1
This commit is contained in:
@@ -1,15 +1,16 @@
|
||||
|
||||
|
||||
namespace Yes.Infrastructure.Authorizations
|
||||
namespace Yes.Infrastructure.Authorizations
|
||||
{
|
||||
public static class AuthenticationExtensions
|
||||
{
|
||||
public static IServiceCollection AddUserAuthentication(this IServiceCollection services)
|
||||
public static IServiceCollection AddAdminAuthentication(this IServiceCollection services,IConfiguration configuration)
|
||||
{
|
||||
services.AddAuthentication(AuthenticationScheme.UserScheme)
|
||||
.AddCookie(AuthenticationScheme.UserScheme, options =>
|
||||
var securityKeyBase64 = JwtHelper.GenerateKey(configuration["SecretKey"] ?? "");
|
||||
|
||||
|
||||
services.AddAuthentication(AuthenticationScheme.AdminScheme)
|
||||
.AddCookie(AuthenticationScheme.AdminScheme, options =>
|
||||
{
|
||||
options.Cookie.Name = AuthenticationScheme.UserScheme;
|
||||
options.Cookie.Name = AuthenticationScheme.AdminScheme;
|
||||
options.LoginPath = "/admin/login";
|
||||
options.LogoutPath = "/admin/logout";
|
||||
options.ExpireTimeSpan = TimeSpan.FromDays(3);
|
||||
@@ -18,7 +19,7 @@ namespace Yes.Infrastructure.Authorizations
|
||||
options.Events.OnRedirectToAccessDenied =
|
||||
options.Events.OnRedirectToLogin = c =>
|
||||
{
|
||||
if(c.Request.GetDisplayUrl().Contains("/api"))
|
||||
if (c.Request.GetDisplayUrl().Contains("/api"))
|
||||
{
|
||||
c.Response.ContentType = "application/json";
|
||||
c.Response.StatusCode = StatusCodes.Status401Unauthorized;
|
||||
@@ -30,18 +31,32 @@ namespace Yes.Infrastructure.Authorizations
|
||||
return Task.CompletedTask;
|
||||
}
|
||||
};
|
||||
});
|
||||
}).AddJwtBearer(AuthenticationScheme.ApiScheme, options =>
|
||||
{
|
||||
options.TokenValidationParameters = new TokenValidationParameters
|
||||
{
|
||||
ValidateLifetime = true,
|
||||
RequireSignedTokens = false,
|
||||
RequireExpirationTime = false,
|
||||
ValidateIssuer = true,
|
||||
ValidateIssuerSigningKey = true,
|
||||
ValidIssuer = "hyrule",
|
||||
IssuerSigningKey = new SymmetricSecurityKey(Encoding.UTF8.GetBytes(securityKeyBase64))
|
||||
};
|
||||
|
||||
});
|
||||
|
||||
return services;
|
||||
}
|
||||
|
||||
public static async Task SignIn(this HttpContext context, IdentityInfo account)
|
||||
|
||||
|
||||
public static async Task SignIn(this HttpContext context, IdentityInfo account, int tokenLifetimeMinutes)
|
||||
{
|
||||
await context.SignIn(AuthenticationScheme.UserScheme, account);
|
||||
await context.SignIn(AuthenticationScheme.AdminScheme, account, tokenLifetimeMinutes);
|
||||
}
|
||||
|
||||
public static async Task SignIn(this HttpContext context, string authenticationScheme, IdentityInfo account)
|
||||
public static async Task SignIn(this HttpContext context, string authenticationScheme, IdentityInfo account, int tokenLifetimeMinutes)
|
||||
{
|
||||
var claims = new List<Claim>
|
||||
{
|
||||
@@ -59,7 +74,7 @@ namespace Yes.Infrastructure.Authorizations
|
||||
new AuthenticationProperties()
|
||||
{
|
||||
IsPersistent = true,
|
||||
ExpiresUtc = DateTimeOffset.UtcNow.AddHours(24 * 30),//有效时间
|
||||
ExpiresUtc = DateTimeOffset.UtcNow.AddMinutes(tokenLifetimeMinutes),//有效时间
|
||||
AllowRefresh = true
|
||||
}
|
||||
);
|
||||
@@ -74,7 +89,7 @@ namespace Yes.Infrastructure.Authorizations
|
||||
|
||||
public static async Task SignOut(this HttpContext context)
|
||||
{
|
||||
await context.SignOutAsync(AuthenticationScheme.UserScheme);
|
||||
await context.SignOutAsync(AuthenticationScheme.AdminScheme);
|
||||
}
|
||||
|
||||
public static async Task<bool> HasLogin(this HttpContext context)
|
||||
|
||||
@@ -2,10 +2,11 @@
|
||||
{
|
||||
public class AuthenticationScheme
|
||||
{
|
||||
public const string MerchanScheme = "merchan";
|
||||
public const string AdminScheme = "admin";
|
||||
|
||||
public const string ApiScheme = "api";
|
||||
|
||||
|
||||
public const string UserScheme = "user";
|
||||
|
||||
public const string UserApiScheme = "userapi";
|
||||
}
|
||||
}
|
||||
|
||||
@@ -2,11 +2,11 @@
|
||||
{
|
||||
public class JwtProvider : IJwtProvider
|
||||
{
|
||||
private readonly string securityKey = "";
|
||||
private readonly BlogSettings _settings;
|
||||
|
||||
public JwtProvider(IConfiguration configuration)
|
||||
public JwtProvider(IOptionsMonitor<BlogSettings> options)
|
||||
{
|
||||
securityKey = configuration.GetSection("Jwt").GetValue<string>("securityKey");
|
||||
_settings = options.CurrentValue;
|
||||
}
|
||||
|
||||
|
||||
@@ -15,16 +15,16 @@
|
||||
{
|
||||
return await Task.Run(() =>
|
||||
{
|
||||
var securityKeyBase64 = Convert.ToBase64String(Encoding.UTF8.GetBytes(securityKey));
|
||||
var securityKeyBase64 = Convert.ToBase64String(Encoding.UTF8.GetBytes(_settings.SecretKey));
|
||||
var key = new SymmetricSecurityKey(Encoding.UTF8.GetBytes(securityKeyBase64));
|
||||
|
||||
var jwtHander = new JwtSecurityTokenHandler();
|
||||
var claimsIdentity = jwtHander.ValidateToken(token, new TokenValidationParameters
|
||||
{
|
||||
ValidateIssuer = false,
|
||||
ValidateIssuer = true,
|
||||
ValidateAudience = false,
|
||||
ValidateIssuerSigningKey = true,
|
||||
ValidIssuer = "",
|
||||
ValidIssuer = "hyrule",
|
||||
ValidAudience = "",
|
||||
IssuerSigningKey = key,
|
||||
ValidateLifetime = true,
|
||||
|
||||
@@ -2,11 +2,11 @@
|
||||
{
|
||||
|
||||
|
||||
public class UserApiAuthorizeAttribute : AuthorizeAttribute
|
||||
public class ApiAuthorizeAttribute : AuthorizeAttribute
|
||||
{
|
||||
public UserApiAuthorizeAttribute()
|
||||
public ApiAuthorizeAttribute()
|
||||
{
|
||||
AuthenticationSchemes = AuthenticationScheme.UserApiScheme;
|
||||
AuthenticationSchemes = AuthenticationScheme.ApiScheme;
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
@@ -1,12 +0,0 @@
|
||||
namespace Yes.Infrastructure.Authorizations.User
|
||||
{
|
||||
|
||||
|
||||
public class UserAuthorizeAttribute : AuthorizeAttribute
|
||||
{
|
||||
public UserAuthorizeAttribute()
|
||||
{
|
||||
AuthenticationSchemes = AuthenticationScheme.UserScheme;
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,12 @@
|
||||
namespace Yes.Infrastructure.Authorizations.User
|
||||
{
|
||||
|
||||
|
||||
public class PageAuthorizeAttribute : AuthorizeAttribute
|
||||
{
|
||||
public PageAuthorizeAttribute()
|
||||
{
|
||||
AuthenticationSchemes = "admin";
|
||||
}
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user