2
votes

I am trying to form a basic authentication header by getting a username and password from my web.config When I get these values from web.config, the base64 string is different than the ones I get from hard coding the values straight into the code.

This is my web.config:

 <?xml version="1.0" encoding="utf-8"?>
    <appSettings>
    <add key="Username" value="lowercaseusername"/>
    <add key="Password" value="mixedcasePassword​"/>
    </appSettings>

And my code:

var username = ConfigurationManager.AppSettings["Username"];
var password = ConfigurationManager.AppSettings["Password"];
string encodedValues = `Convert.ToBase64String(System.Text.Encoding.UTF8.GetBytes(username + ":" + password));`

I get an extra "4oCL" at the end of the encoded string when I get them from web.config as opposed to hardcoded directly as values in the code

1
Did you resolve your issue? - krlzlx

1 Answers

0
votes

Your web.config have an utf-8 encoding. If I copy-pasted your password and set the web.config encoding to iso-8859-1:

<?xml version="1.0" encoding="iso-8859-1"?>

that's what I get when getting the value from the config:

mixedcasePasswordâ\u0080\u008b

This should correspond to

mixedcasePassword​

So there's some invisible characters that have been incorrectly encoded in your web.config.

The web.config file is an XML file, so the values need to be encoded. So if you set in your web.config (keeping the encoding at utf-8):

<add key="Password" value="mixedcasePassword&#226;&#8364;&#8249;" />

you should have true if you test:

ConfigurationManager.AppSettings["Password"] == "mixedcasePassword​"

Then your base64 should match if you get the password from the web.config or hard coded.