From 85f956f5aed8b50f5949fcd9ac325607f8a23d4d Mon Sep 17 00:00:00 2001 From: mperk Date: Sun, 19 Jan 2020 01:03:21 +0300 Subject: [PATCH] authorize check with combine --- .../MethodInvocationAuthorizationService.cs | 29 +++++-------------- .../Abp/Authorization/Authorization_Tests.cs | 16 ++++++++++ .../TestServices/IMyAuthorizedService1.cs | 2 ++ .../TestServices/MyAuthorizedService1.cs | 7 +++++ 4 files changed, 33 insertions(+), 21 deletions(-) diff --git a/framework/src/Volo.Abp.Authorization/Volo/Abp/Authorization/MethodInvocationAuthorizationService.cs b/framework/src/Volo.Abp.Authorization/Volo/Abp/Authorization/MethodInvocationAuthorizationService.cs index 82a0f9c2d1..b2e06c0207 100644 --- a/framework/src/Volo.Abp.Authorization/Volo/Abp/Authorization/MethodInvocationAuthorizationService.cs +++ b/framework/src/Volo.Abp.Authorization/Volo/Abp/Authorization/MethodInvocationAuthorizationService.cs @@ -14,15 +14,18 @@ namespace Volo.Abp.Authorization private readonly IAuthorizationService _authorizationService; private readonly ICurrentUser _currentUser; private readonly ICurrentClient _currentClient; + private readonly IAbpAuthorizationPolicyProvider _abpAuthorizationPolicyProvider; public MethodInvocationAuthorizationService( IAuthorizationService authorizationService, ICurrentUser currentUser, - ICurrentClient currentClient) + ICurrentClient currentClient, + IAbpAuthorizationPolicyProvider abpAuthorizationPolicyProvider) { _authorizationService = authorizationService; _currentUser = currentUser; _currentClient = currentClient; + _abpAuthorizationPolicyProvider = abpAuthorizationPolicyProvider; } public async Task CheckAsync(MethodInvocationAuthorizationContext context) @@ -64,26 +67,10 @@ namespace Volo.Abp.Authorization protected async Task CheckAsync(IAuthorizeData authorizationAttribute) { - if (authorizationAttribute.Policy != null) - { - await _authorizationService.CheckAsync(authorizationAttribute.Policy).ConfigureAwait(false); - } - else if (authorizationAttribute.Roles != null) - { - if(_currentUser.IsInRole(authorizationAttribute.Roles) == false) - { - throw new AbpAuthorizationException("Authorization failed! Given roles has not granted: " + authorizationAttribute.Roles); - } - } - else - { - //TODO: Can we find a better, unified, way of checking if current request has been authenticated - if (!_currentUser.IsAuthenticated && !_currentClient.IsAuthenticated) - { - throw new AbpAuthorizationException("Authorization failed! User has not logged in."); - } - } - + var authorizationPolicy = await AuthorizationPolicy.CombineAsync( + _abpAuthorizationPolicyProvider, + new List { authorizationAttribute }); + await _authorizationService.CheckAsync(authorizationPolicy).ConfigureAwait(false); } } } \ No newline at end of file diff --git a/framework/test/Volo.Abp.Authorization.Tests/Volo/Abp/Authorization/Authorization_Tests.cs b/framework/test/Volo.Abp.Authorization.Tests/Volo/Abp/Authorization/Authorization_Tests.cs index 3968d1baf5..827f7b676e 100644 --- a/framework/test/Volo.Abp.Authorization.Tests/Volo/Abp/Authorization/Authorization_Tests.cs +++ b/framework/test/Volo.Abp.Authorization.Tests/Volo/Abp/Authorization/Authorization_Tests.cs @@ -61,5 +61,21 @@ namespace Volo.Abp.Authorization await _myAuthorizedService1.ProtectedByRole().ConfigureAwait(false); }).ConfigureAwait(false); } + + [Fact] + public async Task Should_Allow_To_Call_Method_If_Has_No_Role_ProtectedByRole_Async() + { + int result = await _myAuthorizedService1.ProtectedByRole().ConfigureAwait(false); + result.ShouldBe(42); + } + + [Fact] + public async Task Should_Not_Allow_To_Call_Method_If_Has_No_Role_ProtectedByScheme_Async() + { + await Assert.ThrowsAsync(async () => + { + await _myAuthorizedService1.ProtectedByScheme().ConfigureAwait(false); + }).ConfigureAwait(false); + } } } \ No newline at end of file diff --git a/framework/test/Volo.Abp.Authorization.Tests/Volo/Abp/Authorization/TestServices/IMyAuthorizedService1.cs b/framework/test/Volo.Abp.Authorization.Tests/Volo/Abp/Authorization/TestServices/IMyAuthorizedService1.cs index 077934c0d2..6c4042168c 100644 --- a/framework/test/Volo.Abp.Authorization.Tests/Volo/Abp/Authorization/TestServices/IMyAuthorizedService1.cs +++ b/framework/test/Volo.Abp.Authorization.Tests/Volo/Abp/Authorization/TestServices/IMyAuthorizedService1.cs @@ -13,5 +13,7 @@ namespace Volo.Abp.Authorization.TestServices Task ProtectedByClassAsync(); Task ProtectedByRole(); + + Task ProtectedByScheme(); } } \ No newline at end of file diff --git a/framework/test/Volo.Abp.Authorization.Tests/Volo/Abp/Authorization/TestServices/MyAuthorizedService1.cs b/framework/test/Volo.Abp.Authorization.Tests/Volo/Abp/Authorization/TestServices/MyAuthorizedService1.cs index 07ccfa7deb..a25227babf 100644 --- a/framework/test/Volo.Abp.Authorization.Tests/Volo/Abp/Authorization/TestServices/MyAuthorizedService1.cs +++ b/framework/test/Volo.Abp.Authorization.Tests/Volo/Abp/Authorization/TestServices/MyAuthorizedService1.cs @@ -36,5 +36,12 @@ namespace Volo.Abp.Authorization.TestServices { return Task.FromResult(42); } + + [Authorize(AuthenticationSchemes = "Bearer")] + [Authorize(Roles = "MyRole")] + public virtual Task ProtectedByScheme() + { + return Task.FromResult(42); + } } } \ No newline at end of file