mirror of https://github.com/abpframework/abp.git
7 changed files with 55 additions and 71 deletions
@ -1,19 +0,0 @@ |
|||||
using System.Collections.Generic; |
|
||||
using Volo.Abp.Domain.Entities; |
|
||||
|
|
||||
namespace Volo.Abp.Authorization.Permissions.Resources; |
|
||||
|
|
||||
public static class EntityExtensions |
|
||||
{ |
|
||||
public static string GetResourceName(this IEntity entity) |
|
||||
{ |
|
||||
Check.NotNull(entity, nameof(entity)); |
|
||||
return entity.GetType().FullName!; |
|
||||
} |
|
||||
|
|
||||
public static string GetResourceKey(this IEntity entity) |
|
||||
{ |
|
||||
Check.NotNull(entity, nameof(entity)); |
|
||||
return entity.GetKeys().JoinAsString(","); |
|
||||
} |
|
||||
} |
|
||||
@ -1,30 +0,0 @@ |
|||||
using System.Threading.Tasks; |
|
||||
using Microsoft.AspNetCore.Authorization; |
|
||||
using Volo.Abp.Domain.Entities; |
|
||||
|
|
||||
namespace Volo.Abp.Authorization.Permissions.Resources; |
|
||||
|
|
||||
public class EntityResourcePermissionRequirementHandler : AuthorizationHandler<ResourcePermissionRequirement, IEntity> |
|
||||
{ |
|
||||
protected readonly IResourcePermissionChecker PermissionChecker; |
|
||||
|
|
||||
public EntityResourcePermissionRequirementHandler(IResourcePermissionChecker permissionChecker) |
|
||||
{ |
|
||||
PermissionChecker = permissionChecker; |
|
||||
} |
|
||||
|
|
||||
protected override async Task HandleRequirementAsync(AuthorizationHandlerContext context, ResourcePermissionRequirement requirement, IEntity? resource) |
|
||||
{ |
|
||||
if (resource == null) |
|
||||
{ |
|
||||
return; |
|
||||
} |
|
||||
|
|
||||
var resourceName = resource.GetResourceName(); |
|
||||
var resourceKey = resource.GetResourceKey(); |
|
||||
if (await PermissionChecker.IsGrantedAsync(context.User, requirement.PermissionName, resourceName, resourceKey)) |
|
||||
{ |
|
||||
context.Succeed(requirement); |
|
||||
} |
|
||||
} |
|
||||
} |
|
||||
@ -1,29 +1,28 @@ |
|||||
using System.Threading.Tasks; |
using System.Threading.Tasks; |
||||
using Volo.Abp.Domain.Entities; |
|
||||
|
|
||||
namespace Volo.Abp.Authorization.Permissions.Resources; |
namespace Volo.Abp.Authorization.Permissions.Resources; |
||||
|
|
||||
public static class EntityResourcePermissionCheckerExtensions |
public static class KeyedObjectResourcePermissionCheckerExtensions |
||||
{ |
{ |
||||
/// <summary>
|
/// <summary>
|
||||
/// Checks if the specified permission is granted for the given entity.
|
/// Checks if the specified permission is granted for the given resource.
|
||||
/// </summary>
|
/// </summary>
|
||||
/// <typeparam name="TEntity">The type of the entity.</typeparam>
|
/// <typeparam name="TResource">The type of the object.</typeparam>
|
||||
/// <param name="resourcePermissionChecker">The resource permission checker instance.</param>
|
/// <param name="resourcePermissionChecker">The resource permission checker instance.</param>
|
||||
/// <param name="permissionName">The name of the permission to check.</param>
|
/// <param name="permissionName">The name of the permission to check.</param>
|
||||
/// <param name="entity">The entity for which the permission is being checked.</param>
|
/// <param name="resource">The resource for which the permission is being checked.</param>
|
||||
/// <returns>A task that represents the asynchronous operation. The task result is a boolean indicating whether the permission is granted.</returns>
|
/// <returns>A task that represents the asynchronous operation. The task result is a boolean indicating whether the permission is granted.</returns>
|
||||
public static Task<bool> IsGrantedAsync<TEntity>(this IResourcePermissionChecker resourcePermissionChecker, string permissionName, TEntity entity) |
public static Task<bool> IsGrantedAsync<TResource>(this IResourcePermissionChecker resourcePermissionChecker, string permissionName, TResource resource) |
||||
where TEntity : class, IEntity |
where TResource : class, IKeyedObject |
||||
{ |
{ |
||||
Check.NotNull(resourcePermissionChecker, nameof(resourcePermissionChecker)); |
Check.NotNull(resourcePermissionChecker, nameof(resourcePermissionChecker)); |
||||
Check.NotNullOrWhiteSpace(permissionName, nameof(permissionName)); |
Check.NotNullOrWhiteSpace(permissionName, nameof(permissionName)); |
||||
Check.NotNull(entity, nameof(entity)); |
Check.NotNull(resource, nameof(resource)); |
||||
|
|
||||
return resourcePermissionChecker.IsGrantedAsync( |
return resourcePermissionChecker.IsGrantedAsync( |
||||
permissionName, |
permissionName, |
||||
entity, |
resource, |
||||
entity.GetResourceKey() |
resource.GetObjectKey() ?? throw new AbpException("The resource doesn't have a key.") |
||||
); |
); |
||||
} |
} |
||||
} |
} |
||||
@ -0,0 +1,34 @@ |
|||||
|
using System.Threading.Tasks; |
||||
|
using Microsoft.AspNetCore.Authorization; |
||||
|
|
||||
|
namespace Volo.Abp.Authorization.Permissions.Resources; |
||||
|
|
||||
|
public class KeyedObjectResourcePermissionRequirementHandler : AuthorizationHandler<ResourcePermissionRequirement, IKeyedObject> |
||||
|
{ |
||||
|
protected readonly IResourcePermissionChecker PermissionChecker; |
||||
|
|
||||
|
public KeyedObjectResourcePermissionRequirementHandler( |
||||
|
IResourcePermissionChecker permissionChecker) |
||||
|
{ |
||||
|
PermissionChecker = permissionChecker; |
||||
|
} |
||||
|
|
||||
|
protected override async Task HandleRequirementAsync( |
||||
|
AuthorizationHandlerContext context, |
||||
|
ResourcePermissionRequirement requirement, |
||||
|
IKeyedObject? resource) |
||||
|
{ |
||||
|
if (resource == null) |
||||
|
{ |
||||
|
return; |
||||
|
} |
||||
|
|
||||
|
var resourceName = resource.GetType().FullName!; |
||||
|
var resourceKey = resource.GetObjectKey() ?? throw new AbpException("The resource doesn't have a key."); |
||||
|
|
||||
|
if (await PermissionChecker.IsGrantedAsync(context.User, requirement.PermissionName, resourceName, resourceKey)) |
||||
|
{ |
||||
|
context.Succeed(requirement); |
||||
|
} |
||||
|
} |
||||
|
} |
||||
Loading…
Reference in new issue