From c18394daec3361778c96fe40fbb00e9a20ac7e3e Mon Sep 17 00:00:00 2001 From: maliming Date: Sun, 5 Feb 2023 19:55:39 +0800 Subject: [PATCH] Add `AccessDenied` action. Resolve #15600 --- .../ChallengeAccountController.cs | 28 +++++++++++++++++-- 1 file changed, 25 insertions(+), 3 deletions(-) diff --git a/framework/src/Volo.Abp.AspNetCore.Mvc/Volo/Abp/AspNetCore/Mvc/Authentication/ChallengeAccountController.cs b/framework/src/Volo.Abp.AspNetCore.Mvc/Volo/Abp/AspNetCore/Mvc/Authentication/ChallengeAccountController.cs index f8316da3d8..15abd26b1e 100644 --- a/framework/src/Volo.Abp.AspNetCore.Mvc/Volo/Abp/AspNetCore/Mvc/Authentication/ChallengeAccountController.cs +++ b/framework/src/Volo.Abp.AspNetCore.Mvc/Volo/Abp/AspNetCore/Mvc/Authentication/ChallengeAccountController.cs @@ -1,7 +1,10 @@ using System; +using System.Collections.Generic; using System.Threading.Tasks; using Microsoft.AspNetCore.Authentication; using Microsoft.AspNetCore.Mvc; +using Microsoft.Extensions.DependencyInjection; +using Microsoft.Extensions.Options; namespace Volo.Abp.AspNetCore.Mvc.Authentication; @@ -9,15 +12,17 @@ public abstract class ChallengeAccountController : AbpController { protected string[] ChallengeAuthenticationSchemas { get; } protected string AuthenticationType { get; } + protected string[] ForbidSchemes { get; } protected ChallengeAccountController(string[] challengeAuthenticationSchemas = null) { ChallengeAuthenticationSchemas = challengeAuthenticationSchemas ?? new[] { "oidc" }; AuthenticationType = "Identity.Application"; + ForbidSchemes = Array.Empty(); } [HttpGet] - public ActionResult Login(string returnUrl = "", string returnUrlHash = "") + public virtual ActionResult Login(string returnUrl = "", string returnUrlHash = "") { if (CurrentUser.IsAuthenticated) { @@ -28,7 +33,7 @@ public abstract class ChallengeAccountController : AbpController } [HttpGet] - public async Task Logout(string returnUrl = "", string returnUrlHash = "") + public virtual async Task Logout(string returnUrl = "", string returnUrlHash = "") { await HttpContext.SignOutAsync(); @@ -41,7 +46,7 @@ public abstract class ChallengeAccountController : AbpController } [HttpGet] - public async Task FrontChannelLogout(string sid) + public virtual async Task FrontChannelLogout(string sid) { if (User.Identity != null && User.Identity.IsAuthenticated) { @@ -54,4 +59,21 @@ public abstract class ChallengeAccountController : AbpController return NoContent(); } + + [HttpGet] + public virtual Task AccessDenied(string returnUrl = "", string returnUrlHash = "") + { + return Task.FromResult(Challenge( + new AuthenticationProperties + { + RedirectUri = GetRedirectUrl(returnUrl, returnUrlHash) + }, + ForbidSchemes.IsNullOrEmpty() + ? new[] + { + HttpContext.RequestServices.GetRequiredService>().Value.DefaultForbidScheme + } + : ForbidSchemes + )); + } }