Browse Source

Added authorize attribute for new user app service methods.

pull/7950/head
Alper Ebicoglu 8 years ago
parent
commit
30dac1df5e
  1. 4
      modules/identity/src/Volo.Abp.Identity.Application/Volo/Abp/Identity/IdentityUserAppService.cs
  2. 9
      modules/identity/src/Volo.Abp.Identity.HttpApi/Volo/Abp/Identity/IdentityUserController.cs

4
modules/identity/src/Volo.Abp.Identity.Application/Volo/Abp/Identity/IdentityUserAppService.cs

@ -17,7 +17,7 @@ namespace Volo.Abp.Identity
private readonly IPermissionAppServiceHelper _permissionAppServiceHelper; private readonly IPermissionAppServiceHelper _permissionAppServiceHelper;
public IdentityUserAppService( public IdentityUserAppService(
IdentityUserManager userManager, IdentityUserManager userManager,
IIdentityUserRepository userRepository, IIdentityUserRepository userRepository,
IPermissionAppServiceHelper permissionAppServiceHelper) IPermissionAppServiceHelper permissionAppServiceHelper)
{ {
@ -113,6 +113,7 @@ namespace Volo.Abp.Identity
await _permissionAppServiceHelper.UpdateAsync(UserPermissionValueProvider.ProviderName, id.ToString(), input); await _permissionAppServiceHelper.UpdateAsync(UserPermissionValueProvider.ProviderName, id.ToString(), input);
} }
[Authorize(IdentityPermissions.Users.Default)]
public async Task<IdentityUserDto> FindByUsernameAsync(string username) public async Task<IdentityUserDto> FindByUsernameAsync(string username)
{ {
return ObjectMapper.Map<IdentityUser, IdentityUserDto>( return ObjectMapper.Map<IdentityUser, IdentityUserDto>(
@ -120,6 +121,7 @@ namespace Volo.Abp.Identity
); );
} }
[Authorize(IdentityPermissions.Users.Default)]
public async Task<IdentityUserDto> FindByEmailAsync(string email) public async Task<IdentityUserDto> FindByEmailAsync(string email)
{ {
return ObjectMapper.Map<IdentityUser, IdentityUserDto>( return ObjectMapper.Map<IdentityUser, IdentityUserDto>(

9
modules/identity/src/Volo.Abp.Identity.HttpApi/Volo/Abp/Identity/IdentityUserController.cs

@ -64,16 +64,11 @@ namespace Volo.Abp.Identity
return _userAppService.UpdatePermissionsAsync(id, input); return _userAppService.UpdatePermissionsAsync(id, input);
} }
//todo: add authorize attrbutes on the corresponding methods.
[HttpGet] [HttpGet]
public virtual Task<IdentityUserDto> FindByUsernameAsync(string username) public virtual Task<IdentityUserDto> FindByUsernameAsync(string username)
{ {
if (CurrentUser.Id.HasValue) return _userAppService.FindByUsernameAsync(username);
{
return _userAppService.FindByUsernameAsync(username);
}
Console.WriteLine("Not logged in!");
throw new UnauthorizedAccessException();
} }
[HttpGet] [HttpGet]

Loading…
Cancel
Save