From 1f5d778c2b503ecad466985b9a8911cabdd32353 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Halil=20=C4=B0brahim=20Kalkan?= Date: Thu, 8 Mar 2018 14:35:00 +0300 Subject: [PATCH] Added extension methods to AbpAuthorizationServiceExtensions. Worked on identity permissions and menus. --- .../AbpDesk.Web.Mvc/AbpDesk.Web.Mvc.csproj | 1 - .../AbpDesk.Web.Mvc/AbpDeskWebMvcModule.cs | 1 - .../MicroservicesDemoWebModule.cs | 3 +- .../Pages/Index.cshtml.cs | 7 +- .../Authorization/AbpAuthorizationService.cs | 20 ++- .../AbpAuthorizationServiceExtensions.cs | 132 +++++++++++++++++- .../Authorization/IAbpAuthorizationService.cs | 7 +- .../AbpIdentityWebMainMenuContributor.cs | 26 ++-- .../Pages/Identity/Users/Index.cshtml | 15 +- .../Volo/Abp/Ui/Navigation/StandardMenus.cs | 2 - 10 files changed, 173 insertions(+), 41 deletions(-) diff --git a/src/AbpDesk/AbpDesk.Web.Mvc/AbpDesk.Web.Mvc.csproj b/src/AbpDesk/AbpDesk.Web.Mvc/AbpDesk.Web.Mvc.csproj index e7f2e7fc24..030061a386 100644 --- a/src/AbpDesk/AbpDesk.Web.Mvc/AbpDesk.Web.Mvc.csproj +++ b/src/AbpDesk/AbpDesk.Web.Mvc/AbpDesk.Web.Mvc.csproj @@ -24,7 +24,6 @@ - diff --git a/src/AbpDesk/AbpDesk.Web.Mvc/AbpDeskWebMvcModule.cs b/src/AbpDesk/AbpDesk.Web.Mvc/AbpDeskWebMvcModule.cs index baff058e4b..a5d4997808 100644 --- a/src/AbpDesk/AbpDesk.Web.Mvc/AbpDeskWebMvcModule.cs +++ b/src/AbpDesk/AbpDesk.Web.Mvc/AbpDeskWebMvcModule.cs @@ -41,7 +41,6 @@ namespace AbpDesk.Web.Mvc typeof(AbpAspNetCoreMvcUiBootstrapModule), typeof(AbpDeskApplicationModule), typeof(AbpDeskEntityFrameworkCoreModule), - typeof(AbpIdentityHttpApiModule), typeof(AbpIdentityEntityFrameworkCoreModule), typeof(AbpIdentityWebModule), typeof(AbpAccountWebModule), diff --git a/src/MicroserviceDemo/MicroserviceDemo.Web/MicroservicesDemoWebModule.cs b/src/MicroserviceDemo/MicroserviceDemo.Web/MicroservicesDemoWebModule.cs index 72f9b841b1..f0ff9fed1e 100644 --- a/src/MicroserviceDemo/MicroserviceDemo.Web/MicroservicesDemoWebModule.cs +++ b/src/MicroserviceDemo/MicroserviceDemo.Web/MicroservicesDemoWebModule.cs @@ -43,7 +43,7 @@ namespace MicroserviceDemo.Web { public override void ConfigureServices(IServiceCollection services) { - var hostingEnvironment = services.GetSingletonInstance(); + var hostingEnvironment = services.GetSingletonInstance(); //TODO: Create an extension method, like GetHostingEnvironment() ? var configuration = BuildConfiguration(hostingEnvironment); services.Configure(configuration); @@ -166,6 +166,7 @@ namespace MicroserviceDemo.Web }); } + //TODO: Create an extension method to IHostingEnvironment for that? private static IConfigurationRoot BuildConfiguration(IHostingEnvironment env) { var builder = new ConfigurationBuilder() diff --git a/src/MicroserviceDemo/MicroserviceDemo.Web/Pages/Index.cshtml.cs b/src/MicroserviceDemo/MicroserviceDemo.Web/Pages/Index.cshtml.cs index 0148f298da..dca3bddd63 100644 --- a/src/MicroserviceDemo/MicroserviceDemo.Web/Pages/Index.cshtml.cs +++ b/src/MicroserviceDemo/MicroserviceDemo.Web/Pages/Index.cshtml.cs @@ -1,9 +1,4 @@ -using System; -using System.Collections.Generic; -using System.Linq; -using System.Threading.Tasks; -using Microsoft.AspNetCore.Mvc; -using Microsoft.AspNetCore.Mvc.RazorPages; +using Microsoft.AspNetCore.Mvc.RazorPages; namespace MicroserviceDemo.Web.Pages { diff --git a/src/Volo.Abp.Authorization/Volo/Abp/Authorization/AbpAuthorizationService.cs b/src/Volo.Abp.Authorization/Volo/Abp/Authorization/AbpAuthorizationService.cs index c35471ee5b..d088bfa8ea 100644 --- a/src/Volo.Abp.Authorization/Volo/Abp/Authorization/AbpAuthorizationService.cs +++ b/src/Volo.Abp.Authorization/Volo/Abp/Authorization/AbpAuthorizationService.cs @@ -1,4 +1,5 @@ -using System.Threading.Tasks; +using System; +using System.Security.Claims; using Microsoft.AspNetCore.Authorization; using Microsoft.Extensions.Logging; using Microsoft.Extensions.Options; @@ -10,6 +11,10 @@ namespace Volo.Abp.Authorization [Dependency(ReplaceServices = true)] public class AbpAuthorizationService : DefaultAuthorizationService, IAbpAuthorizationService, ITransientDependency { + public IServiceProvider ServiceProvider { get; } + + public ClaimsPrincipal CurrentPrincipal => _currentPrincipalAccessor.Principal; + private readonly ICurrentPrincipalAccessor _currentPrincipalAccessor; public AbpAuthorizationService( @@ -19,7 +24,8 @@ namespace Volo.Abp.Authorization IAuthorizationHandlerContextFactory contextFactory, IAuthorizationEvaluator evaluator, IOptions options, - ICurrentPrincipalAccessor currentPrincipalAccessor) + ICurrentPrincipalAccessor currentPrincipalAccessor, + IServiceProvider serviceProvider) : base( policyProvider, handlers, @@ -29,15 +35,7 @@ namespace Volo.Abp.Authorization options) { _currentPrincipalAccessor = currentPrincipalAccessor; - } - - public async Task CheckAsync(string policyName) - { - var result = await AuthorizeAsync(_currentPrincipalAccessor.Principal, null, policyName); - if (!result.Succeeded) - { - throw new AbpAuthorizationException("Authorization failed! Given policy has not granted: " + policyName); - } + ServiceProvider = serviceProvider; } } } \ No newline at end of file diff --git a/src/Volo.Abp.Authorization/Volo/Abp/Authorization/AbpAuthorizationServiceExtensions.cs b/src/Volo.Abp.Authorization/Volo/Abp/Authorization/AbpAuthorizationServiceExtensions.cs index 9b6c020ff1..637c82b040 100644 --- a/src/Volo.Abp.Authorization/Volo/Abp/Authorization/AbpAuthorizationServiceExtensions.cs +++ b/src/Volo.Abp.Authorization/Volo/Abp/Authorization/AbpAuthorizationServiceExtensions.cs @@ -1,13 +1,139 @@ -using System.Threading.Tasks; +using System.Collections.Generic; +using System.Threading.Tasks; using Microsoft.AspNetCore.Authorization; namespace Volo.Abp.Authorization { public static class AbpAuthorizationServiceExtensions { - public static Task CheckAsync(this IAuthorizationService authorizationService, string policyName) + public static Task AuthorizeAsync(this IAuthorizationService authorizationService, string policyName) { - return authorizationService.AsAbpAuthorizationService().CheckAsync(policyName); + return authorizationService.AuthorizeAsync( + authorizationService.AsAbpAuthorizationService().CurrentPrincipal, + policyName + ); + } + + public static Task AuthorizeAsync(this IAuthorizationService authorizationService, object resource, IAuthorizationRequirement requirement) + { + return authorizationService.AuthorizeAsync( + authorizationService.AsAbpAuthorizationService().CurrentPrincipal, + resource, + requirement + ); + } + + public static Task AuthorizeAsync(this IAuthorizationService authorizationService, object resource, AuthorizationPolicy policy) + { + return authorizationService.AuthorizeAsync( + authorizationService.AsAbpAuthorizationService().CurrentPrincipal, + resource, + policy + ); + } + + public static Task AuthorizeAsync(this IAuthorizationService authorizationService, AuthorizationPolicy policy) + { + return authorizationService.AuthorizeAsync( + authorizationService.AsAbpAuthorizationService().CurrentPrincipal, + policy + ); + } + + public static Task AuthorizeAsync(this IAuthorizationService authorizationService, object resource, IEnumerable requirements) + { + return authorizationService.AuthorizeAsync( + authorizationService.AsAbpAuthorizationService().CurrentPrincipal, + resource, + requirements + ); + } + + public static Task AuthorizeAsync(this IAuthorizationService authorizationService, object resource, string policyName) + { + return authorizationService.AuthorizeAsync( + authorizationService.AsAbpAuthorizationService().CurrentPrincipal, + resource, + policyName + ); + } + + public static async Task IsGrantedAsync(this IAuthorizationService authorizationService, string policyName) + { + return (await authorizationService.AuthorizeAsync(policyName)).Succeeded; + } + + public static async Task IsGrantedAsync(this IAuthorizationService authorizationService, object resource, IAuthorizationRequirement requirement) + { + return (await authorizationService.AuthorizeAsync(resource, requirement)).Succeeded; + } + + public static async Task IsGrantedAsync(this IAuthorizationService authorizationService, object resource, AuthorizationPolicy policy) + { + return (await authorizationService.AuthorizeAsync(resource, policy)).Succeeded; + } + + public static async Task IsGrantedAsync(this IAuthorizationService authorizationService, AuthorizationPolicy policy) + { + return (await authorizationService.AuthorizeAsync(policy)).Succeeded; + } + + public static async Task IsGrantedAsync(this IAuthorizationService authorizationService, object resource, IEnumerable requirements) + { + return (await authorizationService.AuthorizeAsync(resource, requirements)).Succeeded; + } + + public static async Task IsGrantedAsync(this IAuthorizationService authorizationService, object resource, string policyName) + { + return (await authorizationService.AuthorizeAsync(resource, policyName)).Succeeded; + } + + public static async Task CheckAsync(this IAuthorizationService authorizationService, string policyName) + { + if (!await authorizationService.IsGrantedAsync(policyName)) + { + throw new AbpAuthorizationException("Authorization failed! Given policy has not granted: " + policyName); + } + } + + public static async Task CheckAsync(this IAuthorizationService authorizationService, object resource, IAuthorizationRequirement requirement) + { + if (!await authorizationService.IsGrantedAsync(resource, requirement)) + { + throw new AbpAuthorizationException("Authorization failed! Given requirement has not granted for given resource: " + resource); + } + } + + public static async Task CheckAsync(this IAuthorizationService authorizationService, object resource, AuthorizationPolicy policy) + { + if (!await authorizationService.IsGrantedAsync(resource, policy)) + { + throw new AbpAuthorizationException("Authorization failed! Given policy has not granted for given resource: " + resource); + } + } + + public static async Task CheckAsync(this IAuthorizationService authorizationService, AuthorizationPolicy policy) + { + if (!await authorizationService.IsGrantedAsync(policy)) + { + throw new AbpAuthorizationException("Authorization failed! Given policy has not granted."); + } + } + + public static async Task CheckAsync(this IAuthorizationService authorizationService, object resource, IEnumerable requirements) + { + if (!await authorizationService.IsGrantedAsync(resource, requirements)) + { + throw new AbpAuthorizationException("Authorization failed! Given requirements have not granted for given resource: " + resource); + } + } + + public static async Task CheckAsync(this IAuthorizationService authorizationService, object resource, string policyName) + { + if (!await authorizationService.IsGrantedAsync(resource, policyName)) + { + throw new AbpAuthorizationException("Authorization failed! Given polist has not granted for given resource: " + resource); + } } private static IAbpAuthorizationService AsAbpAuthorizationService(this IAuthorizationService authorizationService) diff --git a/src/Volo.Abp.Authorization/Volo/Abp/Authorization/IAbpAuthorizationService.cs b/src/Volo.Abp.Authorization/Volo/Abp/Authorization/IAbpAuthorizationService.cs index 5928b26062..d4fdb590cc 100644 --- a/src/Volo.Abp.Authorization/Volo/Abp/Authorization/IAbpAuthorizationService.cs +++ b/src/Volo.Abp.Authorization/Volo/Abp/Authorization/IAbpAuthorizationService.cs @@ -1,10 +1,11 @@ -using System.Threading.Tasks; +using System.Security.Claims; using Microsoft.AspNetCore.Authorization; +using Volo.Abp.DependencyInjection; namespace Volo.Abp.Authorization { - public interface IAbpAuthorizationService : IAuthorizationService + public interface IAbpAuthorizationService : IAuthorizationService, IServiceProviderAccessor { - Task CheckAsync(string policyName); + ClaimsPrincipal CurrentPrincipal { get; } } } \ No newline at end of file diff --git a/src/Volo.Abp.Identity.Web/Navigation/AbpIdentityWebMainMenuContributor.cs b/src/Volo.Abp.Identity.Web/Navigation/AbpIdentityWebMainMenuContributor.cs index 145898f014..d7ce55226f 100644 --- a/src/Volo.Abp.Identity.Web/Navigation/AbpIdentityWebMainMenuContributor.cs +++ b/src/Volo.Abp.Identity.Web/Navigation/AbpIdentityWebMainMenuContributor.cs @@ -1,26 +1,34 @@ using System.Threading.Tasks; +using Microsoft.Extensions.DependencyInjection; +using Volo.Abp.Authorization.Permissions; using Volo.Abp.Ui.Navigation; namespace Volo.Abp.Identity.Web.Navigation { public class AbpIdentityWebMainMenuContributor : IMenuContributor { - public Task ConfigureMenuAsync(MenuConfigurationContext context) + public async Task ConfigureMenuAsync(MenuConfigurationContext context) { if (context.Menu.Name != StandardMenus.Main) { - return Task.CompletedTask; + return; } - context.Menu - .AddItem( - new ApplicationMenuItem("Identity", "Identity") - .AddItem(new ApplicationMenuItem("Users", "Users", url: "/Identity/Users")) - .AddItem(new ApplicationMenuItem("Roles", "Roles", url: "/Identity/Roles")) + var permissionChecker = context.ServiceProvider.GetRequiredService(); - ); + var identityMenuItem = new ApplicationMenuItem("Identity", "Identity"); - return Task.CompletedTask; + context.Menu.AddItem(identityMenuItem); + + if (await permissionChecker.IsGrantedAsync(IdentityPermissions.Roles.Default)) + { + identityMenuItem.AddItem(new ApplicationMenuItem("Roles", "Roles", url: "/Identity/Roles")); + } + + if (await permissionChecker.IsGrantedAsync(IdentityPermissions.Users.Default)) + { + identityMenuItem.AddItem(new ApplicationMenuItem("Users", "Users", url: "/Identity/Users")); + } } } } \ No newline at end of file diff --git a/src/Volo.Abp.Identity.Web/Pages/Identity/Users/Index.cshtml b/src/Volo.Abp.Identity.Web/Pages/Identity/Users/Index.cshtml index 1b8b17d86c..ac47f90490 100644 --- a/src/Volo.Abp.Identity.Web/Pages/Identity/Users/Index.cshtml +++ b/src/Volo.Abp.Identity.Web/Pages/Identity/Users/Index.cshtml @@ -1,8 +1,12 @@ @page @model Volo.Abp.Identity.Web.Pages.Identity.Users.IndexModel +@using Microsoft.AspNetCore.Authorization @using Microsoft.AspNetCore.Mvc.Localization +@using Volo.Abp.Authorization +@using Volo.Abp.Identity @using Volo.Abp.Identity.Web.Localization.Resources.AbpIdentity @inject IHtmlLocalizer L +@inject IAuthorizationService Authorization @section styles { } @@ -22,10 +26,13 @@

@L["Users"]

- + @if (await Authorization.IsGrantedAsync(IdentityPermissions.Users.Create)) + { + + }
diff --git a/src/Volo.Abp.UI.Navigation/Volo/Abp/Ui/Navigation/StandardMenus.cs b/src/Volo.Abp.UI.Navigation/Volo/Abp/Ui/Navigation/StandardMenus.cs index 28e5d4a1ab..5df07aec5c 100644 --- a/src/Volo.Abp.UI.Navigation/Volo/Abp/Ui/Navigation/StandardMenus.cs +++ b/src/Volo.Abp.UI.Navigation/Volo/Abp/Ui/Navigation/StandardMenus.cs @@ -1,7 +1,5 @@ namespace Volo.Abp.Ui.Navigation { - //TODO: Move these classes to Volo.Abp.Ui project? - public static class StandardMenus { public const string Main = "Main";