Browse Source

Throw an exception if there is no scheme found.

pull/9940/head
maliming 5 years ago
parent
commit
a4108ec532
  1. 54
      framework/src/Volo.Abp.AspNetCore/Volo/Abp/AspNetCore/ExceptionHandling/DefaultAbpAuthorizationExceptionHandler.cs

54
framework/src/Volo.Abp.AspNetCore/Volo/Abp/AspNetCore/ExceptionHandling/DefaultAbpAuthorizationExceptionHandler.cs

@ -18,30 +18,54 @@ namespace Volo.Abp.AspNetCore.ExceptionHandling
{
var isAuthenticated = httpContext.User.Identity?.IsAuthenticated ?? false;
var authenticationSchemeProvider = httpContext.RequestServices.GetRequiredService<IAuthenticationSchemeProvider>();
var scheme = !handlerOptions.AuthenticationScheme.IsNullOrWhiteSpace()
? await authenticationSchemeProvider.GetSchemeAsync(handlerOptions.AuthenticationScheme)
: isAuthenticated
? await authenticationSchemeProvider.GetDefaultForbidSchemeAsync()
: await authenticationSchemeProvider.GetDefaultChallengeSchemeAsync();
if (scheme != null)
AuthenticationScheme scheme = null;
if (!handlerOptions.AuthenticationScheme.IsNullOrWhiteSpace())
{
scheme = await authenticationSchemeProvider.GetSchemeAsync(handlerOptions.AuthenticationScheme);
if (scheme == null)
{
throw new AbpException($"No authentication scheme named {handlerOptions.AuthenticationScheme} was found.");
}
}
else
{
var handlers = httpContext.RequestServices.GetRequiredService<IAuthenticationHandlerProvider>();
var handler = await handlers.GetHandlerAsync(httpContext, scheme.Name);
if (handler != null)
if (isAuthenticated)
{
if (isAuthenticated)
scheme = await authenticationSchemeProvider.GetDefaultForbidSchemeAsync();
if (scheme == null)
{
await handler.ForbidAsync(null);
throw new AbpException($"There was no DefaultForbidScheme found.");
}
else
}
else
{
scheme = await authenticationSchemeProvider.GetDefaultChallengeSchemeAsync();
if (scheme == null)
{
await handler.ChallengeAsync(null);
throw new AbpException($"There was no DefaultChallengeScheme found.");
}
return true;
}
}
var handlers = httpContext.RequestServices.GetRequiredService<IAuthenticationHandlerProvider>();
var handler = await handlers.GetHandlerAsync(httpContext, scheme.Name);
if (handler == null)
{
throw new AbpException($"No handler of {scheme.Name} was found.");
}
if (isAuthenticated)
{
await handler.ForbidAsync(null);
}
else
{
await handler.ChallengeAsync(null);
}
return true;
}
return false;

Loading…
Cancel
Save