Browse Source

added scope and role mapping seeding

pull/136/head
Galip Tolga Erdem 4 years ago
parent
commit
adfc00eaa0
  1. 64
      shared/EShopOnAbp.Keycloak.DbMigrator/KeycloakDataSeeder.cs

64
shared/EShopOnAbp.Keycloak.DbMigrator/KeycloakDataSeeder.cs

@ -21,7 +21,8 @@ public class KeyCloakDataSeeder : IDataSeedContributor, ITransientDependency
private readonly ILogger<KeyCloakDataSeeder> _logger; private readonly ILogger<KeyCloakDataSeeder> _logger;
private readonly IConfiguration _configuration; private readonly IConfiguration _configuration;
public KeyCloakDataSeeder(IOptions<KeycloakClientOptions> keycloakClientOptions, ILogger<KeyCloakDataSeeder> logger, IConfiguration configuration) public KeyCloakDataSeeder(IOptions<KeycloakClientOptions> keycloakClientOptions, ILogger<KeyCloakDataSeeder> logger,
IConfiguration configuration)
{ {
_logger = logger; _logger = logger;
_configuration = configuration; _configuration = configuration;
@ -37,10 +38,38 @@ public class KeyCloakDataSeeder : IDataSeedContributor, ITransientDependency
public async Task SeedAsync(DataSeedContext context) public async Task SeedAsync(DataSeedContext context)
{ {
await UpdateAdminUserAsync(); await UpdateAdminUserAsync();
await CreateRoleMapperAsync();
await CreateClientScopesAsync(); await CreateClientScopesAsync();
await CreateClientsAsync(); await CreateClientsAsync();
} }
private async Task CreateRoleMapperAsync()
{
var roleScope = (await _keycloakClient.GetClientScopesAsync(_keycloakOptions.RealmName))
.FirstOrDefault(q => q.Name == "roles");
if (roleScope == null)
return;
if (!roleScope.ProtocolMappers.Any(q => q.Name == "roles"))
{
await _keycloakClient.CreateProtocolMapperAsync(_keycloakOptions.RealmName, roleScope.Id,
new ProtocolMapper()
{
Name = "roles",
Protocol = "openid-connect",
_ProtocolMapper = "oidc-usermodel-realm-role-mapper",
Config = new Dictionary<string, string>()
{
{ "access.token.claim", "true" },
{ "id.token.claim", "true" },
{ "claim.name", "roles" },
{ "multivalued", "true" },
{ "userinfo.token.claim", "true" },
}
});
}
}
private async Task CreateClientScopesAsync() private async Task CreateClientScopesAsync()
{ {
await CreateScopeAsync("AdministrationService"); await CreateScopeAsync("AdministrationService");
@ -77,12 +106,15 @@ public class KeyCloakDataSeeder : IDataSeedContributor, ITransientDependency
Name = scopeName, Name = scopeName,
Protocol = "openid-connect", Protocol = "openid-connect",
_ProtocolMapper = "oidc-audience-mapper", _ProtocolMapper = "oidc-audience-mapper",
Config = new Dictionary<string, string>() //TODO: Update when //https://github.com/AnderssonPeter/Keycloak.Net/pull/5 is merged Config =
{ new
{ "id.token.claim", "false" }, Dictionary<string,
{ "access.token.claim", "true" }, string>() //TODO: Update when //https://github.com/AnderssonPeter/Keycloak.Net/pull/5 is merged
{ "included.custom.audience", scopeName } {
} { "id.token.claim", "false" },
{ "access.token.claim", "true" },
{ "included.custom.audience", scopeName }
}
} }
} }
}; };
@ -126,9 +158,9 @@ public class KeyCloakDataSeeder : IDataSeedContributor, ITransientDependency
}; };
await _keycloakClient.CreateClientAsync(_keycloakOptions.RealmName, webClient); await _keycloakClient.CreateClientAsync(_keycloakOptions.RealmName, webClient);
await AddOptionalClientScopesAsync( await AddOptionalClientScopesAsync(
"PublicWeb", "Web",
new List<string> new List<string>
{ {
"AdministrationService", "IdentityService", "BasketService", "CatalogService", "AdministrationService", "IdentityService", "BasketService", "CatalogService",
@ -140,9 +172,10 @@ public class KeyCloakDataSeeder : IDataSeedContributor, ITransientDependency
private async Task CreateSwaggerClientAsync() private async Task CreateSwaggerClientAsync()
{ {
var swaggerClient = (await _keycloakClient.GetClientsAsync(_keycloakOptions.RealmName, clientId: "SwaggerClient")) var swaggerClient =
(await _keycloakClient.GetClientsAsync(_keycloakOptions.RealmName, clientId: "SwaggerClient"))
.FirstOrDefault(); .FirstOrDefault();
if (swaggerClient == null) if (swaggerClient == null)
{ {
var webGatewaySwaggerRootUrl = _configuration[$"Clients:WebGateway:RootUrl"].TrimEnd('/'); var webGatewaySwaggerRootUrl = _configuration[$"Clients:WebGateway:RootUrl"].TrimEnd('/');
@ -155,7 +188,7 @@ public class KeyCloakDataSeeder : IDataSeedContributor, ITransientDependency
var orderingServiceRootUrl = _configuration[$"Clients:OrderingService:RootUrl"].TrimEnd('/'); var orderingServiceRootUrl = _configuration[$"Clients:OrderingService:RootUrl"].TrimEnd('/');
var paymentServiceRootUrl = _configuration[$"Clients:PaymentService:RootUrl"].TrimEnd('/'); var paymentServiceRootUrl = _configuration[$"Clients:PaymentService:RootUrl"].TrimEnd('/');
var cmskitServiceRootUrl = _configuration[$"Clients:CmskitService:RootUrl"].TrimEnd('/'); var cmskitServiceRootUrl = _configuration[$"Clients:CmskitService:RootUrl"].TrimEnd('/');
swaggerClient = new Client swaggerClient = new Client
{ {
ClientId = "SwaggerClient", ClientId = "SwaggerClient",
@ -197,13 +230,14 @@ public class KeyCloakDataSeeder : IDataSeedContributor, ITransientDependency
Name = "Public Web Application", Name = "Public Web Application",
Protocol = "openid-connect", Protocol = "openid-connect",
Enabled = true, Enabled = true,
BaseUrl = publicWebRootUrl, BaseUrl = publicWebRootUrl,
RedirectUris = new List<string> RedirectUris = new List<string>
{ {
$"{publicWebRootUrl.TrimEnd('/')}/signin-oidc" $"{publicWebRootUrl.TrimEnd('/')}/signin-oidc"
}, },
FrontChannelLogout = true, FrontChannelLogout = true,
PublicClient = true PublicClient = true,
ImplicitFlowEnabled = true // for hybrid flow
}; };
publicWebClient.Attributes = new Dictionary<string, object> publicWebClient.Attributes = new Dictionary<string, object>
{ {
@ -211,7 +245,7 @@ public class KeyCloakDataSeeder : IDataSeedContributor, ITransientDependency
}; };
await _keycloakClient.CreateClientAsync(_keycloakOptions.RealmName, publicWebClient); await _keycloakClient.CreateClientAsync(_keycloakOptions.RealmName, publicWebClient);
await AddOptionalClientScopesAsync( await AddOptionalClientScopesAsync(
"PublicWeb", "PublicWeb",
new List<string> new List<string>

Loading…
Cancel
Save