Browse Source

authorize check with combine

pull/2659/head
mperk 7 years ago
parent
commit
85f956f5ae
  1. 29
      framework/src/Volo.Abp.Authorization/Volo/Abp/Authorization/MethodInvocationAuthorizationService.cs
  2. 16
      framework/test/Volo.Abp.Authorization.Tests/Volo/Abp/Authorization/Authorization_Tests.cs
  3. 2
      framework/test/Volo.Abp.Authorization.Tests/Volo/Abp/Authorization/TestServices/IMyAuthorizedService1.cs
  4. 7
      framework/test/Volo.Abp.Authorization.Tests/Volo/Abp/Authorization/TestServices/MyAuthorizedService1.cs

29
framework/src/Volo.Abp.Authorization/Volo/Abp/Authorization/MethodInvocationAuthorizationService.cs

@ -14,15 +14,18 @@ namespace Volo.Abp.Authorization
private readonly IAuthorizationService _authorizationService;
private readonly ICurrentUser _currentUser;
private readonly ICurrentClient _currentClient;
private readonly IAbpAuthorizationPolicyProvider _abpAuthorizationPolicyProvider;
public MethodInvocationAuthorizationService(
IAuthorizationService authorizationService,
ICurrentUser currentUser,
ICurrentClient currentClient)
ICurrentClient currentClient,
IAbpAuthorizationPolicyProvider abpAuthorizationPolicyProvider)
{
_authorizationService = authorizationService;
_currentUser = currentUser;
_currentClient = currentClient;
_abpAuthorizationPolicyProvider = abpAuthorizationPolicyProvider;
}
public async Task CheckAsync(MethodInvocationAuthorizationContext context)
@ -64,26 +67,10 @@ namespace Volo.Abp.Authorization
protected async Task CheckAsync(IAuthorizeData authorizationAttribute)
{
if (authorizationAttribute.Policy != null)
{
await _authorizationService.CheckAsync(authorizationAttribute.Policy).ConfigureAwait(false);
}
else if (authorizationAttribute.Roles != null)
{
if(_currentUser.IsInRole(authorizationAttribute.Roles) == false)
{
throw new AbpAuthorizationException("Authorization failed! Given roles has not granted: " + authorizationAttribute.Roles);
}
}
else
{
//TODO: Can we find a better, unified, way of checking if current request has been authenticated
if (!_currentUser.IsAuthenticated && !_currentClient.IsAuthenticated)
{
throw new AbpAuthorizationException("Authorization failed! User has not logged in.");
}
}
var authorizationPolicy = await AuthorizationPolicy.CombineAsync(
_abpAuthorizationPolicyProvider,
new List<IAuthorizeData> { authorizationAttribute });
await _authorizationService.CheckAsync(authorizationPolicy).ConfigureAwait(false);
}
}
}

16
framework/test/Volo.Abp.Authorization.Tests/Volo/Abp/Authorization/Authorization_Tests.cs

@ -61,5 +61,21 @@ namespace Volo.Abp.Authorization
await _myAuthorizedService1.ProtectedByRole().ConfigureAwait(false);
}).ConfigureAwait(false);
}
[Fact]
public async Task Should_Allow_To_Call_Method_If_Has_No_Role_ProtectedByRole_Async()
{
int result = await _myAuthorizedService1.ProtectedByRole().ConfigureAwait(false);
result.ShouldBe(42);
}
[Fact]
public async Task Should_Not_Allow_To_Call_Method_If_Has_No_Role_ProtectedByScheme_Async()
{
await Assert.ThrowsAsync<AbpAuthorizationException>(async () =>
{
await _myAuthorizedService1.ProtectedByScheme().ConfigureAwait(false);
}).ConfigureAwait(false);
}
}
}

2
framework/test/Volo.Abp.Authorization.Tests/Volo/Abp/Authorization/TestServices/IMyAuthorizedService1.cs

@ -13,5 +13,7 @@ namespace Volo.Abp.Authorization.TestServices
Task<int> ProtectedByClassAsync();
Task<int> ProtectedByRole();
Task<int> ProtectedByScheme();
}
}

7
framework/test/Volo.Abp.Authorization.Tests/Volo/Abp/Authorization/TestServices/MyAuthorizedService1.cs

@ -36,5 +36,12 @@ namespace Volo.Abp.Authorization.TestServices
{
return Task.FromResult(42);
}
[Authorize(AuthenticationSchemes = "Bearer")]
[Authorize(Roles = "MyRole")]
public virtual Task<int> ProtectedByScheme()
{
return Task.FromResult(42);
}
}
}
Loading…
Cancel
Save