Browse Source

Add Identity Two-factor features and settings.

pull/5156/head
maliming 6 years ago
parent
commit
6afc5ca2e7
  1. 14
      modules/feature-management/src/Volo.Abp.FeatureManagement.Web/Pages/FeatureManagement/FeatureManagementModal.cshtml
  2. 1
      modules/identity/src/Volo.Abp.Identity.Domain.Shared/Volo.Abp.Identity.Domain.Shared.csproj
  3. 6
      modules/identity/src/Volo.Abp.Identity.Domain.Shared/Volo/Abp/Identity/AbpIdentityDomainSharedModule.cs
  4. 9
      modules/identity/src/Volo.Abp.Identity.Domain.Shared/Volo/Abp/Identity/Features/IdentityFeature.cs
  5. 23
      modules/identity/src/Volo.Abp.Identity.Domain.Shared/Volo/Abp/Identity/Features/IdentityFeatureCheckerExtensions.cs
  6. 51
      modules/identity/src/Volo.Abp.Identity.Domain.Shared/Volo/Abp/Identity/Features/IdentityFeatureDefinitionProvider.cs
  7. 11
      modules/identity/src/Volo.Abp.Identity.Domain.Shared/Volo/Abp/Identity/Features/IdentityTwoFactorBehaviour.cs
  8. 10
      modules/identity/src/Volo.Abp.Identity.Domain.Shared/Volo/Abp/Identity/Localization/en.json
  9. 11
      modules/identity/src/Volo.Abp.Identity.Domain.Shared/Volo/Abp/Identity/Settings/IdentitySettingNames.cs
  10. 55
      modules/identity/src/Volo.Abp.Identity.Domain/Volo/Abp/Identity/AbpIdentitySettingDefinitionProvider.cs
  11. 25
      modules/identity/src/Volo.Abp.Identity.Domain/Volo/Abp/Identity/IdentitySettingProviderExtensions.cs
  12. 69
      modules/identity/src/Volo.Abp.Identity.Domain/Volo/Abp/Identity/IdentityTwoFactorManager.cs
  13. 34
      modules/identity/src/Volo.Abp.Identity.Domain/Volo/Abp/Identity/IdentityUserStore.cs

14
modules/feature-management/src/Volo.Abp.FeatureManagement.Web/Pages/FeatureManagement/FeatureManagementModal.cshtml

@ -1,13 +1,23 @@
@page @page
@using Microsoft.AspNetCore.Mvc.Localization @using Microsoft.AspNetCore.Mvc.Localization
@using Microsoft.Extensions.Options
@using Volo.Abp.AspNetCore.Mvc.UI.Bootstrap.TagHelpers.Modal @using Volo.Abp.AspNetCore.Mvc.UI.Bootstrap.TagHelpers.Modal
@using Volo.Abp.FeatureManagement.Localization @using Volo.Abp.FeatureManagement.Localization
@using Volo.Abp.Validation.StringValues @using Volo.Abp.Validation.StringValues
@using Volo.Abp.FeatureManagement.Web.Pages.FeatureManagement @using Volo.Abp.FeatureManagement.Web.Pages.FeatureManagement
@using Volo.Abp.Localization
@model FeatureManagementModal @model FeatureManagementModal
@inject IHtmlLocalizerFactory HtmlLocalizerFactory
@inject IOptions<AbpLocalizationOptions> LocalizationOptions
@inject IHtmlLocalizer<AbpFeatureManagementResource> L @inject IHtmlLocalizer<AbpFeatureManagementResource> L
@{ @{
Layout = null; Layout = null;
IHtmlLocalizer CreateHtmlLocalizer(string resourceName)
{
var resource = LocalizationOptions.Value.Resources.Values.FirstOrDefault(x => x.ResourceName == resourceName);
return HtmlLocalizerFactory.Create(resource != null ? resource.ResourceType : LocalizationOptions.Value.DefaultResourceType);
}
} }
<form method="post" asp-page="/FeatureManagement/FeatureManagementModal" data-script-class="abp.modals.FeatureManagement"> <form method="post" asp-page="/FeatureManagement/FeatureManagementModal" data-script-class="abp.modals.FeatureManagement">
<abp-modal size="Large"> <abp-modal size="Large">
@ -38,11 +48,11 @@
{ {
if (item.Value == feature.Value) if (item.Value == feature.Value)
{ {
<option value="@item.Value" selected="selected"> @L.GetString(item.DisplayText.Name) </option> <option value="@item.Value" selected="selected"> @CreateHtmlLocalizer(item.DisplayText.ResourceName).GetString(item.DisplayText.Name) </option>
} }
else else
{ {
<option value="@item.Value"> @L.GetString(item.DisplayText.Name) </option> <option value="@item.Value"> @CreateHtmlLocalizer(item.DisplayText.ResourceName).GetString(item.DisplayText.Name) </option>
} }
} }
</select> </select>

1
modules/identity/src/Volo.Abp.Identity.Domain.Shared/Volo.Abp.Identity.Domain.Shared.csproj

@ -23,6 +23,7 @@
<ItemGroup> <ItemGroup>
<ProjectReference Include="..\..\..\users\src\Volo.Abp.Users.Domain.Shared\Volo.Abp.Users.Domain.Shared.csproj" /> <ProjectReference Include="..\..\..\users\src\Volo.Abp.Users.Domain.Shared\Volo.Abp.Users.Domain.Shared.csproj" />
<ProjectReference Include="..\..\..\..\framework\src\Volo.Abp.Validation\Volo.Abp.Validation.csproj" /> <ProjectReference Include="..\..\..\..\framework\src\Volo.Abp.Validation\Volo.Abp.Validation.csproj" />
<ProjectReference Include="..\..\..\..\framework\src\Volo.Abp.Features\Volo.Abp.Features.csproj" />
</ItemGroup> </ItemGroup>
<ItemGroup> <ItemGroup>

6
modules/identity/src/Volo.Abp.Identity.Domain.Shared/Volo/Abp/Identity/AbpIdentityDomainSharedModule.cs

@ -1,4 +1,5 @@
using Volo.Abp.Identity.Localization; using Volo.Abp.Features;
using Volo.Abp.Identity.Localization;
using Volo.Abp.Localization; using Volo.Abp.Localization;
using Volo.Abp.Localization.ExceptionHandling; using Volo.Abp.Localization.ExceptionHandling;
using Volo.Abp.Modularity; using Volo.Abp.Modularity;
@ -11,7 +12,8 @@ namespace Volo.Abp.Identity
{ {
[DependsOn( [DependsOn(
typeof(AbpUsersDomainSharedModule), typeof(AbpUsersDomainSharedModule),
typeof(AbpValidationModule) typeof(AbpValidationModule),
typeof(AbpFeaturesModule)
)] )]
public class AbpIdentityDomainSharedModule : AbpModule public class AbpIdentityDomainSharedModule : AbpModule
{ {

9
modules/identity/src/Volo.Abp.Identity.Domain.Shared/Volo/Abp/Identity/Features/IdentityFeature.cs

@ -0,0 +1,9 @@
namespace Volo.Abp.Identity.Features
{
public class IdentityFeature
{
public const string GroupName = "Identity";
public const string TwoFactor = GroupName + ".TwoFactor";
}
}

23
modules/identity/src/Volo.Abp.Identity.Domain.Shared/Volo/Abp/Identity/Features/IdentityFeatureCheckerExtensions.cs

@ -0,0 +1,23 @@
using System;
using System.Threading.Tasks;
using JetBrains.Annotations;
using Volo.Abp.Features;
namespace Volo.Abp.Identity.Features
{
public static class IdentityFeatureCheckerExtensions
{
public static async Task<IdentityTwoFactorBehaviour> GetIdentityTwoFactorBehaviour([NotNull] this IFeatureChecker featureChecker)
{
Check.NotNull(featureChecker, nameof(featureChecker));
var value = await featureChecker.GetOrNullAsync(IdentityFeature.TwoFactor);
if (value.IsNullOrWhiteSpace() || !Enum.TryParse<IdentityTwoFactorBehaviour>(value, out var behaviour))
{
throw new AbpException($"{IdentityFeature.TwoFactor} feature value is invalid");
}
return behaviour;
}
}
}

51
modules/identity/src/Volo.Abp.Identity.Domain.Shared/Volo/Abp/Identity/Features/IdentityFeatureDefinitionProvider.cs

@ -0,0 +1,51 @@
using System;
using Volo.Abp.Features;
using Volo.Abp.Identity.Localization;
using Volo.Abp.Localization;
using Volo.Abp.Validation.StringValues;
namespace Volo.Abp.Identity.Features
{
public class IdentityFeatureDefinitionProvider : FeatureDefinitionProvider
{
public override void Define(IFeatureDefinitionContext context)
{
var group = context.AddGroup(IdentityFeature.GroupName, L("Feature:IdentityGroup"));
group.AddFeature(IdentityFeature.TwoFactor,
IdentityTwoFactorBehaviour.Optional.ToString(),
L("Feature:TwoFactor"),
L("Feature:TwoFactorDescription"),
new SelectionStringValueType
{
ItemSource = new StaticSelectionStringValueItemSource(
new LocalizableSelectionStringValueItem
{
Value = IdentityTwoFactorBehaviour.Optional.ToString(),
DisplayText = GetTwoFactorBehaviourLocalizableStringInfo("Feature:TwoFactor.Optional")
},
new LocalizableSelectionStringValueItem
{
Value = IdentityTwoFactorBehaviour.Disabled.ToString(),
DisplayText = GetTwoFactorBehaviourLocalizableStringInfo("Feature:TwoFactor.Disabled")
},
new LocalizableSelectionStringValueItem
{
Value = IdentityTwoFactorBehaviour.Forced.ToString(),
DisplayText = GetTwoFactorBehaviourLocalizableStringInfo("Feature:TwoFactor.Forced")
}
)
});
}
private static LocalizableString L(string name)
{
return LocalizableString.Create<IdentityResource>(name);
}
private static LocalizableStringInfo GetTwoFactorBehaviourLocalizableStringInfo(string key)
{
return new LocalizableStringInfo(LocalizationResourceNameAttribute.GetName(typeof(IdentityResource)), key);
}
}
}

11
modules/identity/src/Volo.Abp.Identity.Domain.Shared/Volo/Abp/Identity/Features/IdentityTwoFactorBehaviour.cs

@ -0,0 +1,11 @@
namespace Volo.Abp.Identity.Features
{
public enum IdentityTwoFactorBehaviour
{
Optional,
Disabled,
Forced
}
}

10
modules/identity/src/Volo.Abp.Identity.Domain.Shared/Volo/Abp/Identity/Localization/en.json

@ -74,6 +74,12 @@
"Permission:ChangePermissions": "Change permissions", "Permission:ChangePermissions": "Change permissions",
"Permission:UserManagement": "User management", "Permission:UserManagement": "User management",
"Permission:UserLookup": "User lookup", "Permission:UserLookup": "User lookup",
"Feature:IdentityGroup": "Identity",
"Feature:TwoFactor": "Two Factor",
"Feature:TwoFactorDescription": "Two Factor",
"Feature:TwoFactor.Optional": "Optional",
"Feature:TwoFactor.Disabled": "Disabled",
"Feature:TwoFactor.Forced": "Forced",
"DisplayName:Abp.Identity.Password.RequiredLength": "Required length", "DisplayName:Abp.Identity.Password.RequiredLength": "Required length",
"DisplayName:Abp.Identity.Password.RequiredUniqueChars": "Required unique characters number", "DisplayName:Abp.Identity.Password.RequiredUniqueChars": "Required unique characters number",
"DisplayName:Abp.Identity.Password.RequireNonAlphanumeric": "Required non-alphanumeric character", "DisplayName:Abp.Identity.Password.RequireNonAlphanumeric": "Required non-alphanumeric character",
@ -102,6 +108,10 @@
"Description:Abp.Identity.SignIn.RequireConfirmedPhoneNumber": "Whether a confirmed telephone number is required to sign in.", "Description:Abp.Identity.SignIn.RequireConfirmedPhoneNumber": "Whether a confirmed telephone number is required to sign in.",
"Description:Abp.Identity.User.IsUserNameUpdateEnabled": "Whether the username can be updated by the user.", "Description:Abp.Identity.User.IsUserNameUpdateEnabled": "Whether the username can be updated by the user.",
"Description:Abp.Identity.User.IsEmailUpdateEnabled": "Whether the email can be updated by the user.", "Description:Abp.Identity.User.IsEmailUpdateEnabled": "Whether the email can be updated by the user.",
"DisplayName:Abp.Identity.TwoFactorBehaviour": "Two Factor behaviour",
"Description:Abp.Identity.TwoFactorBehaviour": "Two Factor behaviour",
"DisplayName:Abp.Identity.UsersCanChange": "Allow users to change their Two Factor.",
"Description:Abp.Identity.UsersCanChange": "Allow users to change their Two Factor.",
"Volo.Abp.Identity:010002": "Can not set more than {MaxUserMembershipCount} organization unit for a user!", "Volo.Abp.Identity:010002": "Can not set more than {MaxUserMembershipCount} organization unit for a user!",
"Volo.Abp.Identity:010003": "Can not change password of an externally logged in user!" "Volo.Abp.Identity:010003": "Can not change password of an externally logged in user!"
} }

11
modules/identity/src/Volo.Abp.Identity.Domain.Shared/Volo/Abp/Identity/Settings/IdentitySettingNames.cs

@ -48,5 +48,14 @@
public const string MaxUserMembershipCount = OrganizationUnitPrefix + ".MaxUserMembershipCount"; public const string MaxUserMembershipCount = OrganizationUnitPrefix + ".MaxUserMembershipCount";
} }
public static class TwoFactor
{
private const string TwoFactorPrefix = Prefix + ".TwoFactor";
public const string Behaviour = TwoFactorPrefix + ".Behaviour";
public const string UsersCanChange = TwoFactorPrefix + ".UsersCanChange";
}
} }
} }

55
modules/identity/src/Volo.Abp.Identity.Domain/Volo/Abp/Identity/AbpIdentitySettingDefinitionProvider.cs

@ -1,4 +1,5 @@
using Volo.Abp.Identity.Localization; using Volo.Abp.Identity.Features;
using Volo.Abp.Identity.Localization;
using Volo.Abp.Identity.Settings; using Volo.Abp.Identity.Settings;
using Volo.Abp.Localization; using Volo.Abp.Localization;
using Volo.Abp.Settings; using Volo.Abp.Settings;
@ -33,85 +34,97 @@ namespace Volo.Abp.Identity
new SettingDefinition( new SettingDefinition(
IdentitySettingNames.Password.RequireLowercase, IdentitySettingNames.Password.RequireLowercase,
true.ToString(), true.ToString(),
L("DisplayName:Abp.Identity.Password.RequireLowercase"), L("DisplayName:Abp.Identity.Password.RequireLowercase"),
L("Description:Abp.Identity.Password.RequireLowercase"), L("Description:Abp.Identity.Password.RequireLowercase"),
true), true),
new SettingDefinition( new SettingDefinition(
IdentitySettingNames.Password.RequireUppercase, IdentitySettingNames.Password.RequireUppercase,
true.ToString(), true.ToString(),
L("DisplayName:Abp.Identity.Password.RequireUppercase"), L("DisplayName:Abp.Identity.Password.RequireUppercase"),
L("Description:Abp.Identity.Password.RequireUppercase"), L("Description:Abp.Identity.Password.RequireUppercase"),
true), true),
new SettingDefinition( new SettingDefinition(
IdentitySettingNames.Password.RequireDigit, IdentitySettingNames.Password.RequireDigit,
true.ToString(), true.ToString(),
L("DisplayName:Abp.Identity.Password.RequireDigit"), L("DisplayName:Abp.Identity.Password.RequireDigit"),
L("Description:Abp.Identity.Password.RequireDigit"), L("Description:Abp.Identity.Password.RequireDigit"),
true), true),
new SettingDefinition( new SettingDefinition(
IdentitySettingNames.Lockout.AllowedForNewUsers, IdentitySettingNames.Lockout.AllowedForNewUsers,
true.ToString(), true.ToString(),
L("DisplayName:Abp.Identity.Lockout.AllowedForNewUsers"), L("DisplayName:Abp.Identity.Lockout.AllowedForNewUsers"),
L("Description:Abp.Identity.Lockout.AllowedForNewUsers"), L("Description:Abp.Identity.Lockout.AllowedForNewUsers"),
true), true),
new SettingDefinition( new SettingDefinition(
IdentitySettingNames.Lockout.LockoutDuration, IdentitySettingNames.Lockout.LockoutDuration,
(5 * 60).ToString(), (5 * 60).ToString(),
L("DisplayName:Abp.Identity.Lockout.LockoutDuration"), L("DisplayName:Abp.Identity.Lockout.LockoutDuration"),
L("Description:Abp.Identity.Lockout.LockoutDuration"), L("Description:Abp.Identity.Lockout.LockoutDuration"),
true), true),
new SettingDefinition( new SettingDefinition(
IdentitySettingNames.Lockout.MaxFailedAccessAttempts, IdentitySettingNames.Lockout.MaxFailedAccessAttempts,
5.ToString(), 5.ToString(),
L("DisplayName:Abp.Identity.Lockout.MaxFailedAccessAttempts"), L("DisplayName:Abp.Identity.Lockout.MaxFailedAccessAttempts"),
L("Description:Abp.Identity.Lockout.MaxFailedAccessAttempts"), L("Description:Abp.Identity.Lockout.MaxFailedAccessAttempts"),
true), true),
new SettingDefinition( new SettingDefinition(
IdentitySettingNames.SignIn.RequireConfirmedEmail, IdentitySettingNames.SignIn.RequireConfirmedEmail,
false.ToString(), false.ToString(),
L("DisplayName:Abp.Identity.SignIn.RequireConfirmedEmail"), L("DisplayName:Abp.Identity.SignIn.RequireConfirmedEmail"),
L("Description:Abp.Identity.SignIn.RequireConfirmedEmail"), L("Description:Abp.Identity.SignIn.RequireConfirmedEmail"),
true), true),
new SettingDefinition( new SettingDefinition(
IdentitySettingNames.SignIn.EnablePhoneNumberConfirmation, IdentitySettingNames.SignIn.EnablePhoneNumberConfirmation,
true.ToString(), true.ToString(),
L("DisplayName:Abp.Identity.SignIn.EnablePhoneNumberConfirmation"), L("DisplayName:Abp.Identity.SignIn.EnablePhoneNumberConfirmation"),
L("Description:Abp.Identity.SignIn.EnablePhoneNumberConfirmation"), L("Description:Abp.Identity.SignIn.EnablePhoneNumberConfirmation"),
true), true),
new SettingDefinition( new SettingDefinition(
IdentitySettingNames.SignIn.RequireConfirmedPhoneNumber, IdentitySettingNames.SignIn.RequireConfirmedPhoneNumber,
false.ToString(), false.ToString(),
L("DisplayName:Abp.Identity.SignIn.RequireConfirmedPhoneNumber"), L("DisplayName:Abp.Identity.SignIn.RequireConfirmedPhoneNumber"),
L("Description:Abp.Identity.SignIn.RequireConfirmedPhoneNumber"), L("Description:Abp.Identity.SignIn.RequireConfirmedPhoneNumber"),
true), true),
new SettingDefinition( new SettingDefinition(
IdentitySettingNames.User.IsUserNameUpdateEnabled, IdentitySettingNames.User.IsUserNameUpdateEnabled,
true.ToString(), true.ToString(),
L("DisplayName:Abp.Identity.User.IsUserNameUpdateEnabled"), L("DisplayName:Abp.Identity.User.IsUserNameUpdateEnabled"),
L("Description:Abp.Identity.User.IsUserNameUpdateEnabled"), L("Description:Abp.Identity.User.IsUserNameUpdateEnabled"),
true), true),
new SettingDefinition( new SettingDefinition(
IdentitySettingNames.User.IsEmailUpdateEnabled, IdentitySettingNames.User.IsEmailUpdateEnabled,
true.ToString(), true.ToString(),
L("DisplayName:Abp.Identity.User.IsEmailUpdateEnabled"), L("DisplayName:Abp.Identity.User.IsEmailUpdateEnabled"),
L("Description:Abp.Identity.User.IsEmailUpdateEnabled"), L("Description:Abp.Identity.User.IsEmailUpdateEnabled"),
true), true),
new SettingDefinition( new SettingDefinition(
IdentitySettingNames.OrganizationUnit.MaxUserMembershipCount, IdentitySettingNames.OrganizationUnit.MaxUserMembershipCount,
int.MaxValue.ToString(), int.MaxValue.ToString(),
L("Identity.OrganizationUnit.MaxUserMembershipCount"), L("Identity.OrganizationUnit.MaxUserMembershipCount"),
L("Identity.OrganizationUnit.MaxUserMembershipCount"), L("Identity.OrganizationUnit.MaxUserMembershipCount"),
true) true),
new SettingDefinition(IdentitySettingNames.TwoFactor.Behaviour,
IdentityTwoFactorBehaviour.Optional.ToString(),
L("DisplayName:Abp.Identity.TwoFactorBehaviour"),
L("Description:Abp.Identity.TwoFactorBehaviour"),
isVisibleToClients: true),
new SettingDefinition(IdentitySettingNames.TwoFactor.UsersCanChange,
true.ToString(),
L("DisplayName:Abp.Identity.UsersCanChange"),
L("Description:Abp.Identity.UsersCanChange"),
isVisibleToClients: true)
); );
} }

25
modules/identity/src/Volo.Abp.Identity.Domain/Volo/Abp/Identity/IdentitySettingProviderExtensions.cs

@ -0,0 +1,25 @@
using System;
using System.Threading.Tasks;
using JetBrains.Annotations;
using Volo.Abp.Identity.Features;
using Volo.Abp.Identity.Settings;
using Volo.Abp.Settings;
namespace Volo.Abp.Identity
{
public static class IdentitySettingProviderExtensions
{
public static async Task<IdentityTwoFactorBehaviour> GetIdentityTwoFactorBehaviour([NotNull] this ISettingProvider settingProvider)
{
Check.NotNull(settingProvider, nameof(settingProvider));
var value = await settingProvider.GetOrNullAsync(IdentitySettingNames.TwoFactor.Behaviour);
if (value.IsNullOrWhiteSpace() || !Enum.TryParse<IdentityTwoFactorBehaviour>(value, out var behaviour))
{
throw new AbpException($"{IdentitySettingNames.TwoFactor.Behaviour} setting value is invalid");
}
return behaviour;
}
}
}

69
modules/identity/src/Volo.Abp.Identity.Domain/Volo/Abp/Identity/IdentityTwoFactorManager.cs

@ -0,0 +1,69 @@
using System.Threading.Tasks;
using Volo.Abp.Domain.Services;
using Volo.Abp.Features;
using Volo.Abp.Identity.Features;
using Volo.Abp.Settings;
namespace Volo.Abp.Identity
{
public class IdentityTwoFactorManager : IDomainService
{
protected IFeatureChecker FeatureChecker { get; }
protected ISettingProvider SettingProvider { get; }
public IdentityTwoFactorManager(IFeatureChecker featureChecker, ISettingProvider settingProvider)
{
FeatureChecker = featureChecker;
SettingProvider = settingProvider;
}
public virtual async Task<bool> IsOptionalAsync()
{
var feature = await FeatureChecker.GetIdentityTwoFactorBehaviour();
if (feature == IdentityTwoFactorBehaviour.Optional)
{
var setting = await SettingProvider.GetIdentityTwoFactorBehaviour();
if (setting == IdentityTwoFactorBehaviour.Optional)
{
return true;
}
}
return false;
}
public virtual async Task<bool> IsForcedEnableAsync()
{
var feature = await FeatureChecker.GetIdentityTwoFactorBehaviour();
if (feature == IdentityTwoFactorBehaviour.Forced)
{
return true;
}
var setting = await SettingProvider.GetIdentityTwoFactorBehaviour();
if (setting == IdentityTwoFactorBehaviour.Forced)
{
return true;
}
return false;
}
public virtual async Task<bool> IsForcedDisableAsync()
{
var feature = await FeatureChecker.GetIdentityTwoFactorBehaviour();
if (feature == IdentityTwoFactorBehaviour.Disabled)
{
return true;
}
var setting = await SettingProvider.GetIdentityTwoFactorBehaviour();
if (setting == IdentityTwoFactorBehaviour.Disabled)
{
return true;
}
return false;
}
}
}

34
modules/identity/src/Volo.Abp.Identity.Domain/Volo/Abp/Identity/IdentityUserStore.cs

@ -11,7 +11,10 @@ using Microsoft.Extensions.Logging;
using Volo.Abp.Data; using Volo.Abp.Data;
using Volo.Abp.DependencyInjection; using Volo.Abp.DependencyInjection;
using Volo.Abp.Domain.Repositories; using Volo.Abp.Domain.Repositories;
using Volo.Abp.Features;
using Volo.Abp.Guids; using Volo.Abp.Guids;
using Volo.Abp.Identity.Features;
using Volo.Abp.Settings;
namespace Volo.Abp.Identity namespace Volo.Abp.Identity
{ {
@ -56,12 +59,17 @@ namespace Volo.Abp.Identity
protected ILookupNormalizer LookupNormalizer { get; } protected ILookupNormalizer LookupNormalizer { get; }
protected IIdentityUserRepository UserRepository { get; } protected IIdentityUserRepository UserRepository { get; }
protected IFeatureChecker FeatureChecker { get; }
protected ISettingProvider SettingProvider { get; }
public IdentityUserStore( public IdentityUserStore(
IIdentityUserRepository userRepository, IIdentityUserRepository userRepository,
IIdentityRoleRepository roleRepository, IIdentityRoleRepository roleRepository,
IGuidGenerator guidGenerator, IGuidGenerator guidGenerator,
ILogger<IdentityRoleStore> logger, ILogger<IdentityRoleStore> logger,
ILookupNormalizer lookupNormalizer, ILookupNormalizer lookupNormalizer,
IFeatureChecker featureChecker,
ISettingProvider settingProvider,
IdentityErrorDescriber describer = null) IdentityErrorDescriber describer = null)
{ {
UserRepository = userRepository; UserRepository = userRepository;
@ -69,6 +77,8 @@ namespace Volo.Abp.Identity
GuidGenerator = guidGenerator; GuidGenerator = guidGenerator;
Logger = logger; Logger = logger;
LookupNormalizer = lookupNormalizer; LookupNormalizer = lookupNormalizer;
FeatureChecker = featureChecker;
SettingProvider = settingProvider;
ErrorDescriber = describer ?? new IdentityErrorDescriber(); ErrorDescriber = describer ?? new IdentityErrorDescriber();
} }
@ -931,13 +941,33 @@ namespace Volo.Abp.Identity
/// The <see cref="Task"/> that represents the asynchronous operation, containing a flag indicating whether the specified /// The <see cref="Task"/> that represents the asynchronous operation, containing a flag indicating whether the specified
/// <paramref name="user"/> has two factor authentication enabled or not. /// <paramref name="user"/> has two factor authentication enabled or not.
/// </returns> /// </returns>
public virtual Task<bool> GetTwoFactorEnabledAsync([NotNull] IdentityUser user, CancellationToken cancellationToken = default) public virtual async Task<bool> GetTwoFactorEnabledAsync([NotNull] IdentityUser user, CancellationToken cancellationToken = default)
{ {
cancellationToken.ThrowIfCancellationRequested(); cancellationToken.ThrowIfCancellationRequested();
Check.NotNull(user, nameof(user)); Check.NotNull(user, nameof(user));
return Task.FromResult(user.TwoFactorEnabled); var feature = await FeatureChecker.GetIdentityTwoFactorBehaviour();
if (feature == IdentityTwoFactorBehaviour.Disabled)
{
return false;
}
if (feature == IdentityTwoFactorBehaviour.Forced)
{
return true;
}
var setting = await SettingProvider.GetIdentityTwoFactorBehaviour();
if (setting == IdentityTwoFactorBehaviour.Disabled)
{
return false;
}
if (setting == IdentityTwoFactorBehaviour.Forced)
{
return true;
}
return user.TwoFactorEnabled;
} }
/// <summary> /// <summary>

Loading…
Cancel
Save