diff --git a/framework/src/Volo.Abp.AspNetCore.Components.Server/Microsoft/AspNetCore/Authentication/Cookies/CookieAuthenticationOptionsExtensions.cs b/framework/src/Volo.Abp.AspNetCore.Components.Server/Microsoft/AspNetCore/Authentication/Cookies/CookieAuthenticationOptionsExtensions.cs
index 327088d3e0..48065bbac2 100644
--- a/framework/src/Volo.Abp.AspNetCore.Components.Server/Microsoft/AspNetCore/Authentication/Cookies/CookieAuthenticationOptionsExtensions.cs
+++ b/framework/src/Volo.Abp.AspNetCore.Components.Server/Microsoft/AspNetCore/Authentication/Cookies/CookieAuthenticationOptionsExtensions.cs
@@ -18,59 +18,64 @@ public static class CookieAuthenticationOptionsExtensions
///
public static CookieAuthenticationOptions IntrospectAccessToken(this CookieAuthenticationOptions options, string oidcAuthenticationScheme = "oidc")
{
- var originalHandler = options.Events.OnValidatePrincipal;
options.Events.OnValidatePrincipal = async principalContext =>
{
- originalHandler?.Invoke(principalContext);
-
- if (principalContext.Principal != null && principalContext.Principal.Identity != null && principalContext.Principal.Identity.IsAuthenticated)
+ if (principalContext.Principal == null || principalContext.Principal.Identity == null || !principalContext.Principal.Identity.IsAuthenticated)
{
- var logger = principalContext.HttpContext.RequestServices.GetRequiredService>();
-
- var accessToken = principalContext.Properties.GetTokenValue("access_token");
- if (!accessToken.IsNullOrWhiteSpace())
- {
- var openIdConnectOptions = principalContext.HttpContext.RequestServices.GetRequiredService>().Get(oidcAuthenticationScheme);
- if (openIdConnectOptions.Configuration == null && openIdConnectOptions.ConfigurationManager != null)
- {
- openIdConnectOptions.Configuration = await openIdConnectOptions.ConfigurationManager.GetConfigurationAsync(principalContext.HttpContext.RequestAborted);
- }
-
- var response = await openIdConnectOptions.Backchannel.IntrospectTokenAsync(new TokenIntrospectionRequest
- {
- Address = openIdConnectOptions.Configuration?.IntrospectionEndpoint ?? openIdConnectOptions.Authority.EnsureEndsWith('/') + "connect/introspect",
- ClientId = openIdConnectOptions.ClientId,
- ClientSecret = openIdConnectOptions.ClientSecret,
- Token = accessToken
- });
+ return;
+ }
- if (response.IsError)
- {
- logger.LogError(response.Error);
- await SignOutAsync(principalContext);
- return;
- }
+ var logger = principalContext.HttpContext.RequestServices.GetRequiredService>();
- if (!response.IsActive)
- {
- logger.LogError("The access_token is not active.");
- await SignOutAsync(principalContext);
- return;
- }
+ var accessToken = principalContext.Properties.GetTokenValue("access_token");
+ if (!accessToken.IsNullOrWhiteSpace())
+ {
+ var openIdConnectOptions = await GetOpenIdConnectOptions(principalContext, oidcAuthenticationScheme);
+ var response = await openIdConnectOptions.Backchannel.IntrospectTokenAsync(new TokenIntrospectionRequest
+ {
+ Address = openIdConnectOptions.Configuration?.IntrospectionEndpoint ?? openIdConnectOptions.Authority.EnsureEndsWith('/') + "connect/introspect",
+ ClientId = openIdConnectOptions.ClientId,
+ ClientSecret = openIdConnectOptions.ClientSecret,
+ Token = accessToken
+ });
- logger.LogInformation("The access_token is active.");
+ if (response.IsError)
+ {
+ logger.LogError(response.Error);
+ await SignOutAsync(principalContext);
+ return;
}
- else
+
+ if (!response.IsActive)
{
- logger.LogError("The access_token is not found in the cookie properties, Please make sure SaveTokens of OpenIdConnectOptions is set as true.");
+ logger.LogError("The access_token is not active.");
await SignOutAsync(principalContext);
+ return;
}
+
+ logger.LogInformation("The access_token is active.");
+ }
+ else
+ {
+ logger.LogError("The access_token is not found in the cookie properties, Please make sure SaveTokens of OpenIdConnectOptions is set as true.");
+ await SignOutAsync(principalContext);
}
};
return options;
}
+ private async static Task GetOpenIdConnectOptions(CookieValidatePrincipalContext principalContext, string oidcAuthenticationScheme)
+ {
+ var openIdConnectOptions = principalContext.HttpContext.RequestServices.GetRequiredService>().Get(oidcAuthenticationScheme);
+ if (openIdConnectOptions.Configuration == null && openIdConnectOptions.ConfigurationManager != null)
+ {
+ openIdConnectOptions.Configuration = await openIdConnectOptions.ConfigurationManager.GetConfigurationAsync(principalContext.HttpContext.RequestAborted);
+ }
+
+ return openIdConnectOptions;
+ }
+
private async static Task SignOutAsync(CookieValidatePrincipalContext principalContext)
{
principalContext.RejectPrincipal();
diff --git a/framework/src/Volo.Abp.AspNetCore/Microsoft/Extensions/DependencyInjection/CookieAuthenticationOptionsExtensions.cs b/framework/src/Volo.Abp.AspNetCore/Microsoft/Extensions/DependencyInjection/CookieAuthenticationOptionsExtensions.cs
index 835455795d..f873f3762b 100644
--- a/framework/src/Volo.Abp.AspNetCore/Microsoft/Extensions/DependencyInjection/CookieAuthenticationOptionsExtensions.cs
+++ b/framework/src/Volo.Abp.AspNetCore/Microsoft/Extensions/DependencyInjection/CookieAuthenticationOptionsExtensions.cs
@@ -19,68 +19,61 @@ public static class CookieAuthenticationOptionsExtensions
{
advance ??= TimeSpan.FromMinutes(3);
validationInterval ??= TimeSpan.FromMinutes(1);
- var originalHandler = options.Events.OnValidatePrincipal;
options.Events.OnValidatePrincipal = async principalContext =>
{
- originalHandler?.Invoke(principalContext);
+ if (principalContext.Principal == null || principalContext.Principal.Identity == null || !principalContext.Principal.Identity.IsAuthenticated)
+ {
+ return;
+ }
+
+ var logger = principalContext.HttpContext.RequestServices.GetRequiredService>();
- if (principalContext.Principal != null && principalContext.Principal.Identity != null && principalContext.Principal.Identity.IsAuthenticated)
+ var tokenExpiresAt = principalContext.Properties.Items[".Token.expires_at"];
+ if (DateTimeOffset.TryParseExact(tokenExpiresAt, "o", null, DateTimeStyles.RoundtripKind, out var expiresAt) &&
+ expiresAt < DateTimeOffset.UtcNow.Subtract(advance.Value))
{
- var logger = principalContext.HttpContext.RequestServices.GetRequiredService>();
+ logger.LogInformation("The access_token is expired.");
+ await SignOutAsync(principalContext);
+ return;
+ }
- var tokenExpiresAt = principalContext.Properties.Items[".Token.expires_at"];
- if (DateTimeOffset.TryParseExact(tokenExpiresAt, "o", null, DateTimeStyles.RoundtripKind, out var expiresAt) && expiresAt < DateTimeOffset.UtcNow.Subtract(advance.Value))
+ if (principalContext.Properties.IssuedUtc != null && DateTimeOffset.UtcNow.Subtract(principalContext.Properties.IssuedUtc.Value) > validationInterval)
+ {
+ logger.LogInformation($"Check the access_token is active every {validationInterval.Value.TotalSeconds} seconds.");
+ var accessToken = principalContext.Properties.GetTokenValue("access_token");
+ if (!accessToken.IsNullOrWhiteSpace())
{
- logger.LogInformation("The access_token is expired.");
- await SignOutAsync(principalContext);
- return;
- }
+ var openIdConnectOptions = await GetOpenIdConnectOptions(principalContext, oidcAuthenticationScheme);
- if (principalContext.Properties.IssuedUtc != null)
- {
- if (DateTimeOffset.UtcNow.Subtract(principalContext.Properties.IssuedUtc.Value) > validationInterval)
+ var response = await openIdConnectOptions.Backchannel.IntrospectTokenAsync(new TokenIntrospectionRequest
{
- logger.LogInformation($"Check the access_token is active every {validationInterval.Value.TotalSeconds} seconds.");
- var accessToken = principalContext.Properties.GetTokenValue("access_token");
- if (!accessToken.IsNullOrWhiteSpace())
- {
- var openIdConnectOptions = principalContext.HttpContext.RequestServices.GetRequiredService>().Get(oidcAuthenticationScheme);
- if (openIdConnectOptions.Configuration == null && openIdConnectOptions.ConfigurationManager != null)
- {
- openIdConnectOptions.Configuration = await openIdConnectOptions.ConfigurationManager.GetConfigurationAsync(principalContext.HttpContext.RequestAborted);
- }
-
- var response = await openIdConnectOptions.Backchannel.IntrospectTokenAsync(new TokenIntrospectionRequest
- {
- Address = openIdConnectOptions.Configuration?.IntrospectionEndpoint ?? openIdConnectOptions.Authority.EnsureEndsWith('/') + "connect/introspect",
- ClientId = openIdConnectOptions.ClientId,
- ClientSecret = openIdConnectOptions.ClientSecret,
- Token = accessToken
- });
+ Address = openIdConnectOptions.Configuration?.IntrospectionEndpoint ?? openIdConnectOptions.Authority.EnsureEndsWith('/') + "connect/introspect",
+ ClientId = openIdConnectOptions.ClientId,
+ ClientSecret = openIdConnectOptions.ClientSecret,
+ Token = accessToken
+ });
- if (response.IsError)
- {
- logger.LogError(response.Error);
- await SignOutAsync(principalContext);
- return;
- }
-
- if (!response.IsActive)
- {
- logger.LogError("The access_token is not active.");
- await SignOutAsync(principalContext);
- return;
- }
+ if (response.IsError)
+ {
+ logger.LogError(response.Error);
+ await SignOutAsync(principalContext);
+ return;
+ }
- logger.LogInformation("The access_token is active.");
- principalContext.ShouldRenew = true;
- }
- else
- {
- logger.LogError("The access_token is not found in the cookie properties, Please make sure SaveTokens of OpenIdConnectOptions is set as true.");
- await SignOutAsync(principalContext);
- }
+ if (!response.IsActive)
+ {
+ logger.LogError("The access_token is not active.");
+ await SignOutAsync(principalContext);
+ return;
}
+
+ logger.LogInformation("The access_token is active.");
+ principalContext.ShouldRenew = true;
+ }
+ else
+ {
+ logger.LogError("The access_token is not found in the cookie properties, Please make sure SaveTokens of OpenIdConnectOptions is set as true.");
+ await SignOutAsync(principalContext);
}
}
};
@@ -88,6 +81,17 @@ public static class CookieAuthenticationOptionsExtensions
return options;
}
+ private async static Task GetOpenIdConnectOptions(CookieValidatePrincipalContext principalContext, string oidcAuthenticationScheme)
+ {
+ var openIdConnectOptions = principalContext.HttpContext.RequestServices.GetRequiredService>().Get(oidcAuthenticationScheme);
+ if (openIdConnectOptions.Configuration == null && openIdConnectOptions.ConfigurationManager != null)
+ {
+ openIdConnectOptions.Configuration = await openIdConnectOptions.ConfigurationManager.GetConfigurationAsync(principalContext.HttpContext.RequestAborted);
+ }
+
+ return openIdConnectOptions;
+ }
+
private async static Task SignOutAsync(CookieValidatePrincipalContext principalContext)
{
principalContext.RejectPrincipal();