From 0da662534451c81baed90403c091e642e263de53 Mon Sep 17 00:00:00 2001 From: Galip Tolga Erdem Date: Wed, 23 Nov 2022 02:23:22 -0500 Subject: [PATCH] Permission check problem when client_credential is invoked --- .../EShopOnAbpPublicWebModule.cs | 2 +- .../src/EShopOnAbp.PublicWeb/appsettings.json | 3 +- .../IdentityServiceController.cs | 42 +++++++++++++++++++ .../KeycloakDataSeeder.cs | 5 ++- tye.yaml | 16 +++---- 5 files changed, 56 insertions(+), 12 deletions(-) create mode 100644 services/identity/src/EShopOnAbp.IdentityService.HttpApi/IdentityServiceController.cs diff --git a/apps/public-web/src/EShopOnAbp.PublicWeb/EShopOnAbpPublicWebModule.cs b/apps/public-web/src/EShopOnAbp.PublicWeb/EShopOnAbpPublicWebModule.cs index fa85989a..5730a51e 100644 --- a/apps/public-web/src/EShopOnAbp.PublicWeb/EShopOnAbpPublicWebModule.cs +++ b/apps/public-web/src/EShopOnAbp.PublicWeb/EShopOnAbpPublicWebModule.cs @@ -144,7 +144,7 @@ public class EShopOnAbpPublicWebModule : AbpModule options.DefaultScheme = "Cookies"; options.DefaultChallengeScheme = "oidc"; }) - .AddCookie("Cookies", options => { options.ExpireTimeSpan = TimeSpan.FromDays(365); }) + .AddCookie("Cookies") .AddAbpOpenIdConnect("oidc", options => { options.Authority = configuration["AuthServer:Authority"]; diff --git a/apps/public-web/src/EShopOnAbp.PublicWeb/appsettings.json b/apps/public-web/src/EShopOnAbp.PublicWeb/appsettings.json index dd89b1f3..f94d61a3 100644 --- a/apps/public-web/src/EShopOnAbp.PublicWeb/appsettings.json +++ b/apps/public-web/src/EShopOnAbp.PublicWeb/appsettings.json @@ -12,7 +12,8 @@ "AllowedHosts": "*", "RemoteServices": { "Default": { - "BaseUrl": "https://localhost:44373/" + "BaseUrl": "https://localhost:44373/", + "UseCurrentAccessToken": "false" } }, "StringEncryption": { diff --git a/services/identity/src/EShopOnAbp.IdentityService.HttpApi/IdentityServiceController.cs b/services/identity/src/EShopOnAbp.IdentityService.HttpApi/IdentityServiceController.cs new file mode 100644 index 00000000..8c92f7f6 --- /dev/null +++ b/services/identity/src/EShopOnAbp.IdentityService.HttpApi/IdentityServiceController.cs @@ -0,0 +1,42 @@ +using System; +using System.Threading.Tasks; +using Microsoft.AspNetCore.Authorization; +using Microsoft.AspNetCore.Http; +using Volo.Abp.Authorization.Permissions; +using Volo.Abp.DependencyInjection; +using Volo.Abp.Identity; +using Volo.Abp.Users; + +namespace EShopOnAbp.IdentityService; + +[Dependency(ReplaceServices = true)] +[ExposeServices(typeof(IdentityUserLookupController), IncludeSelf = true)] +public class IdentityServiceController : IdentityUserLookupController +{ + private readonly IHttpContextAccessor _httpContextAccessor; + private readonly IPermissionDefinitionManager _permissionDefinitionManager; + private readonly IPermissionChecker _permissionChecker; + private readonly IAuthorizationService _authorizationService; + public IdentityServiceController( + IIdentityUserLookupAppService lookupAppService, + IHttpContextAccessor httpContextAccessor, + IAuthorizationService authorizationService, + IPermissionDefinitionManager permissionDefinitionManager, IPermissionChecker permissionChecker) : base(lookupAppService) + { + _httpContextAccessor = httpContextAccessor; + _authorizationService = authorizationService; + _permissionDefinitionManager = permissionDefinitionManager; + _permissionChecker = permissionChecker; + } + + public override async Task FindByIdAsync(Guid id) + { + var permissions = _permissionDefinitionManager.GetPermissions(); + + var isGranted = await _permissionChecker.IsGrantedAsync(IdentityPermissions.UserLookup.Default); + + var result = await _authorizationService.IsGrantedAnyAsync("AbpIdentity.UserLookup"); + var httpContext = _httpContextAccessor.HttpContext; + return await base.FindByIdAsync(id); + } +} \ No newline at end of file diff --git a/shared/EShopOnAbp.Keycloak.DbMigrator/KeycloakDataSeeder.cs b/shared/EShopOnAbp.Keycloak.DbMigrator/KeycloakDataSeeder.cs index dbb0af1a..26eb5439 100644 --- a/shared/EShopOnAbp.Keycloak.DbMigrator/KeycloakDataSeeder.cs +++ b/shared/EShopOnAbp.Keycloak.DbMigrator/KeycloakDataSeeder.cs @@ -142,7 +142,7 @@ public class KeyCloakDataSeeder : IDataSeedContributor, ITransientDependency administrationClient = new Client() { ClientId = "EShopOnAbp_AdministrationService", - Name = "Cmskit microservice client", + Name = "Administration service client", Protocol = "openid-connect", PublicClient = false, ImplicitFlowEnabled = false, @@ -193,7 +193,8 @@ public class KeyCloakDataSeeder : IDataSeedContributor, ITransientDependency cmsKitClient.Attributes = new Dictionary() { { "oauth2.device.authorization.grant.enabled", false }, - { "oidc.ciba.grant.enabled", false } + { "oidc.ciba.grant.enabled", false }, + { "client_credentials.use_refresh_token", false } }; } await _keycloakClient.CreateClientAsync(_keycloakOptions.RealmName, cmsKitClient); diff --git a/tye.yaml b/tye.yaml index de0f4014..3aca4c42 100644 --- a/tye.yaml +++ b/tye.yaml @@ -9,14 +9,14 @@ services: # - Kestrel__Certificates__Default__Path=../../../../etc/dev-cert/localhost.pfx # - Kestrel__Certificates__Default__Password=8b6039b6-c67a-448b-977b-0ce6d3fcfd49 -- name: identity-service - project: services/identity/src/EShopOnAbp.IdentityService.HttpApi.Host/EShopOnAbp.IdentityService.HttpApi.Host.csproj - bindings: - - protocol: https - port: 44351 - env: - - Kestrel__Certificates__Default__Path=../../../../etc/dev-cert/localhost.pfx - - Kestrel__Certificates__Default__Password=8b6039b6-c67a-448b-977b-0ce6d3fcfd49 +# - name: identity-service +# project: services/identity/src/EShopOnAbp.IdentityService.HttpApi.Host/EShopOnAbp.IdentityService.HttpApi.Host.csproj +# bindings: +# - protocol: https +# port: 44351 +# env: +# - Kestrel__Certificates__Default__Path=../../../../etc/dev-cert/localhost.pfx +# - Kestrel__Certificates__Default__Password=8b6039b6-c67a-448b-977b-0ce6d3fcfd49 - name: administration-service project: services/administration/src/EShopOnAbp.AdministrationService.HttpApi.Host/EShopOnAbp.AdministrationService.HttpApi.Host.csproj