From 321918efaac21b87d0040daa567eaba25b4e9b25 Mon Sep 17 00:00:00 2001 From: maliming Date: Thu, 22 Aug 2024 17:17:09 +0800 Subject: [PATCH 1/2] Set `IAuthenticateResultFeature` and `IHttpAuthenticationFeature` after getting dynamic claims. --- .../Claims/AbpDynamicClaimsMiddleware.cs | 17 +++++++++++++++-- 1 file changed, 15 insertions(+), 2 deletions(-) diff --git a/framework/src/Volo.Abp.AspNetCore/Volo/Abp/AspNetCore/Security/Claims/AbpDynamicClaimsMiddleware.cs b/framework/src/Volo.Abp.AspNetCore/Volo/Abp/AspNetCore/Security/Claims/AbpDynamicClaimsMiddleware.cs index d2c328f2ae..a502f2f886 100644 --- a/framework/src/Volo.Abp.AspNetCore/Volo/Abp/AspNetCore/Security/Claims/AbpDynamicClaimsMiddleware.cs +++ b/framework/src/Volo.Abp.AspNetCore/Volo/Abp/AspNetCore/Security/Claims/AbpDynamicClaimsMiddleware.cs @@ -2,6 +2,7 @@ using System; using System.Threading.Tasks; using Microsoft.AspNetCore.Authentication; using Microsoft.AspNetCore.Http; +using Microsoft.AspNetCore.Http.Features.Authentication; using Microsoft.Extensions.DependencyInjection; using Microsoft.Extensions.Options; using Volo.Abp.AspNetCore.Middleware; @@ -18,9 +19,21 @@ public class AbpDynamicClaimsMiddleware : AbpMiddlewareBase, ITransientDependenc { if (context.RequestServices.GetRequiredService>().Value.IsDynamicClaimsEnabled) { - var authenticationType = context.User.Identity.AuthenticationType; + var authenticateResultFeature = context.Features.Get(); + var authenticationType = authenticateResultFeature?.AuthenticateResult?.Ticket?.AuthenticationScheme ?? context.User.Identity.AuthenticationType; + var abpClaimsPrincipalFactory = context.RequestServices.GetRequiredService(); - context.User = await abpClaimsPrincipalFactory.CreateDynamicAsync(context.User); + var user = await abpClaimsPrincipalFactory.CreateDynamicAsync(context.User); + + if (authenticateResultFeature != null && !authenticationType.IsNullOrWhiteSpace()) + { + authenticateResultFeature.AuthenticateResult = AuthenticateResult.Success(new AuthenticationTicket(user, authenticationType)); + var httpAuthenticationFeature = context.Features.Get(); + if (httpAuthenticationFeature != null) + { + httpAuthenticationFeature.User = authenticateResultFeature.AuthenticateResult.Principal; + } + } if (context.User.Identity?.IsAuthenticated == false) { From 390162505b7335c069b4b6216748577c2fa61179 Mon Sep 17 00:00:00 2001 From: EngincanV Date: Mon, 26 Aug 2024 16:31:34 +0300 Subject: [PATCH 2/2] Update AbpDynamicClaimsMiddleware.cs --- .../Security/Claims/AbpDynamicClaimsMiddleware.cs | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/framework/src/Volo.Abp.AspNetCore/Volo/Abp/AspNetCore/Security/Claims/AbpDynamicClaimsMiddleware.cs b/framework/src/Volo.Abp.AspNetCore/Volo/Abp/AspNetCore/Security/Claims/AbpDynamicClaimsMiddleware.cs index a502f2f886..b2bbb78e7b 100644 --- a/framework/src/Volo.Abp.AspNetCore/Volo/Abp/AspNetCore/Security/Claims/AbpDynamicClaimsMiddleware.cs +++ b/framework/src/Volo.Abp.AspNetCore/Volo/Abp/AspNetCore/Security/Claims/AbpDynamicClaimsMiddleware.cs @@ -22,11 +22,11 @@ public class AbpDynamicClaimsMiddleware : AbpMiddlewareBase, ITransientDependenc var authenticateResultFeature = context.Features.Get(); var authenticationType = authenticateResultFeature?.AuthenticateResult?.Ticket?.AuthenticationScheme ?? context.User.Identity.AuthenticationType; - var abpClaimsPrincipalFactory = context.RequestServices.GetRequiredService(); - var user = await abpClaimsPrincipalFactory.CreateDynamicAsync(context.User); - if (authenticateResultFeature != null && !authenticationType.IsNullOrWhiteSpace()) { + var abpClaimsPrincipalFactory = context.RequestServices.GetRequiredService(); + var user = await abpClaimsPrincipalFactory.CreateDynamicAsync(context.User); + authenticateResultFeature.AuthenticateResult = AuthenticateResult.Success(new AuthenticationTicket(user, authenticationType)); var httpAuthenticationFeature = context.Features.Get(); if (httpAuthenticationFeature != null)