mirror of https://github.com/abpframework/abp.git
committed by
GitHub
5 changed files with 101 additions and 2 deletions
@ -0,0 +1,47 @@ |
|||||
|
using System; |
||||
|
using System.Threading.Tasks; |
||||
|
using IdentityServer4.Configuration; |
||||
|
using Microsoft.Extensions.Options; |
||||
|
using Volo.Abp.Caching; |
||||
|
using Volo.Abp.DependencyInjection; |
||||
|
using Volo.Abp.Text.Formatting; |
||||
|
|
||||
|
namespace Volo.Abp.IdentityServer |
||||
|
{ |
||||
|
public class AbpWildcardSubdomainCorsPolicyService : AbpCorsPolicyService |
||||
|
{ |
||||
|
public AbpWildcardSubdomainCorsPolicyService( |
||||
|
IDistributedCache<AllowedCorsOriginsCacheItem> cache, |
||||
|
IHybridServiceScopeFactory hybridServiceScopeFactory, |
||||
|
IOptions<IdentityServerOptions> options) |
||||
|
: base(cache, hybridServiceScopeFactory, options) |
||||
|
{ |
||||
|
|
||||
|
} |
||||
|
|
||||
|
protected override async Task<bool> IsOriginAllowedAsync(string[] allowedOrigins, string origin) |
||||
|
{ |
||||
|
var isAllowed = await base.IsOriginAllowedAsync(allowedOrigins, origin); |
||||
|
if (isAllowed) |
||||
|
{ |
||||
|
return true; |
||||
|
} |
||||
|
|
||||
|
foreach (var url in allowedOrigins) |
||||
|
{ |
||||
|
var extractResult = FormattedStringValueExtracter.Extract(origin, url, ignoreCase: true); |
||||
|
if (extractResult.IsMatch) |
||||
|
{ |
||||
|
return true; |
||||
|
} |
||||
|
|
||||
|
if (url.Replace("{0}.", "").Contains(origin, StringComparison.OrdinalIgnoreCase)) |
||||
|
{ |
||||
|
return true; |
||||
|
} |
||||
|
} |
||||
|
|
||||
|
return false; |
||||
|
} |
||||
|
} |
||||
|
} |
||||
@ -0,0 +1,40 @@ |
|||||
|
using System.Threading.Tasks; |
||||
|
using IdentityServer4.Services; |
||||
|
using Microsoft.Extensions.DependencyInjection; |
||||
|
using Shouldly; |
||||
|
using Xunit; |
||||
|
|
||||
|
namespace Volo.Abp.IdentityServer |
||||
|
{ |
||||
|
public class AbpWildcardSubdomainCorsPolicyService_Tests : AbpIdentityServerTestBase |
||||
|
{ |
||||
|
private readonly ICorsPolicyService _corsPolicyService; |
||||
|
|
||||
|
public AbpWildcardSubdomainCorsPolicyService_Tests() |
||||
|
{ |
||||
|
_corsPolicyService = GetRequiredService<ICorsPolicyService>(); |
||||
|
} |
||||
|
|
||||
|
protected override void AfterAddApplication(IServiceCollection services) |
||||
|
{ |
||||
|
services.AddAbpWildcardSubdomainCorsPolicyService(); |
||||
|
} |
||||
|
|
||||
|
[Fact] |
||||
|
public void Should_Register_AbpWildcardSubdomainCorsPolicyService() |
||||
|
{ |
||||
|
_corsPolicyService.GetType().ShouldBe(typeof(AbpWildcardSubdomainCorsPolicyService)); |
||||
|
} |
||||
|
|
||||
|
[Fact] |
||||
|
public async Task IsOriginAllowedAsync() |
||||
|
{ |
||||
|
(await _corsPolicyService.IsOriginAllowedAsync("https://client1-origin.com")).ShouldBeTrue(); |
||||
|
(await _corsPolicyService.IsOriginAllowedAsync("https://client2-origin.com")).ShouldBeFalse(); |
||||
|
|
||||
|
(await _corsPolicyService.IsOriginAllowedAsync("https://abp.io")).ShouldBeTrue(); |
||||
|
(await _corsPolicyService.IsOriginAllowedAsync("https://t1.abp.io")).ShouldBeTrue(); |
||||
|
(await _corsPolicyService.IsOriginAllowedAsync("https://t1.ng.abp.io")).ShouldBeTrue(); |
||||
|
} |
||||
|
} |
||||
|
} |
||||
Loading…
Reference in new issue