Browse Source

集成IdentityServer4登录

pull/10/head
王军 5 years ago
parent
commit
bf39eb3a8b
  1. 4
      .gitignore
  2. 62
      Readme.md
  3. BIN
      aspnet-core/services/host/CompanyName.ProjectName.HttpApi.Host/publish.zip
  4. 19
      aspnet-core/services/host/CompanyName.ProjectName.IdentityServer/Dockerfile
  5. 2
      aspnet-core/services/src/CompanyName.ProjectName.DbMigrator/appsettings.json
  6. 86
      aspnet-core/services/src/CompanyName.ProjectName.Domain/IdentityServer/IdentityServerDataSeedContributor.cs
  7. 2
      vben271/.env.production
  8. BIN
      vben271/dist.zip
  9. 8
      vben271/src/router/guard/index.ts

4
.gitignore

@ -265,3 +265,7 @@ content/src/Zzz.DbMigrator/Logs/*
/aspnet-core/services/host/CompanyName.ProjectName.HttpApi.Host/appsettings.Production.json
/aspnet-core/services/host/CompanyName.ProjectName.HttpApi.Host/Logs
/aspnet-core/services/host/CompanyName.ProjectName.IdentityServer/Logs
/vben271/dist.zip
/aspnet-core/services/host/CompanyName.ProjectName.HttpApi.Host/publish.zip
/aspnet-core/services/host/CompanyName.ProjectName.IdentityServer/appsettings.Production.json
/aspnet-core/services/host/CompanyName.ProjectName.IdentityServer/publish.zip

62
Readme.md

@ -4,27 +4,48 @@
<table>
<tr>
<td><img src="https://blog-resouce.oss-cn-shenzhen.aliyuncs.com/images/abp/login.png"/></td>
<td><img src="https://blog-resouce.oss-cn-shenzhen.aliyuncs.com/images/abp/user.png"/></td>
<td><img src="https://blog-resouce.oss-cn-shenzhen.aliyuncs.com/images/abp/4.4/4.4login.png"/></td>
<td><img src="https://blog-resouce.oss-cn-shenzhen.aliyuncs.com/images/abp/4.4/4.4roole.png"/></td>
</tr>
<tr>
<td><img src="https://blog-resouce.oss-cn-shenzhen.aliyuncs.com/images/abp/role.png"/></td>
<td><img src="https://blog-resouce.oss-cn-shenzhen.aliyuncs.com/images/abp/settings.png"/></td>
<td><img src="https://blog-resouce.oss-cn-shenzhen.aliyuncs.com/images/abp/4.4/4.4hangfire.png"/></td>
<td><img src="https://blog-resouce.oss-cn-shenzhen.aliyuncs.com/images/abp/4.4/4.4cap.png"/></td>
</tr>
<tr>
<td><img src="https://blog-resouce.oss-cn-shenzhen.aliyuncs.com/images/abp/4.4/4.4client.png"/></td>
<td><img src="https://blog-resouce.oss-cn-shenzhen.aliyuncs.com/images/abp/4.4/4.4identity.png"/></td>
</tr>
</table>
</div>
### 说明
#### 项目简介
基于ABP Vnext4.4.0的微服务架构,基于DDD思想开发,基于vue3.0,Typescript,Antd 的后台管理框架,适用于大型分布式业务系统和企业后台。
[预览地址](https://vvbin.cn/doc-next/) 用户名:admin 密码: 1q2w3E*
#### 系统功能
- main分支为主要开发分支,后续都基于此分支维护,该分支前端基于vue3.0,Typescript,如果要使用Vue请切换到Vue2分支。
- .Net Core5.0
- Abp Vnext 4.2 ,
- Ant Design, Vben Admin [前端文档](https://vvbin.cn/doc-next/)
- Mysql,Redis,Hangfire,ES(日志可选)
- 微服务架构设计, DDD 实践
- 容器化 CI CD
- Xunit 单元测试(提供sample单元测试)
- [x] 用户管理
- [x] 角色管理
- [x] 审计日志
- [x] 后台任务(hangfire)
- [x] 集成事件(dotnetcore.cap)
- [x] IdentityServer4
- [x] 客户端管理
- [x] Api资源管理
- [x] ApiScope管理
- [x] Identity资源管理
- [x] SinglaR消息通知
- [x] 多语言
- [x] FreeSql
- [x] 数据字典(UI暂时没有)
- [x] 容器化部署
- [x] 单元测试
- [x] ES日志
- [ ] 多租户
- [ ] 组织机构
@ -37,18 +58,11 @@
- 后端使用swagger的时候tag请不要用中文 [SwaggerOperation(summary: "获取所有角色", Tags = new[] { "Role" })]
- 前端代理生成在src/services下,如何使用请参考用户模块
### 对接思路
- 前端
- 通过 token 调用 /api/abp/application-configuration 获取应用级别信息,包括权限,多语言,保存在 Store 中;
- 多语言基于前端,后端 Api 的多语言基于 abp 自带的;
- 配置菜单,属性 meta.policy 不传代表不验证权限
- 按钮权限,v-auth 例如:v-auth=('AbpIdentity.Roles.Create')
- 后端
- 项目不一定要基于 IdentityServer4,所以新增了一个登陆方法,生成 Token.
- IdentityServer4的已经独立出来,也会开源。
### 使用
@ -56,19 +70,17 @@
![](https://blog-resouce.oss-cn-shenzhen.aliyuncs.com/images/abp/gui.png)
- 下载模板之后再当前项目src\AbpVnextPro.GUI\bin\Debug\net5.0-windows\decompression可以看到生成的源码
- 启动
- 前端yarn
- 后端修改mysql和redis连接字符串
- 执行tools下的迁移控制台程序
- 执行迁移控制台程序
- 启动host下httpapi.host即可
- host下的public可以忽略,这个用来做暴露第三方接口的,通过id4授权。
- 启动HttpApi.Host和IdentityServer4
#### 参与贡献

BIN
aspnet-core/services/host/CompanyName.ProjectName.HttpApi.Host/publish.zip

Binary file not shown.

19
aspnet-core/services/host/CompanyName.ProjectName.IdentityServer/Dockerfile

@ -0,0 +1,19 @@
FROM mcr.microsoft.com/dotnet/aspnet:5.0
# 创建目录
RUN mkdir /app
COPY publish /app
# 设置工作目录
WORKDIR /app
# 暴露80端口
EXPOSE 80
# 设置环境变量
ENV ASPNETCORE_ENVIRONMENT=Production
ENTRYPOINT ["dotnet", "CompanyName.ProjectName.IdentityServer.dll"]

2
aspnet-core/services/src/CompanyName.ProjectName.DbMigrator/appsettings.json

@ -1,6 +1,6 @@
{
"ConnectionStrings": {
"Default": "Data Source=localhost;Database=CompanyNameProjectNameDB;uid=root;pwd=1q2w3E*;charset=utf8mb4;Allow User Variables=true;AllowLoadLocalInfile=true"
"Default": "Data Source=120.24.194.14;Database=CompanyNameProjectNameDB;uid=root;pwd=1q2w3E*;charset=utf8mb4;Allow User Variables=true;AllowLoadLocalInfile=true"
},
"IdentityServer": {
"Clients": {

86
aspnet-core/services/src/CompanyName.ProjectName.Domain/IdentityServer/IdentityServerDataSeedContributor.cs

@ -20,7 +20,7 @@ using Client = Volo.Abp.IdentityServer.Clients.Client;
namespace CompanyName.ProjectName.IdentityServer
{
public class IdentityServerDataSeedContributor : IDataSeedContributor, ITransientDependency
public class IdentityServerDataSeedContributor : IDataSeedContributor, ITransientDependency
{
private readonly IApiResourceRepository _apiResourceRepository;
private readonly IApiScopeRepository _apiScopeRepository;
@ -86,10 +86,10 @@ namespace CompanyName.ProjectName.IdentityServer
private async Task<ApiResource> CreateApiResourceAsync(IEnumerable<string> claims)
{
var apiResource = new ApiResource(
_guidGenerator.Create(),
"Identity.Api",
"身份认证中心Api"
);
_guidGenerator.Create(),
"Identity.Api",
"身份认证中心Api"
);
//foreach (var claim in claims)
//{
@ -99,31 +99,28 @@ namespace CompanyName.ProjectName.IdentityServer
// }
//}
return await _apiResourceRepository.InsertAsync(apiResource);
}
private async Task CreateApiScopeAsync()
{
await _apiScopeRepository.InsertAsync(
new ApiScope(
_guidGenerator.Create(),
"Api_Read"
),
autoSave: true
);
new ApiScope(
_guidGenerator.Create(),
"Api_Read"
),
autoSave: true
);
await _apiScopeRepository.InsertAsync(
new ApiScope(
_guidGenerator.Create(),
"Api_Write"
),
autoSave: true
);
new ApiScope(
_guidGenerator.Create(),
"Api_Write"
),
autoSave: true
);
}
private async Task CreateClientsAsync()
@ -142,15 +139,14 @@ namespace CompanyName.ProjectName.IdentityServer
name: "Vue3",
description: "Vue3-UI",
scopes: commonScopes,
grantTypes: new[] { "implicit" },
grantTypes: new[] {"implicit"},
secret: "1q2w3E*".Sha256(),
redirectUri: "http://localhost:4200/oidc",
postLogoutRedirectUri: "http://localhost:4200/oidc",
postLogoutRedirectUri: "http://localhost:4200/oidc,http://120.24.194.14:8012/oidc",
frontChannelLogoutUri: "http://localhost:4200/oidc",
corsOrigins: new[] { "https://localhost:4200", "http://localhost:4200" },
corsOrigins: new[] {"https://localhost:4200", "http://localhost:4200", "http://120.24.194.14:8012"},
requireClientSecret: false
);
}
private async Task<Client> CreateClientAsync(
@ -167,28 +163,26 @@ namespace CompanyName.ProjectName.IdentityServer
IEnumerable<string> permissions = null,
IEnumerable<string> corsOrigins = null)
{
var client = new Client(
_guidGenerator.Create(),
name
)
{
ClientName = name,
ProtocolType = "oidc",
Description = description,
AlwaysIncludeUserClaimsInIdToken = true,
AllowOfflineAccess = true,
AbsoluteRefreshTokenLifetime = 31536000, //365 days
AccessTokenLifetime = 31536000, //365 days
AuthorizationCodeLifetime = 300,
IdentityTokenLifetime = 300,
RequireConsent = false,
FrontChannelLogoutUri = frontChannelLogoutUri,
RequireClientSecret = requireClientSecret,
RequirePkce = requirePkce,
AllowAccessTokensViaBrowser = true,
};
_guidGenerator.Create(),
name
)
{
ClientName = name,
ProtocolType = "oidc",
Description = description,
AlwaysIncludeUserClaimsInIdToken = true,
AllowOfflineAccess = true,
AbsoluteRefreshTokenLifetime = 31536000, //365 days
AccessTokenLifetime = 31536000, //365 days
AuthorizationCodeLifetime = 300,
IdentityTokenLifetime = 300,
RequireConsent = false,
FrontChannelLogoutUri = frontChannelLogoutUri,
RequireClientSecret = requireClientSecret,
RequirePkce = requirePkce,
AllowAccessTokensViaBrowser = true,
};
foreach (var scope in scopes)
@ -255,4 +249,4 @@ namespace CompanyName.ProjectName.IdentityServer
return await _clientRepository.InsertAsync(client);
}
}
}
}

2
vben271/.env.production

@ -36,7 +36,7 @@ VITE_LEGACY = false
VITE_BUILD_COMPRESS = 'none'
# 认证授权服务器地址
VITE_AUTH_URL='http://sts.xx.cn'
VITE_AUTH_URL='http://120.24.194.14:8013'
# 接口地址

BIN
vben271/dist.zip

Binary file not shown.

8
vben271/src/router/guard/index.ts

@ -12,7 +12,7 @@ import { createStateGuard } from './stateGuard';
import nProgress from 'nprogress';
import projectSetting from '/@/settings/projectSetting';
import { createParamMenuGuard } from './paramMenuGuard';
import { PageEnum } from '/@/enums/pageEnum';
// Don't change the order of creation
export function setupRouterGuard(router: Router) {
createPageGuard(router);
@ -37,7 +37,11 @@ function createPageGuard(router: Router) {
to.meta.loaded = !!loadedPageMap.get(to.path);
// Notify routing changes
setRouteChange(to);
console.log(1);
if (to.path.includes('Error')) {
router.replace(PageEnum.BASE_LOGIN);
return;
}
return true;
});

Loading…
Cancel
Save