mirror of https://github.com/abpframework/abp.git
4 changed files with 157 additions and 1 deletions
@ -0,0 +1,27 @@ |
|||
using System.Threading.Tasks; |
|||
using Microsoft.Extensions.DependencyInjection; |
|||
using Microsoft.Extensions.Options; |
|||
using Volo.Abp.BackgroundWorkers; |
|||
using Volo.Abp.Threading; |
|||
|
|||
namespace Volo.Abp.OpenIddict.Tokens; |
|||
|
|||
public class TokenCleanupBackgroundWorker : AsyncPeriodicBackgroundWorkerBase |
|||
{ |
|||
public TokenCleanupBackgroundWorker( |
|||
AbpAsyncTimer timer, |
|||
IServiceScopeFactory serviceScopeFactory, |
|||
IOptionsMonitor<TokenCleanupOptions> cleanupOptions) |
|||
: base(timer, serviceScopeFactory) |
|||
{ |
|||
timer.Period = cleanupOptions.CurrentValue.CleanupPeriod; |
|||
} |
|||
|
|||
protected async override Task DoWorkAsync(PeriodicBackgroundWorkerContext workerContext) |
|||
{ |
|||
await workerContext |
|||
.ServiceProvider |
|||
.GetRequiredService<TokenCleanupService>() |
|||
.CleanAsync(); |
|||
} |
|||
} |
|||
@ -0,0 +1,41 @@ |
|||
using System; |
|||
using Volo.Abp.BackgroundWorkers; |
|||
|
|||
namespace Volo.Abp.OpenIddict.Tokens; |
|||
|
|||
public class TokenCleanupOptions |
|||
{ |
|||
/// <summary>
|
|||
/// Default value: true.
|
|||
/// If <see cref="AbpBackgroundWorkerOptions.IsEnabled"/> is false,
|
|||
/// this property is ignored and the cleanup worker doesn't work for this application instance.
|
|||
/// </summary>
|
|||
public bool IsCleanupEnabled { get; set; } = true; |
|||
|
|||
/// <summary>
|
|||
/// Default: 3,600,000 ms.
|
|||
/// </summary>
|
|||
public int CleanupPeriod { get; set; } = 3_600_000; |
|||
|
|||
/// <summary>
|
|||
/// Gets or sets a boolean indicating whether authorizations pruning should be disabled.
|
|||
/// </summary>
|
|||
public bool DisableAuthorizationPruning { get; set; } |
|||
|
|||
/// <summary>
|
|||
/// Gets or sets a boolean indicating whether tokens pruning should be disabled.
|
|||
/// </summary>
|
|||
public bool DisableTokenPruning { get; set; } |
|||
|
|||
/// <summary>
|
|||
/// Gets or sets the minimum lifespan authorizations must have to be pruned.
|
|||
/// By default, this value is set to 14 days and cannot be less than 10 minutes.
|
|||
/// </summary>
|
|||
public TimeSpan MinimumAuthorizationLifespan { get; set; } = TimeSpan.FromDays(14); |
|||
|
|||
/// <summary>
|
|||
/// Gets or sets the minimum lifespan tokens must have to be pruned.
|
|||
/// By default, this value is set to 14 days and cannot be less than 10 minutes.
|
|||
/// </summary>
|
|||
public TimeSpan MinimumTokenLifespan { get; set; } = TimeSpan.FromDays(14); |
|||
} |
|||
@ -0,0 +1,68 @@ |
|||
using System; |
|||
using System.Threading.Tasks; |
|||
using Microsoft.Extensions.Logging; |
|||
using Microsoft.Extensions.Logging.Abstractions; |
|||
using Microsoft.Extensions.Options; |
|||
using OpenIddict.Abstractions; |
|||
using Volo.Abp.DependencyInjection; |
|||
|
|||
namespace Volo.Abp.OpenIddict.Tokens; |
|||
|
|||
// Note: this background task is responsible of automatically removing orphaned tokens/authorizations
|
|||
// (i.e tokens that are no longer valid and ad-hoc authorizations that have no valid tokens associated).
|
|||
// Import: since tokens associated to ad-hoc authorizations are not removed as part of the same operation,
|
|||
// the tokens MUST be deleted before removing the ad-hoc authorizations that no longer have any token.
|
|||
public class TokenCleanupService : ITransientDependency |
|||
{ |
|||
public ILogger<TokenCleanupService> Logger { get; set; } |
|||
protected TokenCleanupOptions CleanupOptions { get; } |
|||
protected IOpenIddictTokenManager TokenManager { get; } |
|||
protected IOpenIddictAuthorizationManager AuthorizationManager { get; } |
|||
|
|||
public TokenCleanupService( |
|||
IOptionsMonitor<TokenCleanupOptions> cleanupOptions, |
|||
IOpenIddictTokenManager tokenManager, |
|||
IOpenIddictAuthorizationManager authorizationManager) |
|||
{ |
|||
Logger = NullLogger<TokenCleanupService>.Instance;; |
|||
|
|||
CleanupOptions = cleanupOptions.CurrentValue; |
|||
TokenManager = tokenManager; |
|||
AuthorizationManager = authorizationManager; |
|||
} |
|||
|
|||
public virtual async Task CleanAsync() |
|||
{ |
|||
Logger.LogInformation("Start cleanup."); |
|||
|
|||
if (!CleanupOptions.DisableTokenPruning) |
|||
{ |
|||
Logger.LogInformation("Start cleanup tokens."); |
|||
|
|||
var threshold = DateTimeOffset.UtcNow - CleanupOptions.MinimumTokenLifespan; |
|||
try |
|||
{ |
|||
await TokenManager.PruneAsync(threshold); |
|||
} |
|||
catch (Exception exception) |
|||
{ |
|||
Logger.LogException(exception); |
|||
} |
|||
} |
|||
|
|||
if (!CleanupOptions.DisableAuthorizationPruning) |
|||
{ |
|||
Logger.LogInformation("Start cleanup authorizations."); |
|||
|
|||
var threshold = DateTimeOffset.UtcNow - CleanupOptions.MinimumAuthorizationLifespan; |
|||
try |
|||
{ |
|||
await AuthorizationManager.PruneAsync(threshold); |
|||
} |
|||
catch (Exception exception) |
|||
{ |
|||
Logger.LogException(exception); |
|||
} |
|||
} |
|||
} |
|||
} |
|||
Loading…
Reference in new issue