Browse Source

Enhance LinkLoginExtensionGrantValidator.

pull/5190/head
maliming 6 years ago
parent
commit
65f3554b4e
  1. 11
      modules/identity/src/Volo.Abp.Identity.Domain/Volo/Abp/Identity/AbpUserClaimsPrincipalFactory.cs
  2. 7
      modules/identityserver/src/Volo.Abp.IdentityServer.Domain.Shared/Volo/Abp/IdentityServer/Localization/Resources/en.json
  3. 5
      modules/identityserver/src/Volo.Abp.IdentityServer.Domain.Shared/Volo/Abp/IdentityServer/Localization/Resources/tr.json
  4. 5
      modules/identityserver/src/Volo.Abp.IdentityServer.Domain.Shared/Volo/Abp/IdentityServer/Localization/Resources/zh-Hans.json
  5. 40
      modules/identityserver/src/Volo.Abp.IdentityServer.Domain/Volo/Abp/IdentityServer/AspNetIdentity/LinkLoginExtensionGrantValidator.cs

11
modules/identity/src/Volo.Abp.Identity.Domain/Volo/Abp/Identity/AbpUserClaimsPrincipalFactory.cs

@ -5,31 +5,22 @@ using System.Threading.Tasks;
using Microsoft.AspNetCore.Identity; using Microsoft.AspNetCore.Identity;
using Microsoft.Extensions.Options; using Microsoft.Extensions.Options;
using Volo.Abp.DependencyInjection; using Volo.Abp.DependencyInjection;
using Volo.Abp.MultiTenancy;
using Volo.Abp.Security.Claims; using Volo.Abp.Security.Claims;
using Volo.Abp.Uow; using Volo.Abp.Uow;
using Volo.Abp.Users;
namespace Volo.Abp.Identity namespace Volo.Abp.Identity
{ {
public class AbpUserClaimsPrincipalFactory : UserClaimsPrincipalFactory<IdentityUser, IdentityRole>, ITransientDependency public class AbpUserClaimsPrincipalFactory : UserClaimsPrincipalFactory<IdentityUser, IdentityRole>, ITransientDependency
{ {
protected ICurrentUser CurrentUser { get; }
protected ICurrentTenant CurrentTenant { get; }
public AbpUserClaimsPrincipalFactory( public AbpUserClaimsPrincipalFactory(
UserManager<IdentityUser> userManager, UserManager<IdentityUser> userManager,
RoleManager<IdentityRole> roleManager, RoleManager<IdentityRole> roleManager,
IOptions<IdentityOptions> options, IOptions<IdentityOptions> options)
ICurrentUser currentUser,
ICurrentTenant currentTenant)
: base( : base(
userManager, userManager,
roleManager, roleManager,
options) options)
{ {
CurrentUser = currentUser;
CurrentTenant = currentTenant;
} }
[UnitOfWork] [UnitOfWork]

7
modules/identityserver/src/Volo.Abp.IdentityServer.Domain.Shared/Volo/Abp/IdentityServer/Localization/Resources/en.json

@ -1,4 +1,4 @@
{ {
"culture": "en", "culture": "en",
"texts": { "texts": {
"Volo.IdentityServer:DuplicateIdentityResourceName": "Identity Resource name already exist: {Name}", "Volo.IdentityServer:DuplicateIdentityResourceName": "Identity Resource name already exist: {Name}",
@ -7,6 +7,7 @@
"UserLockedOut": "The user account has been locked out due to invalid login attempts. Please wait a while and try again.", "UserLockedOut": "The user account has been locked out due to invalid login attempts. Please wait a while and try again.",
"InvalidUserNameOrPassword": "Invalid username or password!", "InvalidUserNameOrPassword": "Invalid username or password!",
"LoginIsNotAllowed": "You are not allowed to login! You need to confirm your email/phone number.", "LoginIsNotAllowed": "You are not allowed to login! You need to confirm your email/phone number.",
"InvalidUsername": "Invalid username or password!" "InvalidUsername": "Invalid username or password!",
"TheTargetUserIsNotLinkedToYou": "The target user is not linked to you!"
} }
} }

5
modules/identityserver/src/Volo.Abp.IdentityServer.Domain.Shared/Volo/Abp/IdentityServer/Localization/Resources/tr.json

@ -7,6 +7,7 @@
"UserLockedOut": "Kullanıcı hesabı hatalı giriş denemeleri nedeniyle kilitlenmiştir. Lütfen bir süre bekleyip tekrar deneyin.", "UserLockedOut": "Kullanıcı hesabı hatalı giriş denemeleri nedeniyle kilitlenmiştir. Lütfen bir süre bekleyip tekrar deneyin.",
"InvalidUserNameOrPassword": "Kullanıcı adı ya da şifre geçersiz!", "InvalidUserNameOrPassword": "Kullanıcı adı ya da şifre geçersiz!",
"LoginIsNotAllowed": "Giriş yapamazsınız! E-posta adresinizi ya da telefon numaranızı doğrulamanız gerekiyor.", "LoginIsNotAllowed": "Giriş yapamazsınız! E-posta adresinizi ya da telefon numaranızı doğrulamanız gerekiyor.",
"InvalidUsername": "Kullanıcı adı ya da şifre geçersiz!" "InvalidUsername": "Kullanıcı adı ya da şifre geçersiz!",
"TheTargetUserIsNotLinkedToYou": "Hedef kullanıcı sizinle bağlantılı değil!"
} }
} }

5
modules/identityserver/src/Volo.Abp.IdentityServer.Domain.Shared/Volo/Abp/IdentityServer/Localization/Resources/zh-Hans.json

@ -7,6 +7,7 @@
"UserLockedOut": "登录失败,用户账户已被锁定.请稍后再试.", "UserLockedOut": "登录失败,用户账户已被锁定.请稍后再试.",
"InvalidUserNameOrPassword": "用户名或密码错误!", "InvalidUserNameOrPassword": "用户名或密码错误!",
"LoginIsNotAllowed": "无法登录!你需要验证邮箱地址/手机号.", "LoginIsNotAllowed": "无法登录!你需要验证邮箱地址/手机号.",
"InvalidUsername": "用户名或密码错误!" "InvalidUsername": "用户名或密码错误!",
"TheTargetUserIsNotLinkedToYou": "目标用户未和你有关联!"
} }
} }

40
modules/identityserver/src/Volo.Abp.IdentityServer.Domain/Volo/Abp/IdentityServer/AspNetIdentity/LinkLoginExtensionGrantValidator.cs

@ -17,7 +17,7 @@ namespace Volo.Abp.IdentityServer.AspNetIdentity
{ {
public class LinkLoginExtensionGrantValidator : IExtensionGrantValidator public class LinkLoginExtensionGrantValidator : IExtensionGrantValidator
{ {
public const string ExtensionGrantType = "LinkUserLogin"; public const string ExtensionGrantType = "LinkLogin";
public string GrantType => ExtensionGrantType; public string GrantType => ExtensionGrantType;
@ -80,8 +80,7 @@ namespace Volo.Abp.IdentityServer.AspNetIdentity
using (CurrentPrincipalAccessor.Change(result.Claims)) using (CurrentPrincipalAccessor.Change(result.Claims))
{ {
var linkUserId = Guid.Empty;; if (!Guid.TryParse(context.Request.Raw["LinkUserId"], out var linkUserId))
if (!StringToGuid(context.Request.Raw["LinkUserId"], ref linkUserId))
{ {
context.Result = new GrantValidationResult context.Result = new GrantValidationResult
{ {
@ -94,7 +93,7 @@ namespace Volo.Abp.IdentityServer.AspNetIdentity
Guid? linkTenantId = null; Guid? linkTenantId = null;
if (!context.Request.Raw["LinkTenantId"].IsNullOrWhiteSpace()) if (!context.Request.Raw["LinkTenantId"].IsNullOrWhiteSpace())
{ {
if (!StringToGuid(context.Request.Raw["LinkTenantId"], ref linkTenantId)) if (!Guid.TryParse(context.Request.Raw["LinkUserId"], out var parsedGuid))
{ {
context.Result = new GrantValidationResult context.Result = new GrantValidationResult
{ {
@ -103,6 +102,8 @@ namespace Volo.Abp.IdentityServer.AspNetIdentity
}; };
return; return;
} }
linkTenantId = parsedGuid;
} }
var isLinked = await IdentityLinkUserManager.IsLinkedAsync( var isLinked = await IdentityLinkUserManager.IsLinkedAsync(
@ -131,8 +132,7 @@ namespace Volo.Abp.IdentityServer.AspNetIdentity
context.Result = new GrantValidationResult context.Result = new GrantValidationResult
{ {
IsError = true, IsError = true,
//TODO: Localizer error message. Error = Localizer["TheTargetUserIsNotLinkedToYou"]
Error = "The_Target_User_Is_Not_Linked_ToYou"
}; };
} }
} }
@ -147,33 +147,5 @@ namespace Volo.Abp.IdentityServer.AspNetIdentity
return Task.CompletedTask; return Task.CompletedTask;
} }
protected virtual bool StringToGuid(string str, ref Guid guid)
{
if (str.IsNullOrWhiteSpace())
{
return false;
}
if (Guid.TryParse(str, out var g))
{
guid = g;
return true;
}
return false;
}
protected virtual bool StringToGuid(string str, ref Guid? guid)
{
var g = Guid.Empty;
if (StringToGuid(str, ref g))
{
guid = g;
return true;
}
return false;
}
} }
} }

Loading…
Cancel
Save