From cc894198008a356eb645ab45a4ed0e92c192f8cc Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Halil=20=C4=B0brahim=20Kalkan?= Date: Tue, 22 Sep 2020 17:10:23 +0300 Subject: [PATCH] #5550 Add Create, Edit & Delete policy checks to the BlazoriseCrudPageBase --- .../Abp/BlazoriseUI/BlazoriseCrudPageBase.cs | 87 ++++- .../Pages/Identity/RoleManagement.razor | 133 ++++---- .../Pages/Identity/RoleManagement.razor.cs | 23 ++ .../Pages/Identity/UserManagement.razor | 300 +++++++++--------- .../Pages/Identity/UserManagement.razor.cs | 34 +- 5 files changed, 330 insertions(+), 247 deletions(-) diff --git a/framework/src/Volo.Abp.BlazoriseUI/Volo/Abp/BlazoriseUI/BlazoriseCrudPageBase.cs b/framework/src/Volo.Abp.BlazoriseUI/Volo/Abp/BlazoriseUI/BlazoriseCrudPageBase.cs index 5889737745..00fa20239d 100644 --- a/framework/src/Volo.Abp.BlazoriseUI/Volo/Abp/BlazoriseUI/BlazoriseCrudPageBase.cs +++ b/framework/src/Volo.Abp.BlazoriseUI/Volo/Abp/BlazoriseUI/BlazoriseCrudPageBase.cs @@ -4,13 +4,16 @@ using System.Linq; using System.Threading.Tasks; using Blazorise; using Blazorise.DataGrid; +using JetBrains.Annotations; using Localization.Resources.AbpUi; +using Microsoft.AspNetCore.Authorization; using Microsoft.AspNetCore.Components; using Microsoft.Extensions.DependencyInjection; using Microsoft.Extensions.Localization; using Volo.Abp.Application.Dtos; using Volo.Abp.Application.Services; using Volo.Abp.AspNetCore.Components.WebAssembly; +using Volo.Abp.Authorization; using Volo.Abp.ObjectMapping; namespace Volo.Abp.BlazoriseUI @@ -20,7 +23,6 @@ namespace Volo.Abp.BlazoriseUI where TAppService : ICrudAppService where TEntityDto : IEntityDto, new() { - } public abstract class BlazoriseCrudPageBase @@ -29,7 +31,6 @@ namespace Volo.Abp.BlazoriseUI where TEntityDto : IEntityDto, new() where TGetListInput : new() { - } public abstract class BlazoriseCrudPageBase @@ -39,10 +40,10 @@ namespace Volo.Abp.BlazoriseUI where TCreateInput : new() where TGetListInput : new() { - } - public abstract class BlazoriseCrudPageBase + public abstract class BlazoriseCrudPageBase : BlazoriseCrudPageBase where TAppService : ICrudAppService where TEntityDto : IEntityDto @@ -50,12 +51,13 @@ namespace Volo.Abp.BlazoriseUI where TUpdateInput : new() where TGetListInput : new() { - } - public abstract class BlazoriseCrudPageBase + public abstract class BlazoriseCrudPageBase : OwningComponentBase - where TAppService : ICrudAppService + where TAppService : ICrudAppService where TGetOutputDto : IEntityDto where TGetListOutputDto : IEntityDto where TCreateInput : new() @@ -65,6 +67,7 @@ namespace Volo.Abp.BlazoriseUI [Inject] protected TAppService AppService { get; set; } [Inject] protected IUiMessageService UiMessageService { get; set; } [Inject] protected IStringLocalizer UiLocalizer { get; set; } + [Inject] protected IAuthorizationService AuthorizationService { get; set; } protected virtual int PageSize { get; } = LimitedResultRequestDto.DefaultMaxResultCount; @@ -78,6 +81,14 @@ namespace Volo.Abp.BlazoriseUI protected Modal CreateModal; protected Modal EditModal; + protected string CreatePolicyName { get; set; } + protected string UpdatePolicyName { get; set; } + protected string DeletePolicyName { get; set; } + + public bool HasCreatePermission { get; set; } + public bool HasUpdatePermission { get; set; } + public bool HasDeletePermission { get; set; } + protected Type ObjectMapperContext { get; set; } protected IObjectMapper ObjectMapper @@ -124,9 +135,28 @@ namespace Volo.Abp.BlazoriseUI protected override async Task OnInitializedAsync() { + await SetPermissionsAsync(); await GetEntitiesAsync(); } + protected virtual async Task SetPermissionsAsync() + { + if (CreatePolicyName != null) + { + HasCreatePermission = await AuthorizationService.IsGrantedAsync(CreatePolicyName); + } + + if (UpdatePolicyName != null) + { + HasUpdatePermission = await AuthorizationService.IsGrantedAsync(UpdatePolicyName); + } + + if (DeletePolicyName != null) + { + HasDeletePermission = await AuthorizationService.IsGrantedAsync(DeletePolicyName); + } + } + protected virtual async Task GetEntitiesAsync() { var input = await CreateGetListInputAsync(); @@ -170,11 +200,12 @@ namespace Volo.Abp.BlazoriseUI StateHasChanged(); } - protected virtual Task OpenCreateModalAsync() + protected virtual async Task OpenCreateModalAsync() { + await CheckCreatePolicyAsync(); + NewEntity = new TCreateInput(); CreateModal.Show(); - return Task.CompletedTask; } protected virtual Task CloseCreateModalAsync() @@ -185,6 +216,8 @@ namespace Volo.Abp.BlazoriseUI protected virtual async Task OpenEditModalAsync(TKey id) { + await CheckUpdatePolicyAsync(); + var entityDto = await AppService.GetAsync(id); EditingEntityId = id; EditingEntity = MapToEditingEntity(entityDto); @@ -204,6 +237,7 @@ namespace Volo.Abp.BlazoriseUI protected virtual async Task CreateEntityAsync() { + await CheckCreatePolicyAsync(); await AppService.CreateAsync(NewEntity); await GetEntitiesAsync(); CreateModal.Hide(); @@ -211,6 +245,7 @@ namespace Volo.Abp.BlazoriseUI protected virtual async Task UpdateEntityAsync() { + await CheckUpdatePolicyAsync(); await AppService.UpdateAsync(EditingEntityId, EditingEntity); await GetEntitiesAsync(); EditModal.Hide(); @@ -218,6 +253,8 @@ namespace Volo.Abp.BlazoriseUI protected virtual async Task DeleteEntityAsync(TGetListOutputDto entity) { + await CheckDeletePolicyAsync(); + if (!await UiMessageService.ConfirmAsync(GetDeleteConfirmationMessage(entity))) { return; @@ -231,5 +268,37 @@ namespace Volo.Abp.BlazoriseUI { return UiLocalizer["ItemWillBeDeletedMessage"]; } + + protected virtual async Task CheckCreatePolicyAsync() + { + await CheckPolicyAsync(CreatePolicyName); + } + + protected virtual async Task CheckUpdatePolicyAsync() + { + await CheckPolicyAsync(UpdatePolicyName); + } + + protected virtual async Task CheckDeletePolicyAsync() + { + await CheckPolicyAsync(DeletePolicyName); + } + + /// + /// Calls IAuthorizationService.CheckAsync for the given . + /// Throws if given policy was not granted for the current user. + /// + /// Does nothing if is null or empty. + /// + /// A policy name to check + protected virtual async Task CheckPolicyAsync([CanBeNull] string policyName) + { + if (string.IsNullOrEmpty(policyName)) + { + return; + } + + await AuthorizationService.CheckAsync(policyName); + } } } diff --git a/modules/identity/src/Volo.Abp.Identity.Blazor/Pages/Identity/RoleManagement.razor b/modules/identity/src/Volo.Abp.Identity.Blazor/Pages/Identity/RoleManagement.razor index 67d2d49ce2..ce8e9175fa 100644 --- a/modules/identity/src/Volo.Abp.Identity.Blazor/Pages/Identity/RoleManagement.razor +++ b/modules/identity/src/Volo.Abp.Identity.Blazor/Pages/Identity/RoleManagement.razor @@ -7,7 +7,6 @@ @using Volo.Abp.PermissionManagement.Blazor.Components @inherits RoleManagementBase @inject IStringLocalizer L -@inject IAuthorizationService AuthorizationService @* ************************* PAGE HEADER ************************* *@ @@ -15,7 +14,7 @@

@L["Roles"]

- @if (canCreate) + @if (HasCreatePermission) { @@ -32,7 +31,7 @@ ShowPager="true" PageSize="PageSize"> - @if (canEdit || canDelete || canEditPermissions) + @if (ShouldShowEntityActions) { @@ -41,23 +40,22 @@ @L["Actions"] - @if (canEdit) + @if (HasUpdatePermission) { @L["Edit"] } - @if (canEditPermissions) + @if (HasManagePermissionsPermission) { @L["Permissions"] } - @if (canDelete) + @if (HasDeletePermission) { - @L["Delete"] } - + } @@ -76,72 +74,59 @@ @* ************************* CREATE MODAL ************************* *@ - - - - - @L["NewRole"] - - - - - @L["DisplayName:RoleName"] - - - - @L["DisplayName:IsDefault"] - @L["DisplayName:IsPublic"] - - - - - - - - - +@if (HasCreatePermission) +{ + + + + + @L["NewRole"] + + + + + @L["DisplayName:RoleName"] + + + + @L["DisplayName:IsDefault"] + @L["DisplayName:IsPublic"] + + + + + + + + +} @* ************************* EDIT MODAL ************************* *@ - - - - - Edit role - - - - - - @L["DisplayName:RoleName"] - - - - @L["DisplayName:IsDefault"] - @L["DisplayName:IsPublic"] - - - - - - - - - - - -@code +@if (HasUpdatePermission) { - bool canCreate; - bool canEdit; - bool canDelete; - bool canEditPermissions; - - protected override async Task OnInitializedAsync() - { - await base.OnInitializedAsync(); + + + + + Edit role + + + + + + @L["DisplayName:RoleName"] + + + + @L["DisplayName:IsDefault"] + @L["DisplayName:IsPublic"] + + + + + + + + +} - canCreate =await AuthorizationService.IsGrantedAsync(IdentityPermissions.Roles.Create); - canEdit = await AuthorizationService.IsGrantedAsync(IdentityPermissions.Roles.Update); - canDelete = await AuthorizationService.IsGrantedAsync(IdentityPermissions.Roles.Delete); - canEditPermissions = await AuthorizationService.IsGrantedAsync(IdentityPermissions.Roles.ManagePermissions); - } -} \ No newline at end of file + diff --git a/modules/identity/src/Volo.Abp.Identity.Blazor/Pages/Identity/RoleManagement.razor.cs b/modules/identity/src/Volo.Abp.Identity.Blazor/Pages/Identity/RoleManagement.razor.cs index a221c84a5d..92c527e970 100644 --- a/modules/identity/src/Volo.Abp.Identity.Blazor/Pages/Identity/RoleManagement.razor.cs +++ b/modules/identity/src/Volo.Abp.Identity.Blazor/Pages/Identity/RoleManagement.razor.cs @@ -1,4 +1,6 @@ using System; +using System.Threading.Tasks; +using Microsoft.AspNetCore.Authorization; using Volo.Abp.Application.Dtos; using Volo.Abp.BlazoriseUI; using Volo.Abp.PermissionManagement.Blazor.Components; @@ -11,9 +13,30 @@ namespace Volo.Abp.Identity.Blazor.Pages.Identity protected PermissionManagementModal PermissionManagementModal; + protected bool HasManagePermissionsPermission { get; set; } + + protected bool ShouldShowEntityActions { get; set; } + public RoleManagementBase() { ObjectMapperContext = typeof(AbpIdentityBlazorModule); + + CreatePolicyName = IdentityPermissions.Roles.Create; + UpdatePolicyName = IdentityPermissions.Roles.Update; + DeletePolicyName = IdentityPermissions.Roles.Delete; + } + + protected override async Task SetPermissionsAsync() + { + await base.SetPermissionsAsync(); + + HasManagePermissionsPermission = await AuthorizationService.IsGrantedAsync( + IdentityPermissions.Roles.ManagePermissions + ); + + ShouldShowEntityActions = HasUpdatePermission || + HasDeletePermission || + HasManagePermissionsPermission; } } } diff --git a/modules/identity/src/Volo.Abp.Identity.Blazor/Pages/Identity/UserManagement.razor b/modules/identity/src/Volo.Abp.Identity.Blazor/Pages/Identity/UserManagement.razor index 899c28ef51..047c571d21 100644 --- a/modules/identity/src/Volo.Abp.Identity.Blazor/Pages/Identity/UserManagement.razor +++ b/modules/identity/src/Volo.Abp.Identity.Blazor/Pages/Identity/UserManagement.razor @@ -2,12 +2,10 @@ @attribute [Authorize(IdentityPermissions.Users.Default)] @using Microsoft.AspNetCore.Authorization @using Microsoft.Extensions.Localization -@using Volo.Abp.Application.Dtos @using Volo.Abp.Identity.Localization @using Volo.Abp.PermissionManagement.Blazor.Components @inherits UserManagementBase @inject IStringLocalizer L -@inject IAuthorizationService AuthorizationService @* ************************* PAGE HEADER ************************* *@ @@ -15,7 +13,7 @@

@L["Users"]

- @if (canCreate) + @if (HasCreatePermission) { @@ -32,7 +30,7 @@ ShowPager="true" PageSize="PageSize"> - @if (canEdit || canDelete || canEditPermissions) + @if (ShouldShowEntityActions) { @@ -41,15 +39,15 @@ @L["Actions"] - @if (canEdit) + @if (HasUpdatePermission) { @L["Edit"] } - @if (canEditPermissions) + @if (HasManagePermissionsPermission) { - @L["Permissions"] + @L["Permissions"] } - @if (canDelete) + @if (HasDeletePermission) { @L["Delete"] @@ -78,161 +76,149 @@ @* ************************* CREATE MODAL ************************* *@ - - - - - @L["NewUser"] - - - - - - @L["UserInformations"] - @L["Roles"] - - - - - @L["DisplayName:UserName"] - - - - @L["DisplayName:Name"] - - - - @L["DisplayName:Surname"] - - - - @L["DisplayName:Password"] - - - - @L["DisplayName:Email"] - - - - @L["DisplayName:PhoneNumber"] - - - - @L["DisplayName:LockoutEnabled"] - - - @L["DisplayName:TwoFactorEnabled"] - - - - @if (NewUserRoles != null) - { - @foreach (var role in NewUserRoles) +@if (HasCreatePermission) +{ + + + + + @L["NewUser"] + + + + + + @L["UserInformations"] + @L["Roles"] + + + + + @L["DisplayName:UserName"] + + + + @L["DisplayName:Name"] + + + + @L["DisplayName:Surname"] + + + + @L["DisplayName:Password"] + + + + @L["DisplayName:Email"] + + + + @L["DisplayName:PhoneNumber"] + + + + @L["DisplayName:LockoutEnabled"] + + + @L["DisplayName:TwoFactorEnabled"] + + + + @if (NewUserRoles != null) { - - - @role.Name - + @foreach (var role in NewUserRoles) + { + + + @role.Name + + } } - } - - - - - - - - - - + + + + + + + + + + +} @* ************************* EDIT MODAL ************************* *@ - - - - - role - - - - +@if (HasUpdatePermission) +{ + + + + + role + + + + - - - @L["UserInformations"] - @L["Roles"] - - - - - @L["DisplayName:UserName"] - - - - @L["DisplayName:Name"] - - - - @L["DisplayName:Surname"] - - - - @L["DisplayName:Password"] - - - - @L["DisplayName:Email"] - - - - @L["DisplayName:PhoneNumber"] - - - - @L["DisplayName:LockoutEnabled"] - - - @L["DisplayName:TwoFactorEnabled"] - - - - @if (EditUserRoles != null) - { - @foreach (var role in EditUserRoles) + + + @L["UserInformations"] + @L["Roles"] + + + + + @L["DisplayName:UserName"] + + + + @L["DisplayName:Name"] + + + + @L["DisplayName:Surname"] + + + + @L["DisplayName:Password"] + + + + @L["DisplayName:Email"] + + + + @L["DisplayName:PhoneNumber"] + + + + @L["DisplayName:LockoutEnabled"] + + + @L["DisplayName:TwoFactorEnabled"] + + + + @if (EditUserRoles != null) { - - - @role.Name - + @foreach (var role in EditUserRoles) + { + + + @role.Name + + } } - } - - - - - - - - - - + + + + + + + + + + +} - -@code -{ - bool canCreate; - bool canEdit; - bool canDelete; - bool canEditPermissions; - - protected override async Task OnInitializedAsync() - { - await base.OnInitializedAsync(); - - canCreate =await AuthorizationService.IsGrantedAsync(IdentityPermissions.Users.Create); - canEdit = await AuthorizationService.IsGrantedAsync(IdentityPermissions.Users.Update); - canDelete = await AuthorizationService.IsGrantedAsync(IdentityPermissions.Users.Delete); - canEditPermissions = await AuthorizationService.IsGrantedAsync(IdentityPermissions.Users.ManagePermissions); - } -} \ No newline at end of file diff --git a/modules/identity/src/Volo.Abp.Identity.Blazor/Pages/Identity/UserManagement.razor.cs b/modules/identity/src/Volo.Abp.Identity.Blazor/Pages/Identity/UserManagement.razor.cs index df79f6bd5f..ca6f1e3870 100644 --- a/modules/identity/src/Volo.Abp.Identity.Blazor/Pages/Identity/UserManagement.razor.cs +++ b/modules/identity/src/Volo.Abp.Identity.Blazor/Pages/Identity/UserManagement.razor.cs @@ -2,9 +2,9 @@ using System.Collections.Generic; using System.Linq; using System.Threading.Tasks; +using Microsoft.AspNetCore.Authorization; using Volo.Abp.BlazoriseUI; using Volo.Abp.PermissionManagement.Blazor.Components; -using Volo.Abp.Threading; namespace Volo.Abp.Identity.Blazor.Pages.Identity { @@ -13,7 +13,7 @@ namespace Volo.Abp.Identity.Blazor.Pages.Identity protected const string PermissionProviderName = "U"; protected const string DefaultSelectedTab = "UserInformations"; - + protected PermissionManagementModal PermissionManagementModal; protected IReadOnlyList Roles; @@ -21,14 +21,21 @@ namespace Volo.Abp.Identity.Blazor.Pages.Identity protected AssignedRoleViewModel[] NewUserRoles; protected AssignedRoleViewModel[] EditUserRoles; - + + protected bool ShouldShowEntityActions { get; set; } + protected bool HasManagePermissionsPermission { get; set; } + protected string _createModalSelectedTab = DefaultSelectedTab; - + protected string _editModalSelectedTab = DefaultSelectedTab; - + public UserManagementBase() { ObjectMapperContext = typeof(AbpIdentityBlazorModule); + + CreatePolicyName = IdentityPermissions.Users.Create; + UpdatePolicyName = IdentityPermissions.Users.Update; + DeletePolicyName = IdentityPermissions.Users.Delete; } protected override async Task OnInitializedAsync() @@ -38,10 +45,23 @@ namespace Volo.Abp.Identity.Blazor.Pages.Identity Roles = (await AppService.GetAssignableRolesAsync()).Items; } + protected override async Task SetPermissionsAsync() + { + await base.SetPermissionsAsync(); + + HasManagePermissionsPermission = await AuthorizationService.IsGrantedAsync( + IdentityPermissions.Users.ManagePermissions + ); + + ShouldShowEntityActions = HasUpdatePermission || + HasDeletePermission || + HasManagePermissionsPermission; + } + protected override Task OpenCreateModalAsync() { _createModalSelectedTab = DefaultSelectedTab; - + NewUserRoles = Roles.Select(x => new AssignedRoleViewModel { Name = x.Name, @@ -61,7 +81,7 @@ namespace Volo.Abp.Identity.Blazor.Pages.Identity protected override async Task OpenEditModalAsync(Guid id) { _editModalSelectedTab = DefaultSelectedTab; - + var userRoleNames = (await AppService.GetRolesAsync(id)).Items.Select(r => r.Name).ToList(); EditUserRoles = Roles.Select(x => new AssignedRoleViewModel