|
|
|
@ -8,8 +8,6 @@ namespace Volo.Abp.AspNetCore.Mvc.AntiForgery |
|
|
|
{ |
|
|
|
public class AbpAutoValidateAntiforgeryTokenAuthorizationFilter : AbpValidateAntiforgeryTokenAuthorizationFilter, ITransientDependency |
|
|
|
{ |
|
|
|
private readonly AbpAntiForgeryCookieNameProvider _antiForgeryCookieNameProvider; |
|
|
|
|
|
|
|
public AbpAutoValidateAntiforgeryTokenAuthorizationFilter( |
|
|
|
IAntiforgery antiforgery, |
|
|
|
AbpAntiForgeryCookieNameProvider antiForgeryCookieNameProvider, |
|
|
|
@ -19,58 +17,26 @@ namespace Volo.Abp.AspNetCore.Mvc.AntiForgery |
|
|
|
antiForgeryCookieNameProvider, |
|
|
|
logger) |
|
|
|
{ |
|
|
|
_antiForgeryCookieNameProvider = antiForgeryCookieNameProvider; |
|
|
|
|
|
|
|
} |
|
|
|
|
|
|
|
protected override bool ShouldValidate(AuthorizationFilterContext context) |
|
|
|
{ |
|
|
|
if (!ShouldValidateInternal(context)) |
|
|
|
{ |
|
|
|
return false; |
|
|
|
} |
|
|
|
|
|
|
|
var authCookieName = _antiForgeryCookieNameProvider.GetAuthCookieNameOrNull(); |
|
|
|
|
|
|
|
//Always perform antiforgery validation when request contains authentication cookie
|
|
|
|
if (authCookieName != null && |
|
|
|
context.HttpContext.Request.Cookies.ContainsKey(authCookieName)) |
|
|
|
{ |
|
|
|
return true; |
|
|
|
} |
|
|
|
|
|
|
|
var antiForgeryCookieName = _antiForgeryCookieNameProvider.GetAntiForgeryCookieNameOrNull(); |
|
|
|
|
|
|
|
//No need to validate if antiforgery cookie is not sent.
|
|
|
|
//That means the request is sent from a non-browser client.
|
|
|
|
//See https://github.com/aspnet/Antiforgery/issues/115
|
|
|
|
if (antiForgeryCookieName != null && |
|
|
|
!context.HttpContext.Request.Cookies.ContainsKey(antiForgeryCookieName)) |
|
|
|
if (IsIgnoredHttpMethod(context)) |
|
|
|
{ |
|
|
|
return false; |
|
|
|
} |
|
|
|
|
|
|
|
// Anything else requires a token.
|
|
|
|
return true; |
|
|
|
return base.ShouldValidate(context); |
|
|
|
} |
|
|
|
|
|
|
|
private static bool ShouldValidateInternal(AuthorizationFilterContext context) |
|
|
|
protected virtual bool IsIgnoredHttpMethod(AuthorizationFilterContext context) |
|
|
|
{ |
|
|
|
if (context == null) |
|
|
|
{ |
|
|
|
throw new ArgumentNullException(nameof(context)); |
|
|
|
} |
|
|
|
|
|
|
|
var method = context.HttpContext.Request.Method; |
|
|
|
if (string.Equals("GET", method, StringComparison.OrdinalIgnoreCase) || |
|
|
|
string.Equals("HEAD", method, StringComparison.OrdinalIgnoreCase) || |
|
|
|
string.Equals("TRACE", method, StringComparison.OrdinalIgnoreCase) || |
|
|
|
string.Equals("OPTIONS", method, StringComparison.OrdinalIgnoreCase)) |
|
|
|
{ |
|
|
|
return false; |
|
|
|
} |
|
|
|
|
|
|
|
// Anything else requires a token.
|
|
|
|
return true; |
|
|
|
return string.Equals("GET", method, StringComparison.OrdinalIgnoreCase) || |
|
|
|
string.Equals("HEAD", method, StringComparison.OrdinalIgnoreCase) || |
|
|
|
string.Equals("TRACE", method, StringComparison.OrdinalIgnoreCase) || |
|
|
|
string.Equals("OPTIONS", method, StringComparison.OrdinalIgnoreCase); |
|
|
|
} |
|
|
|
} |
|
|
|
} |
|
|
|
|