IwbAuthorizationServerProvider.cs 7.0 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154
  1. using System;
  2. using System.Security.Claims;
  3. using System.Threading.Tasks;
  4. using Abp.Dependency;
  5. using Abp.Localization;
  6. using Abp.Localization.Sources;
  7. using IwbZero;
  8. using IwbZero.Authorization.Base;
  9. using IwbZero.ToolCommon.StringModel;
  10. using Microsoft.Owin.Security;
  11. using Microsoft.Owin.Security.OAuth;
  12. namespace WeEngine.Api.Providers
  13. {
  14. public class IwbAuthorizationServerProvider : OAuthAuthorizationServerProvider, ITransientDependency
  15. {
  16. //private LogInManager LogInManager { get; }
  17. private ILocalizationManager LocalizationManager { get; }
  18. public IwbAuthorizationServerProvider()
  19. {
  20. //LogInManager = logInManager;
  21. LocalizationManager = NullLocalizationManager.Instance;
  22. }
  23. public override Task ValidateClientAuthentication(OAuthValidateClientAuthenticationContext context)
  24. {
  25. if (!context.TryGetBasicCredentials(out var clientId, out var clientSecret))
  26. {
  27. context.TryGetFormCredentials(out clientId, out clientSecret);
  28. }
  29. var isValidClient = string.CompareOrdinal(clientId, "app") == 0 &&
  30. string.CompareOrdinal(clientSecret, "app") == 0;
  31. if (isValidClient)
  32. {
  33. context.OwinContext.Set("as:client_id", clientId);
  34. context.Validated(clientId);
  35. }
  36. else
  37. {
  38. context.SetError("invalid client");
  39. }
  40. return Task.FromResult<object>(null);
  41. }
  42. public override async Task GrantResourceOwnerCredentials(OAuthGrantResourceOwnerCredentialsContext context)
  43. {
  44. //var tenantId = context.Request.Query["tenantId"];
  45. //var result = await GetLoginResultAsync(context, context.UserName, context.Password, tenantId);
  46. //if (result.Result == IwbLoginResultType.Success)var result = await GetLoginResultAsync(context, context.UserName, context.Password, tenantId);
  47. var result = await Login(context.UserName, context.Password);
  48. if (result)
  49. {
  50. var claimsIdentity = new ClaimsIdentity();
  51. //var claimsIdentity = new ClaimsIdentity(result.Identity);
  52. claimsIdentity.AddClaim(new Claim(ClaimTypes.Name, context.UserName));
  53. var ticket = new AuthenticationTicket(claimsIdentity, new AuthenticationProperties());
  54. context.Validated(ticket);
  55. }
  56. }
  57. public override Task GrantRefreshToken(OAuthGrantRefreshTokenContext context)
  58. {
  59. var originalClient = context.OwinContext.Get<string>("as:client_id");
  60. var currentClient = context.ClientId;
  61. // enforce client binding of refresh token
  62. if (originalClient != currentClient)
  63. {
  64. context.Rejected();
  65. return Task.FromResult<object>(null);
  66. }
  67. // chance to change authentication ticket for refresh token requests
  68. var newId = new ClaimsIdentity(context.Ticket.Identity);
  69. newId.AddClaim(new Claim("newClaim", "refreshToken"));
  70. var newTicket = new AuthenticationTicket(newId, context.Ticket.Properties);
  71. context.Validated(newTicket);
  72. return Task.FromResult<object>(null);
  73. }
  74. public Task<bool> Login(string userName,string password)
  75. {
  76. var flag= false;
  77. if (userName.IsEmpty())
  78. {
  79. return Task.FromResult(false);
  80. }
  81. flag = "Y".ValB();
  82. return Task.FromResult(flag);
  83. }
  84. //private async Task<IwbLoginResult<Tenant, User>> GetLoginResultAsync(OAuthGrantResourceOwnerCredentialsContext context,
  85. // string usernameOrEmailAddress, string password, string tenancyName)
  86. //{
  87. // var loginResult = await LogInManager.LoginAsync(usernameOrEmailAddress, password, tenancyName);
  88. // switch (loginResult.Result)
  89. // {
  90. // case IwbLoginResultType.Success:
  91. // return loginResult;
  92. // default:
  93. // CreateExceptionForFailedLoginAttempt(context, loginResult.Result, usernameOrEmailAddress, tenancyName);
  94. // //throw CreateExceptionForFailedLoginAttempt(context,loginResult.Result, usernameOrEmailAddress, tenancyName);
  95. // return loginResult;
  96. // }
  97. //}
  98. private void CreateExceptionForFailedLoginAttempt(OAuthGrantResourceOwnerCredentialsContext context,
  99. IwbLoginResultType result, string usernameOrEmailAddress, string tenancyName)
  100. {
  101. switch (result)
  102. {
  103. case IwbLoginResultType.Success:
  104. throw new ApplicationException("Don't call this method with a success result!");
  105. case IwbLoginResultType.InvalidUserNameOrEmailAddress:
  106. case IwbLoginResultType.InvalidPassword:
  107. context.SetError(L("LoginFailed"), L("InvalidUserNameOrPassword"));
  108. break;
  109. // return new UserFriendlyException(("LoginFailed"), ("InvalidUserNameOrPassword"));
  110. case IwbLoginResultType.InvalidTenancyName:
  111. context.SetError(L("LoginFailed"), L("ThereIsNoTenantDefinedWithName", tenancyName));
  112. break;
  113. // return new UserFriendlyException(("LoginFailed"), string.Format("ThereIsNoTenantDefinedWithName{0}", tenancyName));
  114. case IwbLoginResultType.TenantIsNotActive:
  115. context.SetError(L("LoginFailed"), L("TenantIsNotActive", tenancyName));
  116. break;
  117. // return new UserFriendlyException(("LoginFailed"), string.Format("TenantIsNotActive {0}", tenancyName));
  118. case IwbLoginResultType.UserIsNotActive:
  119. context.SetError(L("LoginFailed"), L("UserIsNotActiveAndCanNotLogin", usernameOrEmailAddress));
  120. break;
  121. // return new UserFriendlyException(("LoginFailed"), string.Format("UserIsNotActiveAndCanNotLogin {0}", usernameOrEmailAddress));
  122. case IwbLoginResultType.UserEmailIsNotConfirmed:
  123. context.SetError(L("LoginFailed"), L("UserEmailIsNotConfirmedAndCanNotLogin"));
  124. break;
  125. // return new UserFriendlyException(("LoginFailed"), ("UserEmailIsNotConfirmedAndCanNotLogin"));
  126. //default: //Can not fall to default actually. But other result types can be added in the future and we may forget to handle it
  127. // //Logger.Warn("Unhandled login fail reason: " + result);
  128. // return new UserFriendlyException(("LoginFailed"));
  129. }
  130. }
  131. private string L(string name, params object[] args)
  132. {
  133. //return new LocalizedString(name);
  134. return LocalizationManager.GetSource(IwbZeroConsts.LocalizationSourceName).GetString(name, args);
  135. }
  136. }
  137. }