From c84c5b76c1af7cf10a7f3c7d23ce48d218c3757f Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Halil=20=C4=B0brahim=20Kalkan?= Date: Mon, 5 Mar 2018 09:44:13 +0300 Subject: [PATCH] Working on identity server integration. --- .../MicroservicesAuthServerModule.cs | 7 +- .../MicroservicesDemoWebModule.cs | 46 +++++-- .../MicroserviceDemo.Web/Pages/Index.cshtml | 13 +- .../Pages/Account/Login.cshtml.cs | 4 +- .../Pages/Account/_ScopeListItem.cshtml | 36 ++---- .../Pages/Consent.cshtml | 65 +++++++--- .../Pages/Consent.cshtml.cs | 114 +++++++++++------- .../Pages/Account/Login.cshtml.cs | 3 +- .../AbpIdentityServiceCollectionExtensions.cs | 3 +- ... => AbpIdentityServerBuilderExtensions.cs} | 2 +- .../AbpIdentityServerDomainModule.cs | 15 ++- .../AspNetIdentity/AbpProfileService.cs | 23 +++- .../Clients/ClientAutoMapperProfile.cs | 5 + 13 files changed, 228 insertions(+), 108 deletions(-) rename src/Volo.Abp.IdentityServer.Domain/Volo/Abp/IdentityServer/{AbpZeroIdentityServerBuilderExtensions.cs => AbpIdentityServerBuilderExtensions.cs} (96%) diff --git a/src/MicroserviceDemo/MicroserviceDemo.AuthServer/MicroservicesAuthServerModule.cs b/src/MicroserviceDemo/MicroserviceDemo.AuthServer/MicroservicesAuthServerModule.cs index 7a9e6b2290..dd0a0ccc12 100644 --- a/src/MicroserviceDemo/MicroserviceDemo.AuthServer/MicroservicesAuthServerModule.cs +++ b/src/MicroserviceDemo/MicroserviceDemo.AuthServer/MicroservicesAuthServerModule.cs @@ -13,7 +13,6 @@ using Volo.Abp.Autofac; using Volo.Abp.Data; using Volo.Abp.EntityFrameworkCore; using Volo.Abp.Identity.EntityFrameworkCore; -using Volo.Abp.IdentityServer; using Volo.Abp.IdentityServer.EntityFrameworkCore; using Volo.Abp.Modularity; using Volo.Abp.VirtualFileSystem; @@ -48,6 +47,12 @@ namespace MicroserviceDemo.AuthServer }); }); + services.Configure(iis => + { + iis.AuthenticationDisplayName = "Windows"; + iis.AutomaticAuthentication = false; + }); + if (hostingEnvironment.IsDevelopment()) { services.Configure(options => diff --git a/src/MicroserviceDemo/MicroserviceDemo.Web/MicroservicesDemoWebModule.cs b/src/MicroserviceDemo/MicroserviceDemo.Web/MicroservicesDemoWebModule.cs index 670ec04226..ba35973aff 100644 --- a/src/MicroserviceDemo/MicroserviceDemo.Web/MicroservicesDemoWebModule.cs +++ b/src/MicroserviceDemo/MicroserviceDemo.Web/MicroservicesDemoWebModule.cs @@ -1,9 +1,16 @@ using System; +using System.IdentityModel.Tokens.Jwt; +using System.Security.Claims; +using Microsoft.AspNetCore.Authentication; +using Microsoft.AspNetCore.Authentication.OAuth.Claims; using Microsoft.AspNetCore.Builder; using Microsoft.AspNetCore.Hosting; +using Microsoft.AspNetCore.Identity; using Microsoft.EntityFrameworkCore; using Microsoft.Extensions.Configuration; using Microsoft.Extensions.DependencyInjection; +using Microsoft.IdentityModel.Protocols.OpenIdConnect; +using Microsoft.IdentityModel.Tokens; using Swashbuckle.AspNetCore.Swagger; using Volo.Abp; using Volo.Abp.Account.Web; @@ -21,6 +28,7 @@ using Volo.Abp.MultiTenancy; using Volo.Abp.MultiTenancy.Web; using Volo.Abp.Permissions; using Volo.Abp.Permissions.EntityFrameworkCore; +using Volo.Abp.Security.Claims; namespace MicroserviceDemo.Web { @@ -75,28 +83,41 @@ namespace MicroserviceDemo.Web }); }); + var xxx = JwtSecurityTokenHandler.DefaultInboundClaimTypeMap; + + //JwtSecurityTokenHandler.DefaultInboundClaimTypeMap.Clear(); //TODO: Try to understand if this is really needed? + services.AddAuthentication(options => { - options.DefaultScheme = "Cookies"; - options.DefaultChallengeScheme = "oidc"; + //options.DefaultScheme = IdentityConstants.ApplicationScheme; + //options.DefaultChallengeScheme = "oidc"; }) - .AddCookie("Cookies") + //.AddCookie(IdentityConstants.ApplicationScheme) .AddOpenIdConnect("oidc", options => { - options.SignInScheme = "Cookies"; + //options.SignInScheme = IdentityConstants.ApplicationScheme; options.Authority = "http://localhost:54307"; options.RequireHttpsMetadata = false; - options.ClientId = "mvc"; + options.ClientId = "client"; options.ClientSecret = "secret"; - options.ResponseType = "code id_token"; + options.ResponseType = OpenIdConnectResponseType.CodeIdToken; options.SaveTokens = true; options.GetClaimsFromUserInfoEndpoint = true; - options.Scope.Add("api1"); + options.Scope.Add("openid"); + options.Scope.Add("profile"); + options.Scope.Add("email"); + options.Scope.Add("phone"); + options.Scope.Add("multi-tenancy-api"); options.Scope.Add("offline_access"); + + options.ClaimActions.MapUniqueJsonKey(AbpClaimTypes.UserName, "name"); + options.ClaimActions.MapUniqueJsonKey(AbpClaimTypes.Email, "email"); + + options.SecurityTokenValidator = new MyJwtSecurityTokenHandler(); }); services.Configure(configuration); @@ -153,4 +174,15 @@ namespace MicroserviceDemo.Web return builder.Build(); } } + + public class MyJwtSecurityTokenHandler : JwtSecurityTokenHandler + { + protected override ClaimsIdentity CreateClaimsIdentity(JwtSecurityToken jwt, string issuer, + TokenValidationParameters validationParameters) + { + var xxx = base.CreateClaimsIdentity(jwt, issuer, validationParameters); + + return xxx; + } + } } \ No newline at end of file diff --git a/src/MicroserviceDemo/MicroserviceDemo.Web/Pages/Index.cshtml b/src/MicroserviceDemo/MicroserviceDemo.Web/Pages/Index.cshtml index f61b9abf2f..c92bb117dd 100644 --- a/src/MicroserviceDemo/MicroserviceDemo.Web/Pages/Index.cshtml +++ b/src/MicroserviceDemo/MicroserviceDemo.Web/Pages/Index.cshtml @@ -1,11 +1,14 @@ @page +@using Microsoft.AspNetCore.Authentication +@using Microsoft.AspNetCore.Http @model MicroserviceDemo.Web.Pages.IndexModel +@inject IHttpContextAccessor HttpContextAccessor

Login - + @if (User.Identity.IsAuthenticated) { foreach (var claim in User.Claims) @@ -14,6 +17,14 @@ } } +


+ + @{ + var accessToken = await HttpContextAccessor.HttpContext.GetTokenAsync("access_token"); + } + + @accessToken
+

\ No newline at end of file diff --git a/src/Volo.Abp.Account.Web.IdentityServer/Pages/Account/Login.cshtml.cs b/src/Volo.Abp.Account.Web.IdentityServer/Pages/Account/Login.cshtml.cs index d7c95c98e5..a1db7969f1 100644 --- a/src/Volo.Abp.Account.Web.IdentityServer/Pages/Account/Login.cshtml.cs +++ b/src/Volo.Abp.Account.Web.IdentityServer/Pages/Account/Login.cshtml.cs @@ -133,7 +133,7 @@ namespace Volo.Abp.Account.Web.Pages.Account } await _interaction.GrantConsentAsync(context, ConsentResponse.Denied); - return RedirectSafely(ReturnUrl); + return Redirect(ReturnUrl); } ValidateModel(); @@ -163,7 +163,7 @@ namespace Volo.Abp.Account.Web.Pages.Account return Redirect("~/"); } - return RedirectSafely(ReturnUrl, ReturnUrlHash); + return Redirect(ReturnUrl); //ReturnUrlHash? } [UnitOfWork] diff --git a/src/Volo.Abp.Account.Web.IdentityServer/Pages/Account/_ScopeListItem.cshtml b/src/Volo.Abp.Account.Web.IdentityServer/Pages/Account/_ScopeListItem.cshtml index 12d6ae8c01..95fee3a858 100644 --- a/src/Volo.Abp.Account.Web.IdentityServer/Pages/Account/_ScopeListItem.cshtml +++ b/src/Volo.Abp.Account.Web.IdentityServer/Pages/Account/_ScopeListItem.cshtml @@ -1,30 +1,20 @@ @using Volo.Abp.Account.Web.Pages @using Volo.Abp.Account.Web.Pages.Account -@model Volo.Abp.Account.Web.Pages.ConsentModel.ScopeViewModel - +@model ConsentModel.ScopeViewModel @* TODO: Should re-format this, just made copy/paste *@ -
  • - +
    + +
    @if (Model.Required) { (required) diff --git a/src/Volo.Abp.Account.Web.IdentityServer/Pages/Consent.cshtml b/src/Volo.Abp.Account.Web.IdentityServer/Pages/Consent.cshtml index fe23d661f8..fa3efda621 100644 --- a/src/Volo.Abp.Account.Web.IdentityServer/Pages/Consent.cshtml +++ b/src/Volo.Abp.Account.Web.IdentityServer/Pages/Consent.cshtml @@ -7,48 +7,85 @@

    - @if (Model.ClientLogoUrl != null) + @if (Model.ClientInfo.ClientLogoUrl != null) { - + } - @Model.ClientName + + @Model.ClientInfo.ClientName is requesting your permission

    -
    +
    Uncheck the permissions you do not wish to grant.
    - @if (Model.IdentityScopes.Any()) + @if (Model.ConsentInput.IdentityScopes.Any()) {

    Personal Information

      - @foreach (var scope in Model.IdentityScopes) + @for (var i = 0; i < Model.ConsentInput.IdentityScopes.Count; i++) { - @Html.Partial("Account/_ScopeListItem", scope) +
    • +
      + +
      + @* TODO: Use attributes on the view model instead of using hidden here *@ + @if (Model.ConsentInput.IdentityScopes[i].Description != null) + { + + } +
    • }
    } - @if (Model.ResourceScopes.Any()) + @if (Model.ConsentInput.ApiScopes.Any()) {

    Application Access

      - @foreach (var scope in Model.ResourceScopes) + @for (var i = 0; i < Model.ConsentInput.ApiScopes.Count; i++) { - @Html.Partial("Account/_ScopeListItem", scope) +
    • +
      + +
      + @* TODO: Use attributes on the view model instead of using hidden here *@ + @if (Model.ConsentInput.ApiScopes[i].Description != null) + { + + } +
    • }
    } - @if (Model.AllowRememberConsent) + @if (Model.ClientInfo.AllowRememberConsent) {