Browse Source

added configuration

pull/134/head
Galip Tolga Erdem 4 years ago
parent
commit
fdd9e23221
  1. 79
      apps/public-web/src/EShopOnAbp.PublicWeb/EShopOnAbpPublicWebModule.cs
  2. 8
      apps/public-web/src/EShopOnAbp.PublicWeb/appsettings.json
  3. 4
      etc/docker/docker-compose.infrastructure.override.yml
  4. 4
      services/administration/src/EShopOnAbp.AdministrationService.HttpApi.Host/appsettings.json

79
apps/public-web/src/EShopOnAbp.PublicWeb/EShopOnAbpPublicWebModule.cs

@ -141,27 +141,68 @@ public class EShopOnAbpPublicWebModule : AbpModule
.AddCookie("Cookies", options => { options.ExpireTimeSpan = TimeSpan.FromDays(365); }) .AddCookie("Cookies", options => { options.ExpireTimeSpan = TimeSpan.FromDays(365); })
.AddAbpOpenIdConnect("oidc", options => .AddAbpOpenIdConnect("oidc", options =>
{ {
options.Authority = configuration["AuthServer:Authority"]; /*
options.RequireHttpsMetadata = Convert.ToBoolean(configuration["AuthServer:RequireHttpsMetadata"]); * ASP.NET core uses the http://*:5000 and https://*:5001 ports for default communication with the OIDC middleware
options.ResponseType = OpenIdConnectResponseType.CodeIdToken; * The app requires load balancing services to work with :80 or :443
* These needs to be added to the keycloak client, in order for the redirect to work.
options.ClientId = configuration["AuthServer:ClientId"]; * If you however intend to use the app by itself then,
options.ClientSecret = configuration["AuthServer:ClientSecret"]; * Change the ports in launchsettings.json, but beware to also change the options.CallbackPath and options.SignedOutCallbackPath!
* Use LB services whenever possible, to reduce the config hazzle :)
options.SaveTokens = true; */
//Use default signin scheme
// options.SignInScheme = CookieAuthenticationDefaults.AuthenticationScheme;
//Keycloak server
options.Authority = configuration["Keycloak:ServerRealm"];
//Keycloak client ID
options.ClientId = configuration["Keycloak:ClientId"];
//Keycloak client secret
options.ClientSecret = configuration["Keycloak:ClientSecret"];
//Keycloak .wellknown config origin to fetch config
options.MetadataAddress = configuration["Keycloak:Metadata"];
//Require keycloak to use SSL
options.RequireHttpsMetadata = false;
options.GetClaimsFromUserInfoEndpoint = true; options.GetClaimsFromUserInfoEndpoint = true;
options.Scope.Add("openid");
options.Scope.Add("role"); options.Scope.Add("profile");
options.Scope.Add("email"); //Save the token
options.Scope.Add("phone"); options.SaveTokens = true;
options.Scope.Add("AccountService"); //Token response type, will sometimes need to be changed to IdToken, depending on config.
options.Scope.Add("AdministrationService"); options.ResponseType = OpenIdConnectResponseType.Code;
options.Scope.Add("BasketService"); //SameSite is needed for Chrome/Firefox, as they will give http error 500 back, if not set to unspecified.
options.Scope.Add("CatalogService"); // options.NonceCookie.SameSite = SameSiteMode.Unspecified;
options.Scope.Add("PaymentService"); // options.CorrelationCookie.SameSite = SameSiteMode.Unspecified;
options.Scope.Add("OrderingService"); //
options.Scope.Add("CmskitService"); // options.TokenValidationParameters = new TokenValidationParameters
// {
// NameClaimType = "name",
// RoleClaimType = ClaimTypes.Role,
// ValidateIssuer = true
// };
}); });
// .AddAbpOpenIdConnect("oidc", options =>
// {
// options.Authority = configuration["AuthServer:Authority"];
// options.RequireHttpsMetadata = Convert.ToBoolean(configuration["AuthServer:RequireHttpsMetadata"]);
// options.ResponseType = OpenIdConnectResponseType.CodeIdToken;
//
// options.ClientId = configuration["AuthServer:ClientId"];
// options.ClientSecret = configuration["AuthServer:ClientSecret"];
//
// options.SaveTokens = true;
// options.GetClaimsFromUserInfoEndpoint = true;
//
// options.Scope.Add("role");
// options.Scope.Add("email");
// options.Scope.Add("phone");
// options.Scope.Add("AccountService");
// options.Scope.Add("AdministrationService");
// options.Scope.Add("BasketService");
// options.Scope.Add("CatalogService");
// options.Scope.Add("PaymentService");
// options.Scope.Add("OrderingService");
// options.Scope.Add("CmskitService");
// });
if (Convert.ToBoolean(configuration["AuthServer:IsOnProd"])) if (Convert.ToBoolean(configuration["AuthServer:IsOnProd"]))
{ {
context.Services.Configure<OpenIdConnectOptions>("oidc", options => context.Services.Configure<OpenIdConnectOptions>("oidc", options =>

8
apps/public-web/src/EShopOnAbp.PublicWeb/appsettings.json

@ -43,6 +43,14 @@
"IsOnProd": "false", "IsOnProd": "false",
"MetaAddress": "https://localhost:44330" "MetaAddress": "https://localhost:44330"
}, },
"Keycloak": {
"ServerRealm": "http://localhost:8080/realms/master",
"Metadata": "http://localhost:8080/realms/master/.well-known/openid-configuration",
"ClientId": "PublicWeb",
"ClientSecret": "mPpj650ADqHwQ0g9qvwWNxCqQmefrGw7",
"TokenExchange": "http://localhost:8080/realms/master/protocol/openid-connect/token",
"Audience": "some-audience"
},
"ReverseProxy": { "ReverseProxy": {
"Routes": { "Routes": {
"route1" : { "route1" : {

4
etc/docker/docker-compose.infrastructure.override.yml

@ -30,7 +30,7 @@ services:
keycloak: keycloak:
ports: ports:
- "44320:8080" - "8080:8080"
environment: environment:
DB_VENDOR: postgres DB_VENDOR: postgres
DB_ADDR: "postgres-db" DB_ADDR: "postgres-db"
@ -41,5 +41,5 @@ services:
KEYCLOAK_ADMIN_PASSWORD: admin KEYCLOAK_ADMIN_PASSWORD: admin
KC_HEALTH_ENABLED: true KC_HEALTH_ENABLED: true
entrypoint: ["/opt/keycloak/bin/kc.sh", "start-dev"] entrypoint: ["/opt/keycloak/bin/kc.sh", "start-dev"]

4
services/administration/src/EShopOnAbp.AdministrationService.HttpApi.Host/appsettings.json

@ -4,8 +4,8 @@
"CorsOrigins": "https://localhost:44372,https://localhost:44373" "CorsOrigins": "https://localhost:44372,https://localhost:44373"
}, },
"AuthServer": { "AuthServer": {
"Authority": "https://localhost:44330", "Authority": "http://localhost:8080/realms/master",
"RequireHttpsMetadata": "true", "RequireHttpsMetadata": "false",
"SwaggerClientId": "WebGateway_Swagger", "SwaggerClientId": "WebGateway_Swagger",
"SwaggerClientSecret": "1q2w3e*" "SwaggerClientSecret": "1q2w3e*"
}, },

Loading…
Cancel
Save