using GB5Shared.Connection; namespace FrameworkBLL.Encryption { public class EncryptionBLL : IEncryptionBLL { private const string DefaultKey = "GB5"; private readonly IApplicationConnection _ApplicationConnection; public EncryptionBLL(IApplicationConnection ApplicationConnection) { _ApplicationConnection = ApplicationConnection; } public string Encrypt(string data) => Encrypt(data, DefaultKey); public string Encrypt(string data, string publicKey) { if (string.IsNullOrEmpty(data)) throw new ArgumentException("data is required."); if (string.IsNullOrEmpty(publicKey)) throw new ArgumentException("PublicKey is required."); string ciphertext = _ApplicationConnection.Encrypt(data, publicKey); return ToUrlSafeBase64(ciphertext); } public string Decrypt(string token) => Decrypt(token, DefaultKey); public string Decrypt(string token, string publicKey) { if (string.IsNullOrEmpty(token)) throw new ArgumentException("data is required."); if (string.IsNullOrEmpty(publicKey)) throw new ArgumentException("PublicKey is required."); string ciphertext = FromUrlSafeBase64(token); return _ApplicationConnection.Decrypt(ciphertext, publicKey); } // The token travels in query strings/headers, where standard Base64's '+', '/' and '=' // are prone to being mangled by clients/proxies that don't URL-encode them. Re-encoding // to URL-safe Base64 (RFC 4648 §5 — same scheme JWTs use) avoids that class of bug entirely. private static string ToUrlSafeBase64(string standardBase64) { return standardBase64.Replace('+', '-').Replace('/', '_').TrimEnd('='); } private static string FromUrlSafeBase64(string urlSafeBase64) { string base64 = urlSafeBase64.Replace('-', '+').Replace('_', '/'); int padding = (4 - base64.Length % 4) % 4; return base64 + new string('=', padding); } } }