u00fcrasyonlar\u0131 yeterlidir. Bir \u00f6nceki ad\u0131mda sonu\u00e7 olarak access token yan\u0131nda id token&#8217;da elde edilmi\u015ftir.\n<\/li>\n<li><strong>Refresh Token<\/strong><br \/>\nAuthentication property&#8217;ler aras\u0131nda bir client i\u00e7in refresh token de\u011ferininde elde edilebilmesi i\u00e7in yine Auth Server&#8217;da ki &#8216;Config.cs&#8217; dosyas\u0131nda ilgili client&#8217;a dair &#8216;AllowOfflineAccess&#8217; \u00f6zelli\u011fine &#8216;true&#8217; de\u011ferinin verilmesiyle birlikte a\u015fa\u011f\u0131daki konfig\u00fcrasyonlar\u0131n eklenmesi gerekmektedir.<\/p>\n<pre class=\"brush: jscript; title: ; notranslate\" title=\"\">\r\n                new Client\r\n                        {\r\n                            .\r\n                            .\r\n                            .\r\n                            AllowedScopes = { IdentityServerConstants.StandardScopes.OpenId, IdentityServerConstants.StandardScopes.Profile, IdentityServerConstants.StandardScopes.OfflineAccess },\r\n                            AllowOfflineAccess = true,\r\n                            RefreshTokenUsage = TokenUsage.OneTimeOnly,\r\n                            RefreshTokenExpiration = TokenExpiration.Absolute,\r\n                            AbsoluteRefreshTokenLifetime = 2 * 60 * 60 + (10 * 60)\r\n                        }\r\n<\/pre>\n<p>Burada &#8216;RefreshTokenUsage&#8217; propertysi client&#8217;a dair \u00fcretilecek refresh token&#8217;\u0131n kullan\u0131labilirli\u011fini ayarlamaktad\u0131r. &#8216;OneTimeOnly&#8217; de\u011feri yaln\u0131zca tek seferlik bir kullan\u0131m hakk\u0131 tan\u0131nd\u0131\u011f\u0131n\u0131 ifade etmekle birlikte, &#8216;ReUse&#8217; de\u011feri ile birden fazla kez kullan\u0131labilirlikte ayarlanabilmektedir. &#8216;AbsoluteRefreshTokenLifetime&#8217; property&#8217;si ise refresh token&#8217;\u0131n \u00f6mr\u00fcn\u00fc belirlemektedir. Burada refresh token \u00f6mr\u00fc i\u00e7in &#8216;SlidingRefreshTokenLifetime&#8217;da kullan\u0131labilir. \u0130kisi aras\u0131ndaki fark; ilki net \u00f6mr\u00fc belirtirken, ikincisi ise belli bir s\u00fcre i\u00e7erisinde kullan\u0131ld\u0131\u011f\u0131 taktirde \u00f6mr\u00fcn periyodik uzat\u0131lmas\u0131n\u0131 sa\u011flamaktad\u0131r.<\/p>\n<p>Bu ayarlar\u0131n d\u0131\u015f\u0131nda &#8216;AllowedScopes&#8217; property&#8217;sine dikkat edilirse e\u011fer <code style=\"color:red;\">IdentityServerConstants.StandardScopes.OfflineAccess<\/code> komutu ile ilgili client&#8217;a, \u00fcretilecek olan refresh token&#8217;a dair eri\u015fim yetkisi de verilmektedir.<\/p>\n<p>Son olarak ilgili client&#8217;\u0131n &#8216;Startup.cs&#8217; dosyas\u0131nda yukar\u0131da eklenen OfflineAccess&#8217;e kar\u015f\u0131l\u0131k gelen &#8216;offline_access&#8217; scope de\u011ferinin a\u015fa\u011f\u0131daki gibi eklenmesi gerekmektedir.<\/p>\n<pre class=\"brush: jscript; title: ; notranslate\" title=\"\">\r\n            services.AddAuthentication(_ =&gt;\r\n            {\r\n                _.DefaultScheme = &quot;OnlineBankamatikCookie&quot;;\r\n                _.DefaultChallengeScheme = &quot;oidc&quot;;\r\n            })\r\n            .AddCookie(&quot;OnlineBankamatikCookie&quot;)\r\n            .AddOpenIdConnect(&quot;oidc&quot;, _ =&gt;\r\n            {\r\n                .\r\n                .\r\n                .\r\n                _.Scope.Add(&quot;offline_access&quot;);\r\n            });\r\n<\/pre>\n<p>T\u00fcm bu i\u015flemler neticesinde uygulama derlenip, \u00e7al\u0131\u015ft\u0131r\u0131ld\u0131\u011f\u0131nda refresh token&#8217;\u0131n elde edildi\u011fi g\u00f6r\u00fclecektir.<br \/>\n<a href=\"https:\/\/www.gencayyildiz.com\/blog\/wp-content\/uploads\/2020\/11\/IdentityServer4-Yazi-Serisi-12-Merkezi-Uyelik-Sistemi-Claim-ve-Authentication-Propertyleri-Okuma-4.jpg\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.gencayyildiz.com\/blog\/wp-content\/uploads\/2020\/11\/IdentityServer4-Yazi-Serisi-12-Merkezi-Uyelik-Sistemi-Claim-ve-Authentication-Propertyleri-Okuma-4.jpg\" alt=\"IdentityServer4 Yaz\u0131 Serisi #12 - Merkezi \u00dcyelik Sistemi - Claim ve Authentication Propertyleri Okuma\" width=\"744\" height=\"38\" class=\"aligncenter size-full wp-image-18866\" srcset=\"https:\/\/www.gencayyildiz.com\/blog\/wp-content\/uploads\/2020\/11\/IdentityServer4-Yazi-Serisi-12-Merkezi-Uyelik-Sistemi-Claim-ve-Authentication-Propertyleri-Okuma-4.jpg 744w, https:\/\/www.gencayyildiz.com\/blog\/wp-content\/uploads\/2020\/11\/IdentityServer4-Yazi-Serisi-12-Merkezi-Uyelik-Sistemi-Claim-ve-Authentication-Propertyleri-Okuma-4-300x15.jpg 300w, https:\/\/www.gencayyildiz.com\/blog\/wp-content\/uploads\/2020\/11\/IdentityServer4-Yazi-Serisi-12-Merkezi-Uyelik-Sistemi-Claim-ve-Authentication-Propertyleri-Okuma-4-720x38.jpg 720w\" sizes=\"auto, (max-width: 744px) 100vw, 744px\" \/><\/a>\n<\/li>\n<\/ul>\n<h4 style=\"color:purple;\">Access Token ile Id Token Aras\u0131ndaki Fark<\/h4>\n<p>Her iki JWT de\u011ferini <a href=\"https:\/\/jwt.io\/\" rel=\"noopener noreferrer\" target=\"_blank\">jwt.io<\/a> sitesi \u00fczerinden incelersek e\u011fer;<\/p>\n<table>\n<thead>\n<tr>\n<th>Access Token<\/th>\n<th>Id Token<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td><a href=\"https:\/\/www.gencayyildiz.com\/blog\/wp-content\/uploads\/2020\/11\/IdentityServer4-Yazi-Serisi-12-Merkezi-Uyelik-Sistemi-Claim-ve-Authentication-Propertyleri-Okuma-5.jpg\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.gencayyildiz.com\/blog\/wp-content\/uploads\/2020\/11\/IdentityServer4-Yazi-Serisi-12-Merkezi-Uyelik-Sistemi-Claim-ve-Authentication-Propertyleri-Okuma-5.jpg\" alt=\"IdentityServer4 Yaz\u0131 Serisi #12 - Merkezi \u00dcyelik Sistemi - Claim ve Authentication Propertyleri Okuma\" width=\"799\" height=\"643\" class=\"aligncenter size-full wp-image-18869\" srcset=\"https:\/\/www.gencayyildiz.com\/blog\/wp-content\/uploads\/2020\/11\/IdentityServer4-Yazi-Serisi-12-Merkezi-Uyelik-Sistemi-Claim-ve-Authentication-Propertyleri-Okuma-5.jpg 799w, https:\/\/www.gencayyildiz.com\/blog\/wp-content\/uploads\/2020\/11\/IdentityServer4-Yazi-Serisi-12-Merkezi-Uyelik-Sistemi-Claim-ve-Authentication-Propertyleri-Okuma-5-300x241.jpg 300w, https:\/\/www.gencayyildiz.com\/blog\/wp-content\/uploads\/2020\/11\/IdentityServer4-Yazi-Serisi-12-Merkezi-Uyelik-Sistemi-Claim-ve-Authentication-Propertyleri-Okuma-5-768x618.jpg 768w\" sizes=\"auto, (max-width: 799px) 100vw, 799px\" \/><\/a><\/td>\n<td><a href=\"https:\/\/www.gencayyildiz.com\/blog\/wp-content\/uploads\/2020\/11\/IdentityServer4-Yazi-Serisi-12-Merkezi-Uyelik-Sistemi-Claim-ve-Authentication-Propertyleri-Okuma-6.jpg\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.gencayyildiz.com\/blog\/wp-content\/uploads\/2020\/11\/IdentityServer4-Yazi-Serisi-12-Merkezi-Uyelik-Sistemi-Claim-ve-Authentication-Propertyleri-Okuma-6.jpg\" alt=\"IdentityServer4 Yaz\u0131 Serisi #12 - Merkezi \u00dcyelik Sistemi - Claim ve Authentication Propertyleri Okuma\" width=\"876\" height=\"734\" class=\"aligncenter size-full wp-image-18870\" srcset=\"https:\/\/www.gencayyildiz.com\/blog\/wp-content\/uploads\/2020\/11\/IdentityServer4-Yazi-Serisi-12-Merkezi-Uyelik-Sistemi-Claim-ve-Authentication-Propertyleri-Okuma-6.jpg 876w, https:\/\/www.gencayyildiz.com\/blog\/wp-content\/uploads\/2020\/11\/IdentityServer4-Yazi-Serisi-12-Merkezi-Uyelik-Sistemi-Claim-ve-Authentication-Propertyleri-Okuma-6-300x251.jpg 300w, https:\/\/www.gencayyildiz.com\/blog\/wp-content\/uploads\/2020\/11\/IdentityServer4-Yazi-Serisi-12-Merkezi-Uyelik-Sistemi-Claim-ve-Authentication-Propertyleri-Okuma-6-768x644.jpg 768w\" sizes=\"auto, (max-width: 876px) 100vw, 876px\" \/><\/a><\/td>\n<\/tr>\n<tr>\n<td colspan=\"2\">\nHer iki de\u011ferin a\u00e7\u0131l\u0131m\u0131na g\u00f6z atarsan\u0131z e\u011fer kendilerine has belli ba\u015fl\u0131 bilgilerin yan\u0131nda, access token, eri\u015fimi sa\u011flayabilmesi i\u00e7in &#8216;scope&#8217; alt\u0131nda yetkiler bar\u0131nd\u0131rmaktad\u0131r. Lakin id token&#8217;da &#8216;scope&#8217; yer almamaktad\u0131r. Burada id token&#8217;\u0131n yukar\u0131larda bahsedildi\u011fi gibi sadece do\u011frulama ama\u00e7l\u0131 \u00fcretilen bir de\u011fer oldu\u011fu daha da netle\u015fmi\u015f olmaktad\u0131r.\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h3 style=\"color:#e83e8c;\">Userinfo Endpoint<\/h3>\n<p>Kullan\u0131c\u0131 hakk\u0131nda claim bilgilerini elde etmek i\u00e7in kullan\u0131lan endpoint&#8217;tir.<br \/>\n<code>\/connect\/userinfo<\/code> endpoint&#8217;ine header bilgisi <code>Authorization: Bearer <access_token><\/code> olan bir &#8216;GET&#8217; iste\u011finde bulunulmas\u0131 yeterlidir.<br \/>\n<a href=\"https:\/\/www.gencayyildiz.com\/blog\/wp-content\/uploads\/2020\/11\/IdentityServer4-Yazi-Serisi-12-Merkezi-Uyelik-Sistemi-Claim-ve-Authentication-Propertyleri-Okuma-7.jpg\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.gencayyildiz.com\/blog\/wp-content\/uploads\/2020\/11\/IdentityServer4-Yazi-Serisi-12-Merkezi-Uyelik-Sistemi-Claim-ve-Authentication-Propertyleri-Okuma-7.jpg\" alt=\"IdentityServer4 Yaz\u0131 Serisi #12 - Merkezi \u00dcyelik Sistemi - Claim ve Authentication Propertyleri Okuma\" width=\"351\" height=\"373\" class=\"aligncenter size-full wp-image-18873\" srcset=\"https:\/\/www.gencayyildiz.com\/blog\/wp-content\/uploads\/2020\/11\/IdentityServer4-Yazi-Serisi-12-Merkezi-Uyelik-Sistemi-Claim-ve-Authentication-Propertyleri-Okuma-7.jpg 351w, https:\/\/www.gencayyildiz.com\/blog\/wp-content\/uploads\/2020\/11\/IdentityServer4-Yazi-Serisi-12-Merkezi-Uyelik-Sistemi-Claim-ve-Authentication-Propertyleri-Okuma-7-282x300.jpg 282w\" sizes=\"auto, (max-width: 351px) 100vw, 351px\" \/><\/a><br \/>\nG\u00f6r\u00fcld\u00fc\u011f\u00fc \u00fczere Userinfo Endpoint ile elde edilen claim&#8217;ler, sadece profil i\u00e7in default olarak tan\u0131mlanm\u0131\u015f de\u011ferler de\u011fil, tam aksine kullan\u0131c\u0131ya dair olan t\u00fcm de\u011ferlerdir.<\/p>\n<p>\u0130lgilenenlerin faydalanmas\u0131 dile\u011fiyle&#8230;<br \/>\nSonraki yaz\u0131lar\u0131mda g\u00f6r\u00fc\u015fmek \u00fczere&#8230;<br \/>\n\u0130yi \u00e7al\u0131\u015fmalar&#8230;<\/p>\n<p>Not : \u00d6rnek uygulamay\u0131 indirebilmek i\u00e7in <a href=\"https:\/\/www.gencayyildiz.com\/blog\/wp-content\/uploads\/2020\/11\/IdentityServer4Example-1.zip\">buraya<\/a> t\u0131klay\u0131n\u0131z.<\/p>\n<!-- AddThis Advanced Settings generic via filter on the_content --><!-- AddThis Share Buttons generic via filter on the_content -->","protected":false},"excerpt":{"rendered":"<p>Merhaba, IdentityServer4 Yaz\u0131 Serisinin bir \u00f6nceki kaleme ald\u0131\u011f\u0131m\u0131z Merkezi \u00dcyelik Sistemi Temelleri ba\u015fl\u0131kl\u0131 makalemizde client&#8217;\u0131n Auth Server&#8217;dan authorization code almas\u0131n\u0131 ba\u015farm\u0131\u015f ve client \u00fczerinde authorize olan k\u0131s\u0131mlara yetkili bir \u015fekilde eri\u015fimi test etmi\u015ftik. Bu&#46;&#46;&#46;<!-- AddThis Advanced Settings generic via filter on get_the_excerpt --><!-- AddThis Share Buttons generic via filter on get_the_excerpt --><\/p>\n","protected":false},"author":1,"featured_media":18168,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3826],"tags":[3889,3827,3895,3898,3893,3854,3890,3891,3899,3901,3897,3892,3896,3900,3894],"class_list":["post-18791","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-identityserver4","tag-authentication-property","tag-identityserver4","tag-identityserver4-access-token","tag-identityserver4-access-token-alma","tag-identityserver4-authentication-property","tag-identityserver4-claim","tag-identityserver4-claim-okuma","tag-identityserver4-claim-read","tag-identityserver4-get-access-token","tag-identityserver4-get-refresh-token","tag-identityserver4-id-token","tag-identityserver4-read-claim","tag-identityserver4-refresh-token","tag-identityserver4-refresh-token-alma","tag-userinfo-endpoint"],"amp_enabled":true,"_links":{"self":[{"href":"https:\/\/www.gencayyildiz.com\/blog\/wp-json\/wp\/v2\/posts\/18791","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.gencayyildiz.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.gencayyildiz.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.gencayyildiz.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.gencayyildiz.com\/blog\/wp-json\/wp\/v2\/comments?post=18791"}],"version-history":[{"count":77,"href":"https:\/\/www.gencayyildiz.com\/blog\/wp-json\/wp\/v2\/posts\/18791\/revisions"}],"predecessor-version":[{"id":18884,"href":"https:\/\/www.gencayyildiz.com\/blog\/wp-json\/wp\/v2\/posts\/18791\/revisions\/18884"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.gencayyildiz.com\/blog\/wp-json\/wp\/v2\/media\/18168"}],"wp:attachment":[{"href":"https:\/\/www.gencayyildiz.com\/blog\/wp-json\/wp\/v2\/media?parent=18791"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.gencayyildiz.com\/blog\/wp-json\/wp\/v2\/categories?post=18791"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.gencayyildiz.com\/blog\/wp-json\/wp\/v2\/tags?post=18791"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}