mirror of https://github.com/abpframework/abp.git
8 changed files with 182 additions and 1 deletions
@ -0,0 +1,37 @@ |
|||||
|
using System; |
||||
|
using Microsoft.AspNetCore.Authorization; |
||||
|
using Microsoft.AspNetCore.Mvc; |
||||
|
using Shouldly; |
||||
|
|
||||
|
namespace Volo.Abp.AspNetCore.Mvc.Authorization |
||||
|
{ |
||||
|
[Authorize] |
||||
|
public class AuthTestController : AbpController |
||||
|
{ |
||||
|
public static Guid FakeUserId { get; } = new Guid(); |
||||
|
|
||||
|
[AllowAnonymous] |
||||
|
public ActionResult AnonymousTest() |
||||
|
{ |
||||
|
return Content("OK"); |
||||
|
} |
||||
|
|
||||
|
public ActionResult SimpleAuthorizationTest() |
||||
|
{ |
||||
|
CurrentUser.Id.ShouldBe(FakeUserId); |
||||
|
return Content("OK"); |
||||
|
} |
||||
|
|
||||
|
[Authorize("MyClaimTestPolicy")] |
||||
|
public ActionResult CustomPolicyTest() |
||||
|
{ |
||||
|
return Content("OK"); |
||||
|
} |
||||
|
|
||||
|
//[Authorize("TestPermission")]
|
||||
|
//public ActionResult PermissionTest()
|
||||
|
//{
|
||||
|
// return Content("OK");
|
||||
|
//}
|
||||
|
} |
||||
|
} |
||||
@ -0,0 +1,77 @@ |
|||||
|
using System; |
||||
|
using System.Security.Claims; |
||||
|
using System.Threading.Tasks; |
||||
|
using Shouldly; |
||||
|
using Volo.Abp.AspNetCore.TestBase; |
||||
|
using Volo.Abp.Autofac; |
||||
|
using Volo.Abp.MemoryDb; |
||||
|
using Volo.Abp.Modularity; |
||||
|
using Volo.Abp.Security.Claims; |
||||
|
using Volo.Abp.Session; |
||||
|
using Xunit; |
||||
|
|
||||
|
namespace Volo.Abp.AspNetCore.Mvc.Authorization |
||||
|
{ |
||||
|
[DependsOn( |
||||
|
typeof(AbpAspNetCoreTestBaseModule), |
||||
|
typeof(AbpMemoryDbTestModule), |
||||
|
typeof(AbpAspNetCoreMvcModule), |
||||
|
typeof(AbpAutofacModule) |
||||
|
)] |
||||
|
public class AuthTestController_Tests : AspNetCoreMvcTestBase |
||||
|
{ |
||||
|
private readonly FakeUserClaims _fakeRequiredService; |
||||
|
|
||||
|
public AuthTestController_Tests() |
||||
|
{ |
||||
|
_fakeRequiredService = GetRequiredService<FakeUserClaims>(); |
||||
|
} |
||||
|
|
||||
|
[Fact] |
||||
|
public async Task Should_Call_Anonymous_Method_Without_Authentication() |
||||
|
{ |
||||
|
var result = await GetResponseAsStringAsync("/AuthTest/AnonymousTest"); |
||||
|
result.ShouldBe("OK"); |
||||
|
} |
||||
|
|
||||
|
[Fact] |
||||
|
public async Task Should_Call_Simple_Authorized_Method_With_Authenticated_User() |
||||
|
{ |
||||
|
_fakeRequiredService.Claims.AddRange(new[] |
||||
|
{ |
||||
|
new Claim(AbpClaimTypes.UserId, AuthTestController.FakeUserId.ToString()) |
||||
|
}); |
||||
|
|
||||
|
var result = await GetResponseAsStringAsync("/AuthTest/SimpleAuthorizationTest"); |
||||
|
result.ShouldBe("OK"); |
||||
|
} |
||||
|
|
||||
|
[Fact] |
||||
|
public async Task Custom_Claim_Policy_Should_Work_With_Right_Claim_Provided() |
||||
|
{ |
||||
|
_fakeRequiredService.Claims.AddRange(new[] |
||||
|
{ |
||||
|
new Claim(AbpClaimTypes.UserId, AuthTestController.FakeUserId.ToString()), |
||||
|
new Claim("MyCustomClaimType", "42") |
||||
|
}); |
||||
|
|
||||
|
var result = await GetResponseAsStringAsync("/AuthTest/CustomPolicyTest"); |
||||
|
result.ShouldBe("OK"); |
||||
|
} |
||||
|
|
||||
|
[Fact] |
||||
|
public async Task Custom_Claim_Policy_Should_Not_Work_With_Wrong_Claim_Value() |
||||
|
{ |
||||
|
_fakeRequiredService.Claims.AddRange(new[] |
||||
|
{ |
||||
|
new Claim(AbpClaimTypes.UserId, AuthTestController.FakeUserId.ToString()), |
||||
|
new Claim("MyCustomClaimType", "43") |
||||
|
}); |
||||
|
|
||||
|
//TODO: We can get a real exception if we properly configure authentication schemas for this project
|
||||
|
await Assert.ThrowsAsync<InvalidOperationException>(async () => |
||||
|
await GetResponseAsStringAsync("/AuthTest/CustomPolicyTest") |
||||
|
); |
||||
|
} |
||||
|
} |
||||
|
} |
||||
@ -0,0 +1,33 @@ |
|||||
|
using System.Collections.Generic; |
||||
|
using System.Linq; |
||||
|
using System.Security.Claims; |
||||
|
using System.Threading.Tasks; |
||||
|
using Microsoft.AspNetCore.Http; |
||||
|
|
||||
|
namespace Volo.Abp.AspNetCore.Mvc.Authorization |
||||
|
{ |
||||
|
public class FakeAuthenticationMiddleware |
||||
|
{ |
||||
|
private readonly RequestDelegate _next; |
||||
|
private readonly FakeUserClaims _fakeUserClaims; |
||||
|
|
||||
|
public FakeAuthenticationMiddleware(RequestDelegate next, FakeUserClaims fakeUserClaims) |
||||
|
{ |
||||
|
_next = next; |
||||
|
_fakeUserClaims = fakeUserClaims; |
||||
|
} |
||||
|
|
||||
|
public async Task Invoke(HttpContext httpContext) |
||||
|
{ |
||||
|
if (_fakeUserClaims.Claims.Any()) |
||||
|
{ |
||||
|
httpContext.User = new ClaimsPrincipal(new List<ClaimsIdentity> |
||||
|
{ |
||||
|
new ClaimsIdentity(_fakeUserClaims.Claims, "FakeSchema") |
||||
|
}); |
||||
|
} |
||||
|
|
||||
|
await _next(httpContext); |
||||
|
} |
||||
|
} |
||||
|
} |
||||
@ -0,0 +1,11 @@ |
|||||
|
using System.Collections.Generic; |
||||
|
using System.Security.Claims; |
||||
|
using Volo.Abp.DependencyInjection; |
||||
|
|
||||
|
namespace Volo.Abp.AspNetCore.Mvc.Authorization |
||||
|
{ |
||||
|
public class FakeUserClaims : ISingletonDependency |
||||
|
{ |
||||
|
public List<Claim> Claims { get; } = new List<Claim>(); |
||||
|
} |
||||
|
} |
||||
Loading…
Reference in new issue