diff --git a/aspnet-core/modules/openIddict/LINGYUN.Abp.OpenIddict.AspNetCore.Session/LINGYUN/Abp/OpenIddict/AspNetCore/Session/AbpOpenIddictAspNetCoreSessionModule.cs b/aspnet-core/modules/openIddict/LINGYUN.Abp.OpenIddict.AspNetCore.Session/LINGYUN/Abp/OpenIddict/AspNetCore/Session/AbpOpenIddictAspNetCoreSessionModule.cs index cb43c0309..2a3895ba6 100644 --- a/aspnet-core/modules/openIddict/LINGYUN.Abp.OpenIddict.AspNetCore.Session/LINGYUN/Abp/OpenIddict/AspNetCore/Session/AbpOpenIddictAspNetCoreSessionModule.cs +++ b/aspnet-core/modules/openIddict/LINGYUN.Abp.OpenIddict.AspNetCore.Session/LINGYUN/Abp/OpenIddict/AspNetCore/Session/AbpOpenIddictAspNetCoreSessionModule.cs @@ -37,6 +37,10 @@ public class AbpOpenIddictAspNetCoreSessionModule : AbpModule Configure(options => { options.PersistentSessionGrantTypes.Add(GrantTypes.Password); + options.ValidationSessionEndpointTypes.Add(OpenIddictServerEndpointType.Token); + options.ValidationSessionEndpointTypes.Add(OpenIddictServerEndpointType.UserInfo); + options.ValidationSessionEndpointTypes.Add(OpenIddictServerEndpointType.Introspection); + options.ValidationSessionEndpointTypes.Add(OpenIddictServerEndpointType.Revocation); }); context.Services.Add(ValidationTokenCheckIdentitySession.Descriptor.ServiceDescriptor); diff --git a/aspnet-core/modules/openIddict/LINGYUN.Abp.OpenIddict.AspNetCore.Session/LINGYUN/Abp/OpenIddict/AspNetCore/Session/AbpOpenIddictAspNetCoreSessionOptions.cs b/aspnet-core/modules/openIddict/LINGYUN.Abp.OpenIddict.AspNetCore.Session/LINGYUN/Abp/OpenIddict/AspNetCore/Session/AbpOpenIddictAspNetCoreSessionOptions.cs index c2796845d..80411f605 100644 --- a/aspnet-core/modules/openIddict/LINGYUN.Abp.OpenIddict.AspNetCore.Session/LINGYUN/Abp/OpenIddict/AspNetCore/Session/AbpOpenIddictAspNetCoreSessionOptions.cs +++ b/aspnet-core/modules/openIddict/LINGYUN.Abp.OpenIddict.AspNetCore.Session/LINGYUN/Abp/OpenIddict/AspNetCore/Session/AbpOpenIddictAspNetCoreSessionOptions.cs @@ -1,11 +1,14 @@ -using System.Collections.Generic; +using OpenIddict.Server; +using System.Collections.Generic; namespace LINGYUN.Abp.OpenIddict.AspNetCore.Session; public class AbpOpenIddictAspNetCoreSessionOptions { public List PersistentSessionGrantTypes { get; set; } + public List ValidationSessionEndpointTypes { get; set; } public AbpOpenIddictAspNetCoreSessionOptions() { PersistentSessionGrantTypes = new List(); + ValidationSessionEndpointTypes = new List(); } } diff --git a/aspnet-core/modules/openIddict/LINGYUN.Abp.OpenIddict.AspNetCore.Session/LINGYUN/Abp/OpenIddict/AspNetCore/Session/ProcessSignInIdentitySession.cs b/aspnet-core/modules/openIddict/LINGYUN.Abp.OpenIddict.AspNetCore.Session/LINGYUN/Abp/OpenIddict/AspNetCore/Session/ProcessSignInIdentitySession.cs index 906510146..2373b9077 100644 --- a/aspnet-core/modules/openIddict/LINGYUN.Abp.OpenIddict.AspNetCore.Session/LINGYUN/Abp/OpenIddict/AspNetCore/Session/ProcessSignInIdentitySession.cs +++ b/aspnet-core/modules/openIddict/LINGYUN.Abp.OpenIddict.AspNetCore.Session/LINGYUN/Abp/OpenIddict/AspNetCore/Session/ProcessSignInIdentitySession.cs @@ -1,7 +1,10 @@ using LINGYUN.Abp.Identity.Session; +using Microsoft.Extensions.Logging; +using Microsoft.Extensions.Logging.Abstractions; using Microsoft.Extensions.Options; using OpenIddict.Server; using System; +using System.Security.Principal; using System.Threading.Tasks; namespace LINGYUN.Abp.OpenIddict.AspNetCore.Session; @@ -10,6 +13,8 @@ namespace LINGYUN.Abp.OpenIddict.AspNetCore.Session; /// public class ProcessSignInIdentitySession : IOpenIddictServerHandler { + public ILogger Logger { protected get; set; } + protected IIdentitySessionManager IdentitySessionManager { get; } protected AbpOpenIddictAspNetCoreSessionOptions AbpOpenIddictAspNetCoreSessionOptions { get; } @@ -27,6 +32,8 @@ public class ProcessSignInIdentitySession : IOpenIddictServerHandler.Instance; } public async virtual ValueTask HandleAsync(OpenIddictServerEvents.ProcessSignInContext context) @@ -35,7 +42,15 @@ public class ProcessSignInIdentitySession : IOpenIddictServerHandler public class RevocationIdentitySession : IOpenIddictServerHandler { + public ILogger Logger { protected get; set; } protected ICurrentTenant CurrentTenant { get; } protected IIdentitySessionManager IdentitySessionManager { get; } @@ -28,6 +31,8 @@ public class RevocationIdentitySession : IOpenIddictServerHandler.Instance; } public async virtual ValueTask HandleAsync(OpenIddictServerEvents.HandleRevocationRequestContext context) diff --git a/aspnet-core/modules/openIddict/LINGYUN.Abp.OpenIddict.AspNetCore.Session/LINGYUN/Abp/OpenIddict/AspNetCore/Session/ServerValidationTokenCheckIdentitySession.cs b/aspnet-core/modules/openIddict/LINGYUN.Abp.OpenIddict.AspNetCore.Session/LINGYUN/Abp/OpenIddict/AspNetCore/Session/ServerValidationTokenCheckIdentitySession.cs index 9948778c8..ae5eb8090 100644 --- a/aspnet-core/modules/openIddict/LINGYUN.Abp.OpenIddict.AspNetCore.Session/LINGYUN/Abp/OpenIddict/AspNetCore/Session/ServerValidationTokenCheckIdentitySession.cs +++ b/aspnet-core/modules/openIddict/LINGYUN.Abp.OpenIddict.AspNetCore.Session/LINGYUN/Abp/OpenIddict/AspNetCore/Session/ServerValidationTokenCheckIdentitySession.cs @@ -1,5 +1,7 @@ using LINGYUN.Abp.Identity.Session; using Microsoft.Extensions.Logging; +using Microsoft.Extensions.Logging.Abstractions; +using Microsoft.Extensions.Options; using OpenIddict.Server; using System.Security.Principal; using System.Threading.Tasks; @@ -9,8 +11,10 @@ using static OpenIddict.Abstractions.OpenIddictConstants; namespace LINGYUN.Abp.OpenIddict.AspNetCore.Session; public class ServerValidationTokenCheckIdentitySession : IOpenIddictServerHandler { + public ILogger Logger { protected get; set; } protected ICurrentTenant CurrentTenant { get; } protected IIdentitySessionChecker IdentitySessionChecker { get; } + protected AbpOpenIddictAspNetCoreSessionOptions AbpOpenIddictAspNetCoreSessionOptions { get; } public static OpenIddictServerHandlerDescriptor Descriptor { get; } = OpenIddictServerHandlerDescriptor.CreateBuilder() @@ -20,20 +24,38 @@ public class ServerValidationTokenCheckIdentitySession : IOpenIddictServerHandle public ServerValidationTokenCheckIdentitySession( ICurrentTenant currentTenant, - IIdentitySessionChecker identitySessionChecker) + IIdentitySessionChecker identitySessionChecker, + IOptions abpOpenIddictAspNetCoreSessionOptions) { CurrentTenant = currentTenant; IdentitySessionChecker = identitySessionChecker; + AbpOpenIddictAspNetCoreSessionOptions = abpOpenIddictAspNetCoreSessionOptions.Value; + + Logger = NullLogger.Instance; } public async virtual ValueTask HandleAsync(OpenIddictServerEvents.ValidateTokenContext context) { + Logger.LogInformation("Server Validate Token: {endpointType} - {requestUri}", context.EndpointType, context.RequestUri); + + if (!AbpOpenIddictAspNetCoreSessionOptions.ValidationSessionEndpointTypes.Contains(context.EndpointType)) + { + Logger.LogDebug("Endpoint '{endpointType}' is not in validation whitelist, skipping session validation.", context.EndpointType); + return; + } + + if (context.Principal == null || context.Principal.Identity?.IsAuthenticated == false) + { + Logger.LogWarning("Principal is null or not authenticated for endpoint '{endpointType}', skipping session validation.", context.EndpointType); + return; + } + var tenantId = context.Principal?.FindTenantId(); using (CurrentTenant.Change(tenantId)) { if (!await IdentitySessionChecker.ValidateSessionAsync(context.Principal!)) { - context.Logger.LogWarning("The token is no longer valid because the user's session expired."); + Logger.LogWarning("The token is no longer valid because the user's session expired."); // Errors.InvalidToken ---> 401 // Errors.ExpiredToken ---> 400 context.Reject(Errors.InvalidToken, "The user session has expired."); diff --git a/aspnet-core/modules/openIddict/LINGYUN.Abp.OpenIddict.AspNetCore.Session/LINGYUN/Abp/OpenIddict/AspNetCore/Session/ValidationTokenCheckIdentitySession.cs b/aspnet-core/modules/openIddict/LINGYUN.Abp.OpenIddict.AspNetCore.Session/LINGYUN/Abp/OpenIddict/AspNetCore/Session/ValidationTokenCheckIdentitySession.cs index 9fbb9b612..26f734379 100644 --- a/aspnet-core/modules/openIddict/LINGYUN.Abp.OpenIddict.AspNetCore.Session/LINGYUN/Abp/OpenIddict/AspNetCore/Session/ValidationTokenCheckIdentitySession.cs +++ b/aspnet-core/modules/openIddict/LINGYUN.Abp.OpenIddict.AspNetCore.Session/LINGYUN/Abp/OpenIddict/AspNetCore/Session/ValidationTokenCheckIdentitySession.cs @@ -1,5 +1,6 @@ using LINGYUN.Abp.Identity.Session; using Microsoft.Extensions.Logging; +using Microsoft.Extensions.Logging.Abstractions; using OpenIddict.Validation; using System.Security.Principal; using System.Threading.Tasks; @@ -9,6 +10,7 @@ using static OpenIddict.Abstractions.OpenIddictConstants; namespace LINGYUN.Abp.OpenIddict.AspNetCore.Session; public class ValidationTokenCheckIdentitySession : IOpenIddictValidationHandler { + public ILogger Logger { protected get; set; } protected ICurrentTenant CurrentTenant { get; } protected IIdentitySessionChecker IdentitySessionChecker { get; } @@ -25,16 +27,20 @@ public class ValidationTokenCheckIdentitySession : IOpenIddictValidationHandler< { CurrentTenant = currentTenant; IdentitySessionChecker = identitySessionChecker; + + Logger = NullLogger.Instance; } public async virtual ValueTask HandleAsync(OpenIddictValidationEvents.ValidateTokenContext context) { + Logger.LogInformation("Validate Token: {endpointType} - {requestUri}", context.EndpointType, context.RequestUri); + var tenantId = context.Principal?.FindTenantId(); using (CurrentTenant.Change(tenantId)) { if (!await IdentitySessionChecker.ValidateSessionAsync(context.Principal!)) { - context.Logger.LogWarning("The token is no longer valid because the user's session expired."); + Logger.LogWarning("The token is no longer valid because the user's session expired."); // Errors.InvalidToken ---> 401 // Errors.ExpiredToken ---> 400 context.Reject(Errors.InvalidToken, "The user session has expired.");