Saturday, 17 September 2011

Importing Yahoo contacts In ASP.NET

I am using OAuth to retrieve Yahoo Contacts. First lets see how oauth works:
You can request for an API key by navigating this this link.. You have to fill up the web form before you request for a key. There are 2 steps. The first step is filling out app specific information and request for an API key and the second step is to specify what services can be accessible by the API key. You can choose to access all public resources or alternatively, you can specify which services you are particularly interested in.
Step 1: Setting up App Information & Get API Key
Configuration Notes
  • Application URL: This is the URL where your application resides.You can point out the root of the application here. For my app, I mentioned as app URL.
  • Choose an appropriate application name (my application name is qcontactreader).
  • Specify app kind, my sample app is web based.
  • Provide a small description about your application.
  • Access scope: Choose "This app requires access to private user data." option as my sample app is going to access the user contact list.
  • Hit Get API key and you are ready to roll.
<%@ Page Language="C#" AutoEventWireup="true" CodeFile="oauth-test.aspx.cs" Inherits="test_oauth_test" %>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "">
<html xmlns="">
<head runat="server">
    <title>Untitled Page</title>
    <form id="form1" runat="server">
        <asp:Button ID="Button1" runat="server" Text="Connect to Yahoo!" OnClick="Button1_Click" />
        <asp:Label runat="server" ID="ResponseMessage1"></asp:Label>
        <asp:GridView ID="grvMyFriends" runat="server" AutoGenerateColumns="false" CellPadding="5"
                <asp:TemplateField HeaderText="Email">
                        <%# Container.DataItem %>
                No Friend List Found
using System;
using System.Configuration;
using System.Data;
using System.Web;
using System.Web.Security;
using System.Web.UI;
using System.Web.UI.HtmlControls;
using System.Web.UI.WebControls;
using System.Web.UI.WebControls.WebParts;
using System.Net;
using System.IO;
using OAuth.Net.Common;
using OAuth.Net.Components;
using OAuth.Net.Consumer;
using OAuth;
using System.Text;
using System.Xml;
using System.Collections;
using System.Collections.Generic;
using System.Net.Mail;
using System.Text.RegularExpressions;
public partial class test_oauth_test : System.Web.UI.Page
    public string ConsumerKey
            return "YOUR_CONSUMER_KEY";
    public string ConsumerSecret
            return "YOUR_CUSTOMER_SECRET_KEY";
    public string OauthVerifier
                if (!string.IsNullOrEmpty(Session["Oauth_Verifier"].ToString()))
                    return Session["Oauth_Verifier"].ToString();
                    return string.Empty;
                return string.Empty;
            Session["Oauth_Verifier"] = value;
    public string OauthToken
            if (!string.IsNullOrEmpty(Session["Oauth_Token"].ToString()))
                return Session["Oauth_Token"].ToString();
                return string.Empty;
            Session["Oauth_Token"] = value;
    public string OauthTokenSecret
            if (!string.IsNullOrEmpty(Session["Oauth_Token_Secret"].ToString()))
                return Session["Oauth_Token_Secret"].ToString();
                return string.Empty;
            Session["Oauth_Token_Secret"] = value;
    public string OauthSessionHandle
            if (!string.IsNullOrEmpty(Session["Oauth_Session_Handle"]
                return Session["Oauth_Session_Handle"].ToString();
                return string.Empty;
            Session["Oauth_Session_Handle"] = value;
    public string OauthYahooGuid
                if (!string.IsNullOrEmpty(Session["Oauth_Yahoo_Guid"].ToString()))
                    return Session["Oauth_Yahoo_Guid"].ToString();
                    return string.Empty;
                return string.Empty;
            Session["Oauth_Yahoo_Guid"] = value;
    protected void Page_Load(object sender, EventArgs e)
        if (!IsPostBack)
            string oauth_token = Request["oauth_token"];
            string oauth_verifier = Request["oauth_verifier"];
            if (!string.IsNullOrEmpty(oauth_verifier) && oauth_verifier != "")
                Button1.Visible = false;
                OauthToken = oauth_token;
                OauthVerifier = oauth_verifier;
                RegisterStartupScript("refresh", "<script type='text/javascript'>
window.opener.location = 'oauth-test.aspx'; self.close();</script>");
            else if (!string.IsNullOrEmpty(OauthVerifier))
                Button1.Visible = false;
                if (string.IsNullOrEmpty(OauthYahooGuid))
                    GetAccessToken(OauthToken, OauthVerifier);
    private string GetRequestToken()
        string authorizationUrl = string.Empty;
        OAuthBase oauth = new OAuthBase();
        Uri uri = new Uri("");
        string nonce = oauth.GenerateNonce();
        string timeStamp = oauth.GenerateTimeStamp();
        string normalizedUrl;
        string normalizedRequestParameters;
        string sig = oauth.GenerateSignature(uri, ConsumerKey,
ConsumerSecret, string.Empty, string.Empty, "GET", timeStamp, nonce, OAuthBase.SignatureTypes.PLAINTEXT, out normalizedUrl, out normalizedRequestParameters); //OAuthBase.SignatureTypes.HMACSHA1
        StringBuilder sbRequestToken = new StringBuilder(uri.ToString());
        sbRequestToken.AppendFormat("?oauth_nonce={0}&", nonce);
        sbRequestToken.AppendFormat("oauth_timestamp={0}&", timeStamp);
        sbRequestToken.AppendFormat("oauth_consumer_key={0}&", ConsumerKey);
        sbRequestToken.AppendFormat("oauth_signature_method={0}&", "PLAINTEXT");
        sbRequestToken.AppendFormat("oauth_signature={0}&", sig);
        sbRequestToken.AppendFormat("oauth_version={0}&", "1.0");
        sbRequestToken.AppendFormat("oauth_callback={0}", HttpUtility.UrlEncode(""));
            string returnStr = string.Empty;
            string[] returnData;
            HttpWebRequest req = (HttpWebRequest)WebRequest.Create(sbRequestToken.ToString());
            HttpWebResponse res = (HttpWebResponse)req.GetResponse();
            StreamReader streamReader = new StreamReader(res.GetResponseStream());
            returnStr = streamReader.ReadToEnd();
            returnData = returnStr.Split(new Char[] { '&' });
            int index;
            if (returnData.Length > 0)
                //index = returnData[0].IndexOf("=");
                //string oauth_token = returnData[0].Substring(index + 1);
                //Session["Oauth_Token"] = oauth_token;
                index = returnData[1].IndexOf("=");
                string oauth_token_secret = returnData[1].Substring(index + 1);
                OauthTokenSecret = oauth_token_secret;
                //index = returnData[2].IndexOf("=");
                //int oauth_expires_in;
                //Int32.TryParse(returnData[2].Substring(index + 1), out oauth_expires_in);
                //Session["Oauth_Expires_In"] = oauth_expires_in;
                index = returnData[3].IndexOf("=");
                string oauth_request_auth_url = returnData[3].Substring(index + 1);
                authorizationUrl = HttpUtility.UrlDecode(oauth_request_auth_url);
        catch (WebException ex)
        return authorizationUrl;
    private void RedirectUserForAuthorization(string authorizationUrl)
        RegisterStartupScript("openwin", "<script type='text/javascript'>'" + authorizationUrl + "','mywindow', 'left=250,top=50,menubar=0,resizable=0,
    private void GetAccessToken(string oauth_token, string oauth_verifier)
        OAuthBase oauth = new OAuthBase();
        Uri uri = new Uri("");
        string nonce = oauth.GenerateNonce();
        string timeStamp = oauth.GenerateTimeStamp();
        string sig = ConsumerSecret + "%26" + OauthTokenSecret;
        StringBuilder sbAccessToken = new StringBuilder(uri.ToString());
        sbAccessToken.AppendFormat("?oauth_consumer_key={0}&", ConsumerKey);
        sbAccessToken.AppendFormat("oauth_signature_method={0}&", "PLAINTEXT");
        sbAccessToken.AppendFormat("oauth_signature={0}&", sig);
        sbAccessToken.AppendFormat("oauth_timestamp={0}&", timeStamp);
        sbAccessToken.AppendFormat("oauth_version={0}&", "1.0");
        sbAccessToken.AppendFormat("oauth_token={0}&", oauth_token);
        sbAccessToken.AppendFormat("oauth_nonce={0}&", nonce);
        sbAccessToken.AppendFormat("oauth_verifier={0}", oauth_verifier);
            string returnStr = string.Empty;
            string[] returnData;
            HttpWebRequest req = (HttpWebRequest)WebRequest.Create(sbAccessToken.ToString());
            HttpWebResponse res = (HttpWebResponse)req.GetResponse();
            StreamReader streamReader = new StreamReader(res.GetResponseStream());
            returnStr = streamReader.ReadToEnd();
            returnData = returnStr.Split(new Char[] { '&' });
            int index;
            if (returnData.Length > 0)
                index = returnData[0].IndexOf("=");
                OauthToken = returnData[0].Substring(index + 1);
                index = returnData[1].IndexOf("=");
                string oauth_token_secret = returnData[1].Substring(index + 1);
                OauthTokenSecret = oauth_token_secret;
                //index = returnData[2].IndexOf("=");
                //int oauth_expires_in;
                //Int32.TryParse(returnData[2].Substring(index + 1), out oauth_expires_in);
                index = returnData[3].IndexOf("=");
                string oauth_session_handle = returnData[3].Substring(index + 1);
                OauthSessionHandle = oauth_session_handle;
                //index = returnData[4].IndexOf("=");
                //int oauth_authorization_expires_in;
                //Int32.TryParse(returnData[4].Substring(index + 1), out oauth_authorization_expires_in);
                index = returnData[5].IndexOf("=");
                string xoauth_yahoo_guid = returnData[5].Substring(index + 1);
                OauthYahooGuid = xoauth_yahoo_guid;
        catch (WebException ex)
    private void RefreshToken()
        OAuthBase oauth = new OAuthBase();
        Uri uri = new Uri("");
        string nonce = oauth.GenerateNonce();
        string timeStamp = oauth.GenerateTimeStamp();
        string sig = ConsumerSecret + "%26" + OauthTokenSecret;
        StringBuilder sbrefreshToken = new StringBuilder(uri.ToString());
        sbrefreshToken.AppendFormat("?oauth_consumer_key={0}&", ConsumerKey);
        sbrefreshToken.AppendFormat("oauth_signature_method={0}&", "PLAINTEXT");
        sbrefreshToken.AppendFormat("oauth_signature={0}&", sig);
        sbrefreshToken.AppendFormat("oauth_timestamp={0}&", timeStamp);
        sbrefreshToken.AppendFormat("oauth_version={0}&", "1.0");
        sbrefreshToken.AppendFormat("oauth_token={0}&", OauthToken);
        sbrefreshToken.AppendFormat("oauth_session_handle={0}&", OauthSessionHandle);
        sbrefreshToken.AppendFormat("oauth_nonce={0}", nonce);
            string returnStr = string.Empty;
            string[] returnData;
            HttpWebRequest req = (HttpWebRequest)WebRequest.Create(sbrefreshToken.ToString());
            HttpWebResponse res = (HttpWebResponse)req.GetResponse();
            StreamReader streamReader = new StreamReader(res.GetResponseStream());
            returnStr = streamReader.ReadToEnd();
            returnData = returnStr.Split(new Char[] { '&' });
            int index;
            if (returnData.Length > 0)
                index = returnData[0].IndexOf("=");
                string oauth_token = returnData[0].Substring(index + 1);
                OauthToken = oauth_token;
                index = returnData[1].IndexOf("=");
                string oauth_token_secret = returnData[1].Substring(index + 1);
                OauthTokenSecret = oauth_token_secret;
                //index = returnData[2].IndexOf("=");
                //int oauth_expires_in;
                //Int32.TryParse(returnData[2].Substring(index + 1), out oauth_expires_in);
                index = returnData[3].IndexOf("=");
                string oauth_session_handle = returnData[3].Substring(index + 1);
                OauthSessionHandle = oauth_session_handle;
                //index = returnData[4].IndexOf("=");
                //int oauth_authorization_expires_in;
                //Int32.TryParse(returnData[4].Substring(index + 1), out oauth_authorization_expires_in);
                index = returnData[5].IndexOf("=");
                string xoauth_yahoo_guid = returnData[5].Substring(index + 1);
                OauthYahooGuid = xoauth_yahoo_guid;
        catch (WebException ex)
    private void RetriveContacts()
        OAuthBase oauth = new OAuthBase();
        Uri uri = new Uri("" + OauthYahooGuid + "/contacts?format=XML");
        string nonce = oauth.GenerateNonce();
        string timeStamp = oauth.GenerateTimeStamp();
        string normalizedUrl;
        string normalizedRequestParameters;
        string sig = oauth.GenerateSignature(uri, ConsumerKey, ConsumerSecret, OauthToken, OauthTokenSecret, "GET", timeStamp, nonce, OAuthBase.SignatureTypes.HMACSHA1,
out normalizedUrl, out normalizedRequestParameters);
        StringBuilder sbGetContacts = new StringBuilder(uri.ToString());
        //Response.Write("URL: " + sbGetContacts.ToString());
            string returnStr = string.Empty;
            HttpWebRequest req = (HttpWebRequest)WebRequest.Create(sbGetContacts.ToString());
            req.Method = "GET";
            string authHeader = "Authorization: OAuth " +
            "realm=\"\"" +
            ",oauth_consumer_key=\"" + ConsumerKey + "\"" +
            ",oauth_nonce=\"" + nonce + "\"" +
            ",oauth_signature_method=\"HMAC-SHA1\"" +
            ",oauth_timestamp=\"" + timeStamp + "\"" +
            ",oauth_token=\"" + OauthToken + "\"" +
            ",oauth_version=\"1.0\"" +
            ",oauth_signature=\"" + HttpUtility.UrlEncode(sig) + "\"";
            //Response.Write("</br>Headers: " + authHeader);
            HttpWebResponse res = (HttpWebResponse)req.GetResponse();
            StreamReader streamReader = new StreamReader(res.GetResponseStream());
            returnStr = streamReader.ReadToEnd();
            XmlDocument xmldoc = new XmlDocument();
            XmlNodeList elemList = xmldoc.DocumentElement.GetElementsByTagName("fields");
            ArrayList emails = new ArrayList();
            for (int i = 0; i < elemList.Count; i++)
                if (elemList[i].ChildNodes[1].InnerText == "email")
                //Response.Write(elemList[i].ChildNodes[2].InnerText + "<br/>");
            grvMyFriends.DataSource = emails;
        #region error
        catch (WebException ex)
            Response.Write("<br/>" + ex.Message + "</br>xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx");
            Response.Write("<br/>length: " + ex.Source.Length.ToString());
            Response.Write("<br/>stack trace: " + ex.StackTrace);
            Response.Write("<br/>status: " + ex.Status.ToString());
            HttpWebResponse res = (HttpWebResponse)ex.Response;
            int code = Convert.ToInt32(res.StatusCode);
            Response.Write("<br/>Status Code: (" + code.ToString() + ") " + res.StatusCode.ToString());
            Response.Write("<br/>Status Description: " + res.StatusDescription);
            if (ex.InnerException != null)
                Response.Write("<br/>innerexception: " + ex.InnerException.Message);
            if (ex.Source.Length > 0)
                Response.Write("<br/>source: " + ex.Source.ToString());
            if (res != null)
                for (int i = 0; i < res.Headers.Count; i++)
                    Response.Write("<br/>headers: " + i.ToString() + ": " + res.Headers[i]);
        #endregion error
    protected void Button1_Click(object sender, EventArgs e)
        string authorizationUrl = string.Empty;
        authorizationUrl = GetRequestToken();
using System;
using System.Security.Cryptography;
using System.Collections.Generic;
using System.Text;
using System.Web;
public class OAuthBase
    /// <summary>
    /// Provides a predefined set of algorithms that are supported
officially by the protocol
    /// </summary>
    public enum SignatureTypes
    /// <summary>
    /// Provides an internal structure to sort the query parameter
    /// </summary>
    protected class QueryParameter
        private string name = null;
        private string value = null;
        public QueryParameter(string name, string value)
   = name;
            this.value = value;
        public string Name
            get { return name; }
        public string Value
            get { return value; }
    /// <summary>
    /// Comparer class used to perform the sorting of the query parameters
    /// </summary>
    protected class QueryParameterComparer : IComparer<QueryParameter>
        #region IComparer<QueryParameter> Members
        public int Compare(QueryParameter x, QueryParameter y)
            if (x.Name == y.Name)
                return string.Compare(x.Value, y.Value);
                return string.Compare(x.Name, y.Name);
    protected const string OAuthVersion = "1.0";
    protected const string OAuthParameterPrefix = "oauth_";
    // List of know and used oauth parameters' names
    protected const string OAuthConsumerKeyKey = "oauth_consumer_key";
    protected const string OAuthCallbackKey = "oauth_callback";
    protected const string OAuthVersionKey = "oauth_version";
    protected const string OAuthSignatureMethodKey = "oauth_signature_method";
    protected const string OAuthSignatureKey = "oauth_signature";
    protected const string OAuthTimestampKey = "oauth_timestamp";
    protected const string OAuthNonceKey = "oauth_nonce";
    protected const string OAuthTokenKey = "oauth_token";
    protected const string OAuthTokenSecretKey = "oauth_token_secret";
    protected const string HMACSHA1SignatureType = "HMAC-SHA1";
    protected const string PlainTextSignatureType = "PLAINTEXT";
    protected const string RSASHA1SignatureType = "RSA-SHA1";
    protected Random random = new Random();
    protected string unreservedChars = "abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRST
    /// <summary>
    /// Helper function to compute a hash value
    /// </summary>
    /// <param name="hashAlgorithm">The hashing algoirhtm used. If that algorithm needs some initialization, like HMAC and its derivatives, they should be initialized prior to passing it to this function</param>
    /// <param name="data">The data to hash</param>
    /// <returns>a Base64 string of the hash value</returns>
    private string ComputeHash(HashAlgorithm hashAlgorithm, string data)
        if (hashAlgorithm == null)
            throw new ArgumentNullException("hashAlgorithm");
        if (string.IsNullOrEmpty(data))
            throw new ArgumentNullException("data");
        byte[] dataBuffer = System.Text.Encoding.ASCII.GetBytes(data);
        byte[] hashBytes = hashAlgorithm.ComputeHash(dataBuffer);
        return Convert.ToBase64String(hashBytes);
    /// <summary>
    /// Internal function to cut out all non oauth query string parameters (all parameters not begining with "oauth_")
    /// </summary>
    /// <param name="parameters">The query string part of the Url</param>
    /// <returns>A list of QueryParameter each containing the parameter name and value</returns>
    private List<QueryParameter> GetQueryParameters(string parameters)
        if (parameters.StartsWith("?"))
            parameters = parameters.Remove(0, 1);
        List<QueryParameter> result = new List<QueryParameter>();
        if (!string.IsNullOrEmpty(parameters))
            string[] p = parameters.Split('&');
            foreach (string s in p)
                if (!string.IsNullOrEmpty(s) && !s.StartsWith(OAuthParameterPrefix))
                    if (s.IndexOf('=') > -1)
                        string[] temp = s.Split('=');
                        result.Add(new QueryParameter(temp[0], temp[1]));
                        result.Add(new QueryParameter(s, string.Empty));
        return result;
    /// <summary>
    /// This is a different Url Encode implementation since the default .NET one outputs the percent encoding in lower case.
    /// While this is not a problem with the percent encoding spec, it is used in upper case throughout OAuth
    /// </summary>
    /// <param name="value">The value to Url encode</param>
    /// <returns>Returns a Url encoded string</returns>
    protected string UrlEncode(string value)
        StringBuilder result = new StringBuilder();
        foreach (char symbol in value)
            if (unreservedChars.IndexOf(symbol) != -1)
                result.Append('%' + String.Format("{0:X2}", (int)symbol));
        return result.ToString();
    /// <summary>
    /// Normalizes the request parameters according to the spec
    /// </summary>
    /// <param name="parameters">The list of parameters already sorted</param>
    /// <returns>a string representing the normalized parameters</returns>
    protected string NormalizeRequestParameters(IList<QueryParameter> parameters)
        StringBuilder sb = new StringBuilder();
        QueryParameter p = null;
        for (int i = 0; i < parameters.Count; i++)
            p = parameters[i];
            sb.AppendFormat("{0}={1}", p.Name, p.Value);
            if (i < parameters.Count - 1)
        return sb.ToString();
    /// <summary>
    /// Generate the signature base that is used to produce the signature
    /// </summary>
    /// <param name="url">The full url that needs to be signed including its non OAuth url parameters</param>
    /// <param name="consumerKey">The consumer key</param>       
    /// <param name="token">The token, if available. If not available pass null or an empty string</param>
    /// <param name="tokenSecret">The token secret, if available. If not available pass null or an empty string</param>
    /// <param name="httpMethod">The http method used. Must be a valid HTTP method verb (POST,GET,PUT, etc)</param>
    /// <param name="signatureType">The signature type. To use the default values use <see cref="OAuthBase.SignatureTypes">OAuthBase.SignatureTypes</see>.</param>
    /// <returns>The signature base</returns>
    public string GenerateSignatureBase(Uri url, string consumerKey, string token, string tokenSecret, string httpMethod, string timeStamp, string nonce, string signatureType, out string normalizedUrl, out string normalizedRequestParameters)
        if (token == null)
            token = string.Empty;
        if (tokenSecret == null)
            tokenSecret = string.Empty;
        if (string.IsNullOrEmpty(consumerKey))
            throw new ArgumentNullException("consumerKey");
        if (string.IsNullOrEmpty(httpMethod))
            throw new ArgumentNullException("httpMethod");
        if (string.IsNullOrEmpty(signatureType))
            throw new ArgumentNullException("signatureType");
        normalizedUrl = null;
        normalizedRequestParameters = null;
        List<QueryParameter> parameters = GetQueryParameters(url.Query);
        parameters.Add(new QueryParameter(OAuthVersionKey, OAuthVersion));
        parameters.Add(new QueryParameter(OAuthNonceKey, nonce));
        parameters.Add(new QueryParameter(OAuthTimestampKey, timeStamp));
        parameters.Add(new QueryParameter(OAuthSignatureMethodKey, signatureType));
        parameters.Add(new QueryParameter(OAuthConsumerKeyKey, consumerKey));
        if (!string.IsNullOrEmpty(token))
            parameters.Add(new QueryParameter(OAuthTokenKey, token));
        parameters.Sort(new QueryParameterComparer());
        normalizedUrl = string.Format("{0}://{1}", url.Scheme, url.Host);
        if (!((url.Scheme == "http" && url.Port == 80) || (url.Scheme == "https" && url.Port == 443)))
            normalizedUrl += ":" + url.Port;
        normalizedUrl += url.AbsolutePath;
        normalizedRequestParameters = NormalizeRequestParameters(parameters);
        StringBuilder signatureBase = new StringBuilder();
        signatureBase.AppendFormat("{0}&", httpMethod.ToUpper());
        signatureBase.AppendFormat("{0}&", UrlEncode(normalizedUrl));
        signatureBase.AppendFormat("{0}", UrlEncode(normalizedRequestParameters));
        return signatureBase.ToString();
    /// <summary>
    /// Generate the signature value based on the given signature base and hash algorithm
    /// </summary>
    /// <param name="signatureBase">The signature based as produced by the GenerateSignatureBase method or by any other means</param>
    /// <param name="hash">The hash algorithm used to perform the hashing. If the hashing algorithm requires initialization or a key it should be set prior to calling this method</param>
    /// <returns>A base64 string of the hash value</returns>
    public string GenerateSignatureUsingHash(string signatureBase, HashAlgorithm hash)
        return ComputeHash(hash, signatureBase);
    /// <summary>
    /// Generates a signature using the HMAC-SHA1 algorithm
    /// </summary>       
    /// <param name="url">The full url that needs to be signed including its non OAuth url parameters</param>
    /// <param name="consumerKey">The consumer key</param>
    /// <param name="consumerSecret">The consumer seceret</param>
    /// <param name="token">The token, if available. If not available pass null or an empty string</param>
    /// <param name="tokenSecret">The token secret, if available. If not available pass null or an empty string</param>
    /// <param name="httpMethod">The http method used. Must be a valid HTTP method verb (POST,GET,PUT, etc)</param>
    /// <returns>A base64 string of the hash value</returns>
    public string GenerateSignature(Uri url, string consumerKey, string consumerSecret, string token, string tokenSecret, string httpMethod, string timeStamp, string nonce, out string normalizedUrl, out string normalizedRequestParameters)
        return GenerateSignature(url, consumerKey, consumerSecret, token, tokenSecret, httpMethod, timeStamp, nonce, SignatureTypes.HMACSHA1, out normalizedUrl, out normalizedRequestParameters);
    /// <summary>
    /// Generates a signature using the specified signatureType
    /// </summary>       
    /// <param name="url">The full url that needs to be signed including its non OAuth url parameters</param>
    /// <param name="consumerKey">The consumer key</param>
    /// <param name="consumerSecret">The consumer seceret</param>
    /// <param name="token">The token, if available. If not available pass null or an empty string</param>
    /// <param name="tokenSecret">The token secret, if available. If not available pass null or an empty string</param>
    /// <param name="httpMethod">The http method used. Must be a valid HTTP method verb (POST,GET,PUT, etc)</param>
    /// <param name="signatureType">The type of signature to use</param>
    /// <returns>A base64 string of the hash value</returns>
    public string GenerateSignature(Uri url, string consumerKey, string consumerSecret, string token, string tokenSecret, string httpMethod, string timeStamp, string nonce, SignatureTypes signatureType, out string normalizedUrl, out string normalizedRequestParameters)
        normalizedUrl = null;
        normalizedRequestParameters = null;
        switch (signatureType)
            case SignatureTypes.PLAINTEXT:
                return HttpUtility.UrlEncode(string.Format("{0}&{1}", consumerSecret, tokenSecret));
            case SignatureTypes.HMACSHA1:
                string signatureBase = GenerateSignatureBase(url, consumerKey, token, tokenSecret, httpMethod, timeStamp, nonce, HMACSHA1SignatureType, out normalizedUrl, out normalizedRequestParameters);
                HMACSHA1 hmacsha1 = new HMACSHA1();
                hmacsha1.Key = Encoding.ASCII.GetBytes(string.Format("{0}&{1}", UrlEncode(consumerSecret), string.IsNullOrEmpty(tokenSecret) ? "" : UrlEncode(tokenSecret)));
                return GenerateSignatureUsingHash(signatureBase, hmacsha1);
            case SignatureTypes.RSASHA1:
                throw new NotImplementedException();
                throw new ArgumentException("Unknown signature type", "signatureType");
    /// <summary>
    /// Generate the timestamp for the signature       
    /// </summary>
    /// <returns></returns>
    public virtual string GenerateTimeStamp()
        // Default implementation of UNIX time of the current UTC time
        TimeSpan ts = DateTime.UtcNow - new DateTime(1970, 1, 1, 0, 0, 0, 0);
        string timeStamp = ts.TotalSeconds.ToString();
        timeStamp = timeStamp.Substring(0, timeStamp.IndexOf("."));
        return timeStamp;
    /// <summary>
    /// Generate a nonce
    /// </summary>
    /// <returns></returns>
    public virtual string GenerateNonce()
        // Just a simple implementation of a random number between 123400 and 9999999
        return random.Next(123400, 9999999).ToString();
I think this post will help you. Thanks. Happy Coding.


  1. Hi, There is an error in this code on compilation will you please clarify this .

    The type or namespace name 'OAuth' could not be found (are you missing a using directive or an assembly reference?)

    Line 10: using System.Net;
    Line 11: using System.IO;
    Line 12: using OAuth.Net.Common;
    Line 13: using OAuth.Net.Components;
    Line 14: using OAuth.Net.Consumer;

  2. hi after making this workable
    this error is occurred

    The remote server returned an error: (401) Unauthorized.

  3. Hello,

    Your code was very helpful and great suffering to find what was wrong, it does not work unless you put the http:// in the header retrievecontacts - should look like this:

    AuthHeader string = "Authorization: OAuth realm = \" \ "" + ....



  4. hi sir,

    How to resolve this error : -
    The remote server returned an error: (401) Unauthorized.

    Thanks in Advance.

  5. Hi I also get above error in this sample..can any body please reply how to resolve this?

  6. This comment has been removed by the author.

  7. hi, i also get the foloowing error in retrivecontacts

    The remote server returned an error: (401) Unauthorized.
    Please provide valid credentials. OAuth oauth_problem="signature_invalid", realm=""

    Please help me...

  8. hello sir,

    i am integrate this code in my application. I am successfully login in yahoo and after the login redirect to my site and call the retrievecontacts() i have error: The remote server returned an error: (401) Unauthorized.
    Please provide valid credentials. OAuth oauth_problem="signature_invalid", realm="". please help me how can i solve this error?

    1. Hi Guys,

      I was getting 401-unauthorized error, and it was driving me nuts. I finally realized that i was using token secret returned from the original request token call instead of the new one returned from the "access token" call.

      This helped me:

  9. could you please provide the link adress of

  10. hi, i executed the application with my credentials and i got the output in but once i converted to and also i created new project in my yahoo acoount i added those credentials too,after entering credentilals and wen i click on agree button,control not enntering into retrieve contacts block throwing exception :

    The remote server returned an error: (401) Unauthorized.
    length: 6
    stack trace: at System.Net.HttpWebRequest.GetResponse() at _Default.RetriveContacts() in D:\ImportYahooContacts\MyYahooContacts.aspx.vb:line 339
    status: ProtocolError
    Status Code: (401) Unauthorized
    Status Description: Authorization Required
    source: System
    headers: 0: Keep-Alive
    headers: 1: chunked
    headers: 2: Accept-Encoding
    headers: 3: private
    headers: 4: application/xml
    headers: 5: Fri, 14 Jun 2013 04:47:24 GMT
    headers: 6: HTTP/1.1 UserFiberFramework/1.0
    headers: 7: HTTP/1.1 UserFiberFramework/1.0
    headers: 8: OAuth oauth_problem="signature_invalid", realm=""

    can any one resolve

  11. hi dear,
    anyone one have any solution to remove the error as you all discussed about that ."The remote server returned an error: (401) Unauthorized."

    so if anyone of you have got the solution then please share here.

  12. Hii

    Can anyone help me how to solve "The remote server returned an error: (401) Unauthorized." error.

    1. Make sure that you've specified your own ConsumerKey, ConsumerSecret and own callback url (value specified in the oauth_callback parameter). All those settings must be defined in Yahoo when creating your API

  13. can we get name and mobile numbers

  14. how to run the code in localhost?I finding problem in like these

    The remote server returned an error: (404) Not Found.
    length: 6
    stack trace: at System.Net.HttpWebRequest.GetResponse() at WebApplication2.WebForm1.RetriveContacts() in C:\Users\Agaram-Pc-5\Documents\Visual Studio 2010\WebApplication2\WebApplication2\WebForm1.aspx.cs:line 351
    status: ProtocolError
    Status Code: (404) NotFound
    Status Description: Not Found on Accelerator
    source: System
    headers: 0: close
    headers: 1: en
    headers: 2: 1865
    headers: 3: no-store
    headers: 4: text/html
    headers: 5: Thu, 30 Oct 2014 05:25:29 GMT
    headers: 6: ATS
    headers: 7: http/1.1 (ApacheTrafficServer [c s f ])

    Please help.......

  15. Did anyone got the solution for running code locally? I am getting same error while executing{MY-QUERY}.
    But when I run same command using POST MAN (Rest client), its working.
    Please help?

  16. I am getting an error

    The type or namespace name 'OAuth' could not be found (are you missing a using directive or an assembly reference?)

    Line 10: using System.Net;
    Line 11: using System.IO;
    Line 12: using OAuth.Net.Common;
    Line 13: using OAuth.Net.Components;
    Line 14: using OAuth.Net.Consumer;

  17. "Nice and good article.. it is very useful for me to learn and understand easily.. thanks for sharing your valuable information and time.. please keep updating.php jobs in hyderabad.

  18. Nice and good article. It is very useful for me to learn and understand easily. Thanks for sharing your valuable information and time. Please keep updating.

    Digital Marketing Training in Chennai

    Digital Marketing Course in Chennai
