Compare commits

..

7 Commits

Author SHA1 Message Date
achiez 30cf049f23 refactor(auth): redesign Steam audience and web domain authorization model
- Rename AuthorizedDomains to WebDomains
- Introduce explicit Steam audience constants and web audience mappings
- Improve Steam token/domain resolution and cookie installation flow
- Allow mobile-issued tokens with "web" audience to be used for web domains
- Align authorization logic closer to actual Steam audience behavior
- Rename cookie APIs from Add* to Set* where appropriate
2026-05-12 16:36:37 +03:00
achiez ce55005d44 chore: remove outdated README files and update main README with new features and documentation link 2026-05-04 19:37:37 +03:00
github-actions a23d7017a7 chore(release): 1.8.4 2026-03-14 13:36:41 +00:00
achiez c879dd462c fix(build): include NebulaAuth.exe in release package
Fix CI packaging configuration to ensure NebulaAuth.exe is included
in the published release artifacts.
2026-03-14 15:36:02 +02:00
github-actions e681ca07f1 chore(release): 1.8.3 2026-03-13 13:37:20 +00:00
Achies 9227b383bb Merge pull request #20 from achiez/1.8.3
Release 1.8.3
2026-03-13 15:36:47 +02:00
Achies a3804dd48d Update README.md
Add copyright disclaimer
2026-03-12 15:41:38 +02:00
19 changed files with 278 additions and 331 deletions
+5 -3
View File
@@ -111,10 +111,12 @@ jobs:
- name: Build NebulaAuth
run: |
dotnet publish src/NebulaAuth/NebulaAuth.csproj \
dotnet publish src/NebulaAuth/NebulaAuth.csproj \
-c Release \
-o build \
-p:EnableWindowsTargeting=true
-r win-x64 \
--self-contained false \
-p:EnableWindowsTargeting=true \
-o build
# --------------------------------------------------------
# Package ZIP
+1
View File
@@ -22,6 +22,7 @@
<File Path="changelog/1.8.1.html" />
<File Path="changelog/1.8.2.html" />
<File Path="changelog/1.8.3.json" />
<File Path="changelog/1.8.4.json" />
</Folder>
<Project Path="src/NebulaAuth/NebulaAuth.csproj" />
<Project Path="src/SteamLibForked/SteamLibForked.csproj" />
+5 -4
View File
@@ -1,7 +1,8 @@
<?xml version="1.0" encoding="UTF-8"?>
<item>
<version>1.8.2</version>
<url>https://github.com/achiez/NebulaAuth-Steam-Desktop-Authenticator-by-Achies/releases/download/1.8.2/NebulaAuth.1.8.2.zip</url>
<changelog>https://achiez.github.io/NebulaAuth-Steam-Desktop-Authenticator-by-Achies/changelog/1.8.2.html</changelog>
<item>
<version>1.8.4</version>
<url>https://github.com/achiez/NebulaAuth-Steam-Desktop-Authenticator-by-Achies/releases/download/1.8.4/NebulaAuth.1.8.4.zip</url>
<changelog>https://achiez.github.io/NebulaAuth-Steam-Desktop-Authenticator-by-Achies/changelog/1.8.4.html</changelog>
<mandatory>false</mandatory>
<checksum algorithm="SHA256">5ecad7a711bab7e98f5f3bfa92b7a00e21efc18aa92251bb30bd3e50a2f7d2f2</checksum>
</item>
-74
View File
@@ -1,74 +0,0 @@
# NebulaAuth
## Описание
<h3 align="center" style="margin-bottom:0">
<a href="https://github.com/achiez/NebulaAuth-Steam-Desktop-Authenticator-by-Achies/releases/latest">Скачать последнюю версию</a>
</h3>
<h3 align="center">NebulaAuth — это приложение для эмуляции действий из мобильного приложения Steam. Которая заменяет ваш смартфон при работе в Steam.</h3>
<h4 align="center"><a href="https://t.me/nebulaauth">Официальная группа в Telegram</a></h4>
## Основные преимущества
- **Локализация на трёх языках**: английском, русском и украинском.
- **Полная функциональность Steam Desktop Authenticator**, переосмысление [старого приложения](https://github.com/Jessecar96/SteamDesktopAuthenticator)
- **Поддержка прокси** во всех процессах работы с аккаунтом.
- **Группировка мафайлов** для продвинутого контроля.
- **Автоматическое подтверждение трейдов/действий на ТП** для экономии времени.
- **Массовый импорт мафайлов** с помощью Drag'n'Drop или CTRL+V для удобства.
- **Настройка внешнего вида** для персонализации интерфейса.
- **Возможность подтвердить вход в учетную запись без ввода кода** для облегчения доступа.
- **Автообновление** программы для использования новейших функций.
- **Автоматический повторный вход в случае проблем с сессией** для непрерывной работы.
- **Интуитивно понятный интерфейс** с подсказками и удобствами
- **Постоянная поддержка** кода приложения и других функций.
## Установка
1. Если приложение не запускается, необходимо установить [.NET Desktop Runtime](https://dotnet.microsoft.com/en-us/download/dotnet/8.0)
2. [Скачать программу из релизов этого репозитория на Github](https://github.com/achiez/NebulaAuth-Steam-Desktop-Authenticator-by-Achies/releases/latest)
* *Для сохранности ваших данных скачивайте приложение только отсюда*
4. Распакуйте ZIP-файл в любую папку.
5. Запустите файл **NebulaAuth.exe**.
## Использование
![gh-main-window-rus](https://github.com/achiez/NebulaAuth-Steam-Desktop-Authenticator-by-Achies/assets/106531132/6a84f414-0e24-40a4-8adb-f1923fbe8719)
1. Панель управления.
- управление файлами и настройки
- управление аккаунтом (вход, привязка, отвязка)
- группировка
- выбор прокси
- индикатор с подсказкой об используемом прокси (горит либо желтым, либо красным, при наведении отобразит дополнительную информацию)
- таймеры для автоматического подтверждения трейдов/продаж на торговой площадке
- интервал таймера подтверждений (в секундах)
2. Список ваших аккаунтов
3. Код подтверждения входа (нажмите, чтобы скопировать)
4. Главное окно подтверждений
5. Поиск по логину или SteamID (7xxxxxxxxxxxxx)
6. Подтвердить вход на другогом устройстве.
7. Гиперссылка на официальную страницу приложения с указанием авторства.
## Настройки
![gh-settings-rus](https://github.com/achiez/NebulaAuth-Steam-Desktop-Authenticator-by-Achies/assets/106531132/33246ed1-1e3d-4310-88c5-085e5c50bc6b)
1. Режим фона. Используйте, если вы хотите отключить фон или установить собственный (поместите файл «Background.png» в папку приложения)
2. Язык приложения
3. Отключить таймеры при переключении между аккаунтами
4. Скрывать в трей при сворачивании
5. Индикатор с цветом. Маленький кружочек на значке панели задач с произвольным цветом. Полезно при использовании нескольких окон.
6. Пользовательский цвет приложения.
7. Текущий пароль шифрования. Если установлено, вы можете сохранять зашифрованные пароли в mafile, чтобы облегчить повторный вход в систему при проблемах с сессией. (Не рекомендуется)
8. Режим устаревших файлов. Режим совместимости Mafile с другими клиентами (SDA и т.д.). Если установлено, приложение будет сохранять файлы в старом стандартном формате (по умолчанию: включено).
9. Разрешить автообновление без подтверждения
## [Лицензия](/LICENSE.md)
Коммерческое использование запрещено. При распространении измененного кода необходимо указывать оригинальное авторство.
-71
View File
@@ -1,71 +0,0 @@
# NebulaAuth
## Опис
<h3 align="center" style="margin-bottom:0">
<a href="https://github.com/achiez/NebulaAuth-Steam-Desktop-Authenticator-by-Achies/releases/latest">Завантажити останню версію</a>
</h3>
<h3 align="center">NebulaAuth - це програма для емуляції дій з мобільного додатку Steam. Яка замінює ваш смартфон під час роботи в Steam.</h3>
<h4 align="center"><a href="https://t.me/nebulaauth">Офіційна група в Telegram</a></h4>
## Основні переваги
- **Локалізація трьома мовами**: англійською, російською та українською.
- **Повна функціональність Steam Desktop Authenticator** переосмислення [старої програми](https://github.com/Jessecar96/SteamDesktopAuthenticator)
- **Підтримка проксі** у всіх процесах роботи з обліковим записом.
- **Угруповання мафайлів** для просунутого контролю.
- **Автоматичне підтвердження трейдів/дій на маркеті** для економії часу.
- **Масовий імпорт мафайлів** за допомогою Drag'n'Drop або CTRL+V для зручності.
- **Налаштування зовнішнього вигляду** для персоналізації інтерфейсу.
- **Можливість підтвердити вхід до облікового запису без введення коду** для полегшення доступу.
- **Автооновлення** програми для використання новітніх функцій.
- **Автоматичний повторний вхід у разі проблем із сесією** для безперервної роботи.
- **Інтуїтивно зрозумілий інтерфейс** з підказками та зручностями
- **Постійна підтримка** коду програми та інших функцій.
## Монтаж
1. Якщо програма не запускається, необхідно встановити [.NET Desktop Runtime](https://dotnet.microsoft.com/en-us/download/dotnet/8.0)
2. [Завантажити програму з релізів цього репозиторію на Github](https://github.com/achiez/NebulaAuth-Steam-Desktop-Authenticator-by-Achies/releases/latest)
* *Для збереження ваших даних завантажуйте програму тільки звідси*
4. Розпакуйте ZIP-файл у будь-яку папку.
5. Запустіть файл **NebulaAuth.exe**.
## Використання
![gh-main-window-ua](https://github.com/achiez/NebulaAuth-Steam-Desktop-Authenticator-by-Achies/assets/106531132/bf61ac61-b21c-4589-9b5a-751a6d983120)
1. Панель керування.
- керування файлами та налаштування
- керування акаунтом (вхід, прив'язка, відв'язування)
- угруповання
- вибір проксі
- індикатор з підказкою про проксі (світиться або жовтим, або червоним, при наведенні відобразить додаткову інформацію)
- таймери для автоматичного підтвердження трейдів/продажів на маркеті
- інтервал таймера підтверджень (у секундах)
2. Список ваших облікових записів
3. Код підтвердження входу (натисніть, щоб скопіювати)
4. Головне вікно підтвердження
5. Пошук за логіном або SteamID (7xxxxxxxxxxxxx)
6. Підтвердити вхід на іншому пристрою.
7. Гіперпосилання на офіційну сторінку додатку із зазначенням авторства.
## Налаштування
![gh-settings-ua](https://github.com/achiez/NebulaAuth-Steam-Desktop-Authenticator-by-Achies/assets/106531132/3f57e58d-d647-42a1-a4c9-ca53ab7b38a3)
1. Режим фону. Використовуйте, якщо ви хочете вимкнути фон або встановити власний (помістіть файл "Background.png" у папку програми)
2. Мова локалізації
3. Вимкнути таймери під час перемикання між обліковими записами
4. Приховувати у трей при згортанні
5. Індикатор із кольором. Маленький кружечок на піктограмі панелі завдань з довільним кольором. Корисно при використанні кількох вікон.
6. Власний колір програми.
7. Поточний пароль шифрування. Якщо встановлено, ви можете зберігати зашифровані паролі в mafile, щоб полегшити повторний вхід до системи у разі проблеми з сесією. (Не рекомендується)
8. Режим застарілих файлів. Режим сумісності Mafile з іншими клієнтами (SDA тощо). Якщо встановлено, програма зберігатиме файли у старому стандартному форматі (за замовчуванням: увімкнено).
9. Дозволити автооновлення без підтвердження
## [Ліцензія](/LICENSE.md)
Комерційне використання заборонено. У разі поширення зміненого коду необхідно вказувати оригінальне авторство.
+25 -46
View File
@@ -1,36 +1,44 @@
# NebulaAuth
* [Русский](README-RU.md)
* [Українська](README-UA.md)
## Description
<h3 align="center" style="margin-bottom:0">
<a href="https://github.com/achiez/NebulaAuth-Steam-Desktop-Authenticator-by-Achies/releases/latest">Download latest version</a>
</h3>
<h3 align="center">NebulaAuth is an application for emulating actions from the Steam Mobile App. Which replaces your smartphone when operating on Steam. </h3>
<h3 align="center">
NebulaAuth is an application for emulating actions from the Steam Mobile App, replacing your smartphone when operating on Steam.
</h3>
<p align="center">
<sub>NebulaAuth is an independent project and is not affiliated with Valve or Steam.</sub>
</p>
<h4 align="center"><a href="https://t.me/nebulaauth">Official Telegram Group</a></h4>
<h4 align="center"><a href="https://achiefy-project.gitbook.io/nebulaauth">Documentation</a></h4>
## Main advantages
- **Localization in three languages**: English, Russian and Ukrainian.
<p align="center">
<img src="misc/main_window.png" width="600"/>
</p>
- **Localization in six languages**: English, Russian, Ukrainian, Spanish, Turkish and Kazakh.
- **Full functionality of Steam Desktop Authenticator** reimagining [old app](https://github.com/Jessecar96/SteamDesktopAuthenticator)
- **Proxy support** in all account work processes.
- **Mafile grouping** for improved management.
- **Automatic confirmations of trades/market actions** to save time.
- **Bulk import of .mafiles** via Drag'n'Drop or CTRL+V for convenience.
- **Bulk import of .mafiles** via Drag'n'Drop or Ctrl+V, including SDA-encrypted mafiles with automatic manifest detection.
- **Design customization** to personalize the interface.
- **Ability to confirm account login without entering a code** for easier access.
- **Auto-update** program to use the latest features.
- **Auto-update** with SHA256 checksum verification, changelog viewer and flexible update options.
- **Automatic relogin in case of problems with the session** for continuous operation.
- **Intuitive interface** with tips and conveniences
- **Continious support** of application code and other features.
- **Intuitive interface** with tips and conveniences.
- **Continuous support** of application code and other features.
## Documentation
You can find the documentation for the application [here](https://achiefy-project.gitbook.io/nebulaauth). Currently, only the Russian version is available, but the English version will be released soon.
## Installation
1. If the application does not start, you need to install [.NET Desktop Runtime](https://dotnet.microsoft.com/en-us/download/dotnet/8.0)
@@ -39,40 +47,11 @@
4. Unpack the .zip file to any folder
5. Run the file **NebulaAuth.exe**
## Usage
![gh-main-window-eng](https://github.com/achiez/NebulaAuth-Steam-Desktop-Authenticator-by-Achies/assets/106531132/15c0e870-1766-43a5-9e8c-2f34d5436beb)
1. Control panel.
- file management and settings
- account management (login, linking, unlinking)
- grouping
- proxy selection
- an indicator with a hint about the proxy used (lit either yellow or red, when hovered it will display additional information)
- timers for automatic confirmation of trade offers/sale offers on the marketplace
- confirmation timer interval (in seconds)
2. List of your accounts
3. Login confirmation code (click to copy)
4. Main confirmation window
5. Search by login or SteamID (7xxxxxxxxxxxxx)
6. Confirm login on another device
7. Hyperlink to the official application page with attribution
## Project Ownership
## Settings
![gh-settings-eng](https://github.com/achiez/NebulaAuth-Steam-Desktop-Authenticator-by-Achies/assets/106531132/cd704495-d2df-45a7-a73e-40c19410eb72)
NebulaAuth is the original project by Achiefy™.
1. Background mode. Use it if you want to disable default or set custom background of application (put file 'Background.png' to your application folder)
2. Localization language
3. Disable timers when switching between accounts
4. Hide to tray on minimize
5. Indicator with color. Small ellipse on your task-bar icon with custom color. Useful when using multiple windows
6. Custom background color of application
7. Current encryption password. If set you can save encrypted passwords to mafile to help re-login on session troubles. (Not recommended)
8. Legacy mafile mode. Mafile compability mode for another applications (SDA and etc). If checked application will save mafiles with old standart format (Default: checked)
9. Allow auto-update without confirmation
Please keep attribution and do not present modified versions as official.
## [License](/LICENSE.md)
Commercial use prohibited. When redistributing modified code, you must indicate the original authorship.
AGPL-3.0 — see [LICENSE](/LICENSE).
+27
View File
@@ -0,0 +1,27 @@
<!DOCTYPE html>
<html>
<head>
<meta charset="UTF-8">
<title>Changelog</title>
<style>
body { font-family: Segoe UI, sans-serif; background:#eeeeee; padding:20px; }
.change { background:white; padding:25px; border-radius:10px; }
li { margin-bottom:6px; }
</style>
</head>
<body>
<div class="change">
<ul>
<li><b>NEW:</b> Introduced a redesigned update system with a custom update dialog and integrated changelog viewer <a href="https://github.com/achiez/NebulaAuth-Steam-Desktop-Authenticator-by-Achies/pull/19">details</a></li>
<li><b>NEW:</b> Added support for importing SDA-encrypted mafiles with automatic manifest detection <a href="https://github.com/achiez/NebulaAuth-Steam-Desktop-Authenticator-by-Achies/pull/17">details</a></li>
<li><b>NEW:</b> Grouped market confirmations can now be expanded to reveal individual items <a href="https://github.com/achiez/NebulaAuth-Steam-Desktop-Authenticator-by-Achies/pull/18">details</a></li>
<li><b>SECURITY:</b> Added SHA256 checksum verification for downloaded update packages</li>
<li><b>IMPROVEMENT:</b> Export feature now trims input automatically to prevent issues caused by invisible characters or extra spaces</li>
<li><b>IMPROVEMENT:</b> Improved update experience with 'Remind later' and 'Skip version' options</li>
<li><b>IMPROVEMENT:</b> Added visual update indicator and manual 'Check for updates' action</li>
<li><b>IMPROVEMENT:</b> Expanded localization support with Spanish, Turkish and Kazakh languages</li>
<li><b>INFO:</b> Read the full release notes for NebulaAuth 1.8.3 <a href="https://teletype.in/@achies_raw/o-RDwZKZkAU">details</a></li>
</ul>
</div>
</body>
</html>
+28
View File
@@ -0,0 +1,28 @@
<!DOCTYPE html>
<html>
<head>
<meta charset="UTF-8">
<title>Changelog</title>
<style>
body { font-family: Segoe UI, sans-serif; background:#eeeeee; padding:20px; }
.change { background:white; padding:25px; border-radius:10px; }
li { margin-bottom:6px; }
</style>
</head>
<body>
<div class="change">
<ul>
<li><b>FIX:</b> Rebuilt release package to include the missing NebulaAuth.exe file. Version 1.8.4 is functionally identical to 1.8.3 and only fixes the packaging issue that caused the executable to be absent in the previous release.</li>
<li><b>NEW:</b> Introduced a redesigned update system with a custom update dialog and integrated changelog viewer <a href="https://github.com/achiez/NebulaAuth-Steam-Desktop-Authenticator-by-Achies/pull/19">details</a></li>
<li><b>NEW:</b> Added support for importing SDA-encrypted mafiles with automatic manifest detection <a href="https://github.com/achiez/NebulaAuth-Steam-Desktop-Authenticator-by-Achies/pull/17">details</a></li>
<li><b>NEW:</b> Grouped market confirmations can now be expanded to reveal individual items <a href="https://github.com/achiez/NebulaAuth-Steam-Desktop-Authenticator-by-Achies/pull/18">details</a></li>
<li><b>SECURITY:</b> Added SHA256 checksum verification for downloaded update packages</li>
<li><b>IMPROVEMENT:</b> Export feature now trims input automatically to prevent issues caused by invisible characters or extra spaces</li>
<li><b>IMPROVEMENT:</b> Improved update experience with 'Remind later' and 'Skip version' options</li>
<li><b>IMPROVEMENT:</b> Added visual update indicator and manual 'Check for updates' action</li>
<li><b>IMPROVEMENT:</b> Expanded localization support with Spanish, Turkish and Kazakh languages</li>
<li><b>INFO:</b> Read the full release notes for NebulaAuth 1.8.3 <a href="https://teletype.in/@achies_raw/o-RDwZKZkAU">details</a></li>
</ul>
</div>
</body>
</html>
+50
View File
@@ -0,0 +1,50 @@
{
"version": "1.8.4",
"date": "2026-03-14",
"changes": [
{
"type": "FIX",
"text": "Rebuilt release package to include the missing NebulaAuth.exe file. Version 1.8.4 is functionally identical to 1.8.3 and only fixes the packaging issue that caused the executable to be absent in the previous release."
},
{
"type": "NEW",
"text": "Introduced a redesigned update system with a custom update dialog and integrated changelog viewer",
"link": "https://github.com/achiez/NebulaAuth-Steam-Desktop-Authenticator-by-Achies/pull/19"
},
{
"type": "NEW",
"text": "Added support for importing SDA-encrypted mafiles with automatic manifest detection",
"link": "https://github.com/achiez/NebulaAuth-Steam-Desktop-Authenticator-by-Achies/pull/17"
},
{
"type": "NEW",
"text": "Grouped market confirmations can now be expanded to reveal individual items",
"link": "https://github.com/achiez/NebulaAuth-Steam-Desktop-Authenticator-by-Achies/pull/18"
},
{
"type": "SECURITY",
"text": "Added SHA256 checksum verification for downloaded update packages"
},
{
"type": "IMPROVEMENT",
"text": "Export feature now trims input automatically to prevent issues caused by invisible characters or extra spaces"
},
{
"type": "IMPROVEMENT",
"text": "Improved update experience with 'Remind later' and 'Skip version' options"
},
{
"type": "IMPROVEMENT",
"text": "Added visual update indicator and manual 'Check for updates' action"
},
{
"type": "IMPROVEMENT",
"text": "Expanded localization support with Spanish, Turkish and Kazakh languages"
},
{
"type": "INFO",
"text": "Read the full release notes for NebulaAuth 1.8.3",
"link": "https://teletype.in/@achies_raw/o-RDwZKZkAU"
}
]
}
Binary file not shown.

After

Width:  |  Height:  |  Size: 335 KiB

-8
View File
@@ -1,8 +0,0 @@
<?xml version="1.0" encoding="UTF-8"?>
<item>
<version>1.5.6.0</version>
<url>https://github.com/achiez/NebulaAuth-Steam-Desktop-Authenticator-by-Achies/releases/download/1.5.6/NebulaAuth.1.5.6.zip</url>
<changelog>https://achiez.github.io/NebulaAuth-Steam-Desktop-Authenticator-by-Achies/changelog/1.5.6.html</changelog>
<mandatory>false</mandatory>
</item>
@@ -62,7 +62,7 @@ public partial class PortableMaClient : ObservableObject, IDisposable
SetStatus(newStatus);
ClientHandler.CookieContainer.ClearAllCookies();
ClientHandler.CookieContainer.SetSteamMobileCookiesWithMobileToken(sessionData);
ClientHandler.CookieContainer.SetSteamMobileCookies(sessionData);
}
+1 -1
View File
@@ -38,7 +38,7 @@ public static class MaClient
{
ClientHandler.CookieContainer.ClearAllCookies();
if (account == null) return;
ClientHandler.CookieContainer.SetSteamMobileCookiesWithMobileToken(account.SessionData);
ClientHandler.CookieContainer.SetSteamMobileCookies(account.SessionData);
Proxy.SetData(account.Proxy?.Data);
}
@@ -30,7 +30,7 @@ public partial class SessionHandler //API
//Trigger PropertyChanged event for PortableMaClient handling session updated from MaClient
mafile.SetSessionData(mafile.SessionData);
await Storage.UpdateMafileAsync(mafile);
chp.Handler.CookieContainer.SetSteamMobileCookiesWithMobileToken(mafile.SessionData);
chp.Handler.CookieContainer.SetSteamMobileCookies(mafile.SessionData);
}
public static async Task LoginAgain(HttpClientHandlerPair chp, Mafile mafile, string password, bool savePassword)
+1 -1
View File
@@ -10,7 +10,7 @@
<SatelliteResourceLanguages>en;ru;ua</SatelliteResourceLanguages>
<ApplicationIcon>Theme\lock.ico</ApplicationIcon>
<SupportedOSPlatformVersion>7.0</SupportedOSPlatformVersion>
<AssemblyVersion>1.8.3</AssemblyVersion>
<AssemblyVersion>1.8.4</AssemblyVersion>
<AllowUnsafeBlocks>true</AllowUnsafeBlocks>
</PropertyGroup>
@@ -54,33 +54,20 @@ public static class AdmissionHelper
return;
}
AddRefreshToken(container, sessionData.RefreshToken);
container.SetSteamRefreshToken(sessionData.RefreshToken);
var community = SteamDomains.GetDomainUri(SteamDomain.Community);
container.Add(community, new Cookie(SESSION_ID_COOKIE_NAME, sessionData.SessionId, "/"));
container.Add(community, new Cookie(LANGUAGE_COOKIE_NAME, setLanguage, "/"));
TransferCommunityCookies(container);
foreach (var domain in SteamDomains.AuthDomains)
foreach (var domain in SteamDomains.WebDomains)
{
var token = sessionData.GetToken(domain);
if (token == null) continue;
AddTokenCookie(container, token.Value);
container.SetSteamAccessToken(token.Value);
}
}
public static void SetDomainCookie(this CookieContainer container, SteamDomain domain, SteamAuthToken token)
{
var uri = SteamDomains.GetDomainUri(domain);
foreach (var cookie in container.GetCookies(uri)
.Where(c => !c.Expired && c.Name.EqualsIgnoreCase(ACCESS_COOKIE_NAME)))
{
cookie.Expired = true;
}
AddTokenCookie(container, token);
}
/// <summary>
/// Clear and set new session
/// </summary>
@@ -95,70 +82,22 @@ public static class AdmissionHelper
return;
}
AddRefreshToken(container, mobileSession.RefreshToken);
container.SetSteamRefreshToken(mobileSession.RefreshToken);
var community = SteamDomains.GetDomainUri(SteamDomain.Community);
container.Add(community, new Cookie("steamid", mobileSession.SteamId.Steam64.ToString()));
container.Add(community, new Cookie(SESSION_ID_COOKIE_NAME, mobileSession.SessionId));
container.Add(community, new Cookie(LANGUAGE_COOKIE_NAME, setLanguage));
TransferCommunityCookies(container);
foreach (var domain in SteamDomains.AuthDomains)
foreach (var domain in SteamDomains.WebDomains)
{
var token = mobileSession.GetToken(domain);
if (token == null) continue;
AddTokenCookie(container, token.Value);
var domainUri = SteamDomains.GetDomainUri(domain);
container.SetSteamAccessTokenUnsafe(token.Value, domainUri);
}
}
/// <summary>
/// Clear and set new session. Not recommended. Uses <see cref="IMobileSessionData.GetMobileToken()" /> for domain
/// <see cref="SteamDomain.Community" /> instead of its own cookie. It's okay to use it only for confirmations. But
/// Market, Trading and other pages won't be authorized
/// </summary>
public static void SetSteamMobileCookiesWithMobileToken(this CookieContainer container,
IMobileSessionData? mobileSession,
string setLanguage = "english")
{
container.ClearSteamCookies(setLanguage);
container.AddMinimalMobileCookies();
if (mobileSession == null)
{
TransferCommunityCookies(container);
return;
}
AddRefreshToken(container, mobileSession.RefreshToken);
var community = SteamDomains.GetDomainUri(SteamDomain.Community);
container.Add(community, new Cookie("steamid", mobileSession.SteamId.Steam64.ToString()));
container.Add(community, new Cookie(SESSION_ID_COOKIE_NAME, mobileSession.SessionId));
container.Add(community, new Cookie(LANGUAGE_COOKIE_NAME, setLanguage));
TransferCommunityCookies(container);
var domainCookieSet = false;
foreach (var domain in SteamDomains.AllDomains)
{
var token = mobileSession.GetToken(domain);
if (token == null || token.Value.IsExpired) continue;
if (domain == SteamDomain.Community)
domainCookieSet = true;
AddTokenCookie(container, token.Value);
}
var mobileToken = mobileSession.GetMobileToken();
if (!domainCookieSet && mobileToken is {IsExpired: false})
{
var domain = SteamDomains.GetDomainUri(SteamDomain.Community);
container.Add(domain, new Cookie(ACCESS_COOKIE_NAME, mobileToken.Value.SignedToken)
{
HttpOnly = true,
Secure = true,
Expires = mobileToken.Value.Expires.ToLocalDateTime()
});
}
}
public static void AddMinimalMobileCookies(this CookieContainer container)
{
@@ -229,27 +168,93 @@ public static class AdmissionHelper
}
}
public static void AddRefreshToken(CookieContainer container, SteamAuthToken token)
/// <summary>
/// Sets a Steam refresh token as a cookie to the specified cookie container.
/// </summary>
/// <remarks>
/// The added cookie will have its expiration set according to the token's expiration time. This
/// method is typically used to enable authenticated requests to Steam services that require a refresh
/// token.
/// </remarks>
/// <param name="container">The cookie container to which the Steam refresh token cookie will be added. Cannot be null.</param>
/// <param name="token">
/// The Steam authentication token to add as a refresh cookie. Must be of type Refresh or
/// MobileRefresh.
/// </param>
/// <exception cref="ArgumentException">Thrown if the token is not of type Refresh or MobileRefresh.</exception>
public static void SetSteamRefreshToken(this CookieContainer container, SteamAuthToken token)
{
if (token.Type is not (SteamAccessTokenType.Refresh or SteamAccessTokenType.MobileRefresh))
throw new ArgumentException(
$"Token must be of type Refresh or MobileRefresh. Provided token has type: {token.Type}",
nameof(token));
var refreshToken = token.SignedToken;
container.Add(SteamLoginUri, new Cookie(REFRESH_COOKIE_NAME, refreshToken)
SetSteamRefreshTokenUnsafe(container, token, SteamLoginUri);
}
/// <summary>
/// Sets a Steam refresh token as a cookie to the specified cookie container for the given domain.
/// </summary>
/// <remarks>
/// This method does not perform validation on the input parameters. Callers must ensure that the
/// provided values are valid and appropriate for use.
/// </remarks>
/// <param name="container">The cookie container to which the refresh token cookie will be added. Cannot be null.</param>
/// <param name="token">
/// The Steam authentication token containing the signed token value and expiration information. Cannot
/// be null.
/// </param>
/// <param name="domainUri">The URI of the domain for which the refresh token cookie should be set. Cannot be null.</param>
public static void SetSteamRefreshTokenUnsafe(CookieContainer container, SteamAuthToken token, Uri domainUri)
{
container.Add(domainUri, new Cookie(REFRESH_COOKIE_NAME, token.SignedToken)
{
Expires = token.Expires.ToLocalDateTime()
});
}
public static void AddTokenCookie(CookieContainer container, SteamAuthToken token)
/// <summary>
/// Sets a Steam access token to the specified cookie container for use with Steam web requests.
/// </summary>
/// <remarks>
/// This method is intended for standard web access tokens bound to a specific Steam web domain.
/// Mobile tokens are intentionally rejected, since their audiences are capability-based rather
/// than domain-based and may grant access to multiple web domains.
/// </remarks>
/// <param name="container">The cookie container to which the Steam access token will be added. Cannot be null.</param>
/// <param name="token">
/// The Steam access token to add. Must be of type AccessToken and associated with a valid Steam
/// domain.
/// </param>
/// <exception cref="ArgumentException">Thrown if the token is not of type AccessToken.</exception>
public static void SetSteamAccessToken(this CookieContainer container, SteamAuthToken token)
{
if (token.Type == SteamAccessTokenType.Mobile)
throw new ArgumentException(
$"Mobile access tokens cannot be added using this method. Use SetSteamAccessTokenUnsafe instead. Provided token has type: {token.Type}",
nameof(token));
if (token.Type is not SteamAccessTokenType.AccessToken)
throw new ArgumentException($"Token must be of type AccessToken. Provided token has type: {token.Type}",
nameof(token));
var domain = SteamDomains.GetDomainUri(token.Domain);
container.Add(domain, new Cookie(ACCESS_COOKIE_NAME, token.SignedToken)
var domainUri = SteamDomains.GetDomainUri(token.Domain);
container.SetSteamAccessTokenUnsafe(token, domainUri);
}
/// <summary>
/// Sets a Steam access token as a secure, HTTP-only cookie to the specified cookie container for the given domain.
/// </summary>
/// <remarks>
/// This method does not perform validation on the input parameters and should only be used when
/// input values are trusted. The added cookie is marked as secure and HTTP-only, and its expiration is set
/// according to the token's expiration time.
/// </remarks>
/// <param name="container">The cookie container to which the Steam access token cookie will be added. Cannot be null.</param>
/// <param name="token">The Steam access token to add as a cookie. Must contain a valid signed token and expiration.</param>
/// <param name="domainUri">The URI of the domain for which the cookie will be set. Cannot be null.</param>
public static void SetSteamAccessTokenUnsafe(this CookieContainer container, SteamAuthToken token, Uri domainUri)
{
container.Add(domainUri, new Cookie(ACCESS_COOKIE_NAME, token.SignedToken)
{
HttpOnly = true,
Secure = true,
@@ -257,7 +262,6 @@ public static class AdmissionHelper
});
}
public static bool IsSteamCookie(Cookie cookie)
{
return cookie.Domain.Contains("steamcommunity.com") || cookie.Domain.Contains("steampowered.com") ||
+29 -35
View File
@@ -1,49 +1,43 @@
using System.Collections.ObjectModel;
using SteamLibForked.Models.Core;
using SteamLibForked.Models.Core;
using System.Collections.Immutable;
namespace SteamLib.Core;
public static class SteamDomains
{
public static IReadOnlyDictionary<SteamDomain, string> Domains { get; } =
new ReadOnlyDictionary<SteamDomain, string>(
new Dictionary<SteamDomain, string>
{
{SteamDomain.Community, SteamConstants.STEAM_COMMUNITY},
{SteamDomain.Store, SteamConstants.STEAM_STORE},
{SteamDomain.Help, SteamConstants.STEAM_HELP},
{SteamDomain.TV, SteamConstants.STEAM_TV},
{SteamDomain.Checkout, SteamConstants.STEAM_CHECKOUT},
{SteamDomain.Login, SteamConstants.STEAM_LOGIN},
{SteamDomain.API, SteamConstants.STEAM_API}
});
new Dictionary<SteamDomain, string>
{
{SteamDomain.Community, SteamConstants.STEAM_COMMUNITY},
{SteamDomain.Store, SteamConstants.STEAM_STORE},
{SteamDomain.Help, SteamConstants.STEAM_HELP},
{SteamDomain.TV, SteamConstants.STEAM_TV},
{SteamDomain.Checkout, SteamConstants.STEAM_CHECKOUT},
{SteamDomain.Login, SteamConstants.STEAM_LOGIN},
{SteamDomain.API, SteamConstants.STEAM_API}
}.ToImmutableDictionary();
public static IReadOnlyDictionary<SteamDomain, Uri> DomainUris { get; }
= new ReadOnlyDictionary<SteamDomain, Uri>(
Domains.ToDictionary(x => x.Key, x => new Uri(x.Value))
);
= Domains
.ToDictionary(x => x.Key, x => new Uri(x.Value))
.ToImmutableDictionary();
public static IEnumerable<SteamDomain> AllDomains { get; } =
[
SteamDomain.Community,
SteamDomain.Store,
SteamDomain.Help,
SteamDomain.TV,
SteamDomain.Checkout,
SteamDomain.Login,
SteamDomain.API
];
public static IEnumerable<SteamDomain> AuthDomains { get; } =
[
SteamDomain.Community,
SteamDomain.Store,
SteamDomain.Help,
SteamDomain.TV,
SteamDomain.Checkout
];
/// <summary>
/// All known public Steam domains.
/// </summary>
public static IEnumerable<SteamDomain> AllDomains { get; } = ImmutableHashSet.Create(SteamDomain.Community,
SteamDomain.Store, SteamDomain.Help, SteamDomain.TV, SteamDomain.Checkout, SteamDomain.Login, SteamDomain.API);
/// <summary>
/// Steam web domains that participate in the standard login authorization flow.
/// <para>
/// These domains use the <c>web:*</c> audience format and receive
/// authentication cookies/tokens during session initialization.
/// </para>
/// </summary>
public static IReadOnlySet<SteamDomain> WebDomains { get; } = ImmutableHashSet.Create(SteamDomain.Community,
SteamDomain.Store, SteamDomain.Help, SteamDomain.TV, SteamDomain.Checkout);
public static Uri GetDomainUri(SteamDomain domain)
{
@@ -1,13 +1,14 @@
using System.Diagnostics.CodeAnalysis;
using Newtonsoft.Json;
using Newtonsoft.Json;
using SteamLib.Core;
using SteamLibForked.Abstractions;
using SteamLibForked.Models.Core;
using System.Diagnostics.CodeAnalysis;
namespace SteamLibForked.Models.Session;
//WARNING: Any changes here should be reflected in MafileSerializer.cs
public sealed class MobileSessionData : SessionData, IMobileSessionData
public class MobileSessionData : SessionData, IMobileSessionData
{
public SteamAuthToken? MobileToken { get; private set; }
@@ -31,26 +32,39 @@ public sealed class MobileSessionData : SessionData, IMobileSessionData
return MobileToken;
}
public override SteamAuthToken? GetToken(SteamDomain domain)
{
var isWeb = SteamDomains.WebDomains.Contains(domain);
if (isWeb)
{
// Mobile-issued tokens usually contain the "web" audience,
// so we assume they can also be used for all web:* domains.
// See: SteamAuthToken 'TODO' for more details
return MobileToken ?? base.GetToken(domain);
}
return base.GetToken(domain);
}
[MemberNotNull(nameof(MobileToken))]
public void SetMobileToken(SteamAuthToken token)
public virtual void SetMobileToken(SteamAuthToken token)
{
if (token.Type != SteamAccessTokenType.Mobile)
throw new ArgumentException("Token must be of type MobileAccess", nameof(token))
{
Data = {{"ActualType", token.Type}}
Data = { { "ActualType", token.Type } }
};
MobileToken = token;
}
public override MobileSessionData Clone()
{
return (MobileSessionData) ((ISessionData) this).Clone();
}
object ICloneable.Clone()
{
return new MobileSessionData(SessionId, SteamId, RefreshToken, MobileToken, Tokens);
}
public override MobileSessionData Clone()
{
return (MobileSessionData)((ISessionData)this).Clone();
}
}
+1 -1
View File
@@ -31,7 +31,7 @@ public static class ClientBuilder
}
else
{
container.SetSteamMobileCookiesWithMobileToken(sessionData);
container.SetSteamMobileCookies(sessionData);
}
//Nebula tweak: