Update permissions

This commit is contained in:
Sipke Schoorstra 2022-08-29 11:36:15 +02:00
parent 7f839555cf
commit 4a5dba3736
28 changed files with 74 additions and 42 deletions

View file

@ -1,4 +1,3 @@
using System.Globalization;
using System.IdentityModel.Tokens.Jwt;
using System.Security.Claims;
using Elsa;

View file

@ -25,6 +25,17 @@ public class ElsaEndpoint<TRequest, TResponse> : Endpoint<TRequest, TResponse> w
}
}
public class ElsaEndpoint<TRequest, TResponse, TMapper> : Endpoint<TRequest, TResponse, TMapper> where TRequest : notnull, new() where TResponse : notnull where TMapper : IMapper, new()
{
protected void ConfigurePermissions(params string[] permissions)
{
if (!EndpointSecurityOptions.SecurityIsEnabled)
AllowAnonymous();
else
Permissions((new[] { PermissionNames.All }).Concat(permissions).ToArray());
}
}
public class ElsaEndpoint<TRequest> : Endpoint<TRequest> where TRequest : notnull, new()
{
protected void ConfigurePermissions(params string[] permissions)

View file

@ -1,4 +1,3 @@
using System.Diagnostics.CodeAnalysis;
using System.Text.Json;
using Elsa.Abstractions;
using Elsa.ActivityDefinitions.Entities;
@ -8,7 +7,6 @@ using Elsa.Models;
using Elsa.Workflows.Core.Serialization;
using Elsa.Workflows.Core.Services;
using Elsa.Workflows.Management.Mappers;
using FastEndpoints;
namespace Elsa.ActivityDefinitions.Endpoints.ActivityDefinitions.Get;

View file

@ -2,7 +2,6 @@ using Elsa.Abstractions;
using Elsa.ActivityDefinitions.Models;
using Elsa.ActivityDefinitions.Services;
using Elsa.Models;
using FastEndpoints;
namespace Elsa.ActivityDefinitions.Endpoints.ActivityDefinitions.List;

View file

@ -6,7 +6,6 @@ using Elsa.Workflows.Core.Activities.Flowchart.Activities;
using Elsa.Workflows.Core.Serialization;
using Elsa.Workflows.Management.Mappers;
using Elsa.Workflows.Management.Models;
using FastEndpoints;
namespace Elsa.ActivityDefinitions.Endpoints.ActivityDefinitions.Post;

View file

@ -4,7 +4,6 @@ using System.Threading.Tasks;
using Elsa.Abstractions;
using Elsa.Workflows.Core.Services;
using Elsa.Workflows.Management.Services;
using FastEndpoints;
namespace Elsa.Workflows.Api.Endpoints.ActivityDescriptors.List;

View file

@ -1,6 +1,7 @@
using System.Linq;
using System.Threading;
using System.Threading.Tasks;
using Elsa.Abstractions;
using Elsa.Workflows.Core.Activities;
using Elsa.Workflows.Core.Helpers;
using Elsa.Workflows.Core.Models;
@ -11,7 +12,7 @@ using FastEndpoints;
namespace Elsa.Workflows.Api.Endpoints.Events.Trigger;
public class Trigger : Endpoint<Request, Response>
public class Trigger : ElsaEndpoint<Request, Response>
{
private readonly IHasher _hasher;
private readonly IStimulusInterpreter _stimulusInterpreter;
@ -27,9 +28,7 @@ public class Trigger : Endpoint<Request, Response>
public override void Configure()
{
Post("/events/{eventName}/trigger");
Policies(Constants.PolicyName);
Permissions("all", "trigger:event");
Roles("Admin");
ConfigurePermissions("trigger:event");
}
public override async Task HandleAsync(Request request, CancellationToken cancellationToken)

View file

@ -1,12 +1,13 @@
using System.Linq;
using System.Threading;
using System.Threading.Tasks;
using Elsa.Abstractions;
using Elsa.Workflows.Core.Services;
using FastEndpoints;
namespace Elsa.Workflows.Api.Endpoints.StorageDrivers.List;
public class List : EndpointWithoutRequest<Response>
public class List : ElsaEndpointWithoutRequest<Response>
{
private readonly IStorageDriverManager _registry;
@ -18,8 +19,7 @@ public class List : EndpointWithoutRequest<Response>
public override void Configure()
{
Get("/descriptors/storage-drivers");
Policies(Constants.PolicyName);
Permissions("all", "read:storage-drivers");
ConfigurePermissions("read:storage-drivers");
}
public override Task<Response> ExecuteAsync(CancellationToken ct)

View file

@ -1,12 +1,13 @@
using System.Threading;
using System.Threading.Tasks;
using Elsa.Abstractions;
using Elsa.Workflows.Core.Serialization;
using Elsa.Workflows.Management.Services;
using FastEndpoints;
namespace Elsa.Workflows.Api.Endpoints.WorkflowDefinitions.BulkDelete;
public class BulkDelete : Endpoint<Request, Response>
public class BulkDelete : ElsaEndpoint<Request, Response>
{
private readonly IWorkflowDefinitionManager _workflowDefinitionManager;
@ -18,6 +19,7 @@ public class BulkDelete : Endpoint<Request, Response>
public override void Configure()
{
Post("/bulk-actions/delete/workflow-definitions/by-definition-id");
ConfigurePermissions("delete:workflow-definitions");
}
public override async Task<Response> ExecuteAsync(Request request, CancellationToken cancellationToken)

View file

@ -1,6 +1,7 @@
using System.Collections.Generic;
using System.Threading;
using System.Threading.Tasks;
using Elsa.Abstractions;
using Elsa.Models;
using Elsa.Workflows.Core.Serialization;
using Elsa.Workflows.Management.Services;
@ -9,7 +10,7 @@ using FastEndpoints;
namespace Elsa.Workflows.Api.Endpoints.WorkflowDefinitions.BulkPublish;
public class BulkPublish : Endpoint<Request, Response>
public class BulkPublish : ElsaEndpoint<Request, Response>
{
private readonly IWorkflowDefinitionStore _store;
private readonly IWorkflowDefinitionPublisher _workflowDefinitionPublisher;
@ -23,6 +24,7 @@ public class BulkPublish : Endpoint<Request, Response>
public override void Configure()
{
Post("/bulk-actions/publish/workflow-definitions/by-definition-id");
ConfigurePermissions("publish:workflow-definitions");
}
public override async Task<Response> ExecuteAsync(Request request, CancellationToken cancellationToken)

View file

@ -1,6 +1,7 @@
using System.Collections.Generic;
using System.Threading;
using System.Threading.Tasks;
using Elsa.Abstractions;
using Elsa.Models;
using Elsa.Workflows.Management.Services;
using Elsa.Workflows.Persistence.Services;
@ -8,7 +9,7 @@ using FastEndpoints;
namespace Elsa.Workflows.Api.Endpoints.WorkflowDefinitions.BulkRetract;
public class BulkRetract : Endpoint<Request, Response>
public class BulkRetract : ElsaEndpoint<Request, Response>
{
private readonly IWorkflowDefinitionStore _store;
private readonly IWorkflowDefinitionPublisher _workflowDefinitionPublisher;
@ -22,6 +23,7 @@ public class BulkRetract : Endpoint<Request, Response>
public override void Configure()
{
Post("/bulk-actions/retract/workflow-definitions/by-definition-id");
ConfigurePermissions("retract:workflow-definitions");
}
public override async Task<Response> ExecuteAsync(Request request, CancellationToken cancellationToken)

View file

@ -1,12 +1,12 @@
using System.Threading;
using System.Threading.Tasks;
using Elsa.Abstractions;
using Elsa.Workflows.Management.Services;
using FastEndpoints;
using Microsoft.AspNetCore.Mvc;
namespace Elsa.Workflows.Api.Endpoints.WorkflowDefinitions.Delete;
public class Delete : Endpoint<Request>
public class Delete : ElsaEndpoint<Request>
{
private readonly IWorkflowDefinitionManager _workflowDefinitionManager;
@ -18,6 +18,7 @@ public class Delete : Endpoint<Request>
public override void Configure()
{
Delete("/workflow-definitions/{definitionId}");
ConfigurePermissions("delete:workflow-definitions");
}
public override async Task HandleAsync(Request request, CancellationToken cancellationToken)

View file

@ -1,5 +1,6 @@
using System.Threading;
using System.Threading.Tasks;
using Elsa.Abstractions;
using Elsa.Models;
using Elsa.Workflows.Persistence.Services;
using Elsa.Workflows.Runtime.Models;
@ -8,7 +9,7 @@ using FastEndpoints;
namespace Elsa.Workflows.Api.Endpoints.WorkflowDefinitions.Dispatch;
public class Endpoint : Endpoint<Request, Response>
public class Endpoint : ElsaEndpoint<Request, Response>
{
private readonly IWorkflowDefinitionStore _store;
private readonly IWorkflowDispatcher _workflowDispatcher;
@ -22,6 +23,7 @@ public class Endpoint : Endpoint<Request, Response>
public override void Configure()
{
Post("/workflow-definitions/{definitionId}/dispatch");
ConfigurePermissions("exec:workflow-definitions");
}
public override async Task HandleAsync(Request request, CancellationToken cancellationToken)

View file

@ -1,5 +1,6 @@
using System.Threading;
using System.Threading.Tasks;
using Elsa.Abstractions;
using Elsa.Models;
using Elsa.Workflows.Persistence.Services;
using Elsa.Workflows.Runtime.Models;
@ -8,7 +9,7 @@ using FastEndpoints;
namespace Elsa.Workflows.Api.Endpoints.WorkflowDefinitions.Execute;
public class Execute : Endpoint<Request, Response>
public class Execute : ElsaEndpoint<Request, Response>
{
private readonly IWorkflowDefinitionStore _store;
private readonly IWorkflowInvoker _workflowInvoker;
@ -22,6 +23,7 @@ public class Execute : Endpoint<Request, Response>
public override void Configure()
{
Post("/workflow-definitions/{definitionId}/execute");
ConfigurePermissions("exec:workflow-definitions");
}
public override async Task HandleAsync(Request request, CancellationToken cancellationToken)

View file

@ -2,6 +2,7 @@ using System.Linq;
using System.Text.Json;
using System.Threading;
using System.Threading.Tasks;
using Elsa.Abstractions;
using Elsa.Models;
using Elsa.Workflows.Api.Models;
using Elsa.Workflows.Core.Serialization;
@ -13,7 +14,7 @@ using Humanizer;
namespace Elsa.Workflows.Api.Endpoints.WorkflowDefinitions.Export;
public class Export : Endpoint<Request>
public class Export : ElsaEndpoint<Request>
{
private readonly IWorkflowDefinitionStore _store;
private readonly IWorkflowDefinitionService _workflowDefinitionService;
@ -35,6 +36,7 @@ public class Export : Endpoint<Request>
public override void Configure()
{
Get("/workflow-definitions/{definitionId}/export");
ConfigurePermissions("read:workflow-definitions");
}
public override async Task HandleAsync(Request request, CancellationToken cancellationToken)

View file

@ -1,5 +1,6 @@
using System.Threading;
using System.Threading.Tasks;
using Elsa.Abstractions;
using Elsa.Models;
using Elsa.Workflows.Api.Mappers;
using Elsa.Workflows.Api.Models;
@ -8,7 +9,7 @@ using FastEndpoints;
namespace Elsa.Workflows.Api.Endpoints.WorkflowDefinitions.Get;
public class Get : Endpoint<Request, WorkflowDefinitionResponse, WorkflowDefinitionMapper>
public class Get : ElsaEndpoint<Request, WorkflowDefinitionResponse, WorkflowDefinitionMapper>
{
private readonly IWorkflowDefinitionStore _store;
@ -20,6 +21,7 @@ public class Get : Endpoint<Request, WorkflowDefinitionResponse, WorkflowDefinit
public override void Configure()
{
Get("/workflow-definitions/{definitionId}");
ConfigurePermissions("read:workflow-definitions");
}
public override async Task HandleAsync(Request request, CancellationToken cancellationToken)

View file

@ -2,6 +2,7 @@ using System.Linq;
using System.Text.Json;
using System.Threading;
using System.Threading.Tasks;
using Elsa.Abstractions;
using Elsa.Workflows.Api.Models;
using Elsa.Workflows.Core.Serialization;
using Elsa.Workflows.Management.Mappers;
@ -12,7 +13,7 @@ using FastEndpoints;
namespace Elsa.Workflows.Api.Endpoints.WorkflowDefinitions.Import;
public class Import : Endpoint<WorkflowDefinitionRequest, WorkflowDefinitionResponse>
public class Import : ElsaEndpoint<WorkflowDefinitionRequest, WorkflowDefinitionResponse>
{
private readonly SerializerOptionsProvider _serializerOptionsProvider;
private readonly IWorkflowDefinitionPublisher _workflowDefinitionPublisher;
@ -34,6 +35,7 @@ public class Import : Endpoint<WorkflowDefinitionRequest, WorkflowDefinitionResp
public override void Configure()
{
Post("workflow-definitions/import", "workflow-definitions/{definitionId}/import");
ConfigurePermissions("write:workflow-definitions");
}
public override async Task HandleAsync(WorkflowDefinitionRequest request, CancellationToken cancellationToken)

View file

@ -2,6 +2,7 @@ using System;
using System.Linq;
using System.Threading;
using System.Threading.Tasks;
using Elsa.Abstractions;
using Elsa.Models;
using Elsa.Workflows.Persistence.Services;
using FastEndpoints;
@ -9,7 +10,7 @@ using Open.Linq.AsyncExtensions;
namespace Elsa.Workflows.Api.Endpoints.WorkflowDefinitions.List;
public class List : Endpoint<Request, Response>
public class List : ElsaEndpoint<Request, Response>
{
private readonly IWorkflowDefinitionStore _store;
@ -21,6 +22,7 @@ public class List : Endpoint<Request, Response>
public override void Configure()
{
Get("/workflow-definitions");
ConfigurePermissions("read:workflow-definitions");
}
public override async Task<Response> ExecuteAsync(Request request, CancellationToken cancellationToken)

View file

@ -3,6 +3,7 @@ using System.Linq;
using System.Text.Json;
using System.Threading;
using System.Threading.Tasks;
using Elsa.Abstractions;
using Elsa.Workflows.Api.Models;
using Elsa.Workflows.Core.Activities;
using Elsa.Workflows.Core.Serialization;
@ -14,7 +15,7 @@ using FastEndpoints;
namespace Elsa.Workflows.Api.Endpoints.WorkflowDefinitions.Post;
public class Post : Endpoint<WorkflowDefinitionRequest, WorkflowDefinitionResponse>
public class Post : ElsaEndpoint<WorkflowDefinitionRequest, WorkflowDefinitionResponse>
{
private readonly SerializerOptionsProvider _serializerOptionsProvider;
private readonly IWorkflowDefinitionPublisher _workflowDefinitionPublisher;
@ -33,6 +34,7 @@ public class Post : Endpoint<WorkflowDefinitionRequest, WorkflowDefinitionRespon
public override void Configure()
{
Post("/workflow-definitions");
ConfigurePermissions("write:workflow-definitions");
}
public override async Task HandleAsync(WorkflowDefinitionRequest request, CancellationToken cancellationToken)

View file

@ -1,19 +1,16 @@
using System.Threading;
using System.Threading.Tasks;
using Elsa.Abstractions;
using Elsa.Models;
using Elsa.Workflows.Api.Mappers;
using Elsa.Workflows.Api.Models;
using Elsa.Workflows.Core.Serialization;
using Elsa.Workflows.Management.Services;
using Elsa.Workflows.Persistence.Entities;
using Elsa.Workflows.Persistence.Services;
using FastEndpoints;
using Microsoft.AspNetCore.Http;
using Microsoft.AspNetCore.Mvc;
namespace Elsa.Workflows.Api.Endpoints.WorkflowDefinitions.Publish;
public class Publish : Endpoint<Request, WorkflowDefinitionResponse, WorkflowDefinitionMapper>
public class Publish : ElsaEndpoint<Request, WorkflowDefinitionResponse, WorkflowDefinitionMapper>
{
private readonly IWorkflowDefinitionStore _store;
private readonly IWorkflowDefinitionPublisher _workflowDefinitionPublisher;
@ -27,6 +24,7 @@ public class Publish : Endpoint<Request, WorkflowDefinitionResponse, WorkflowDef
public override void Configure()
{
Post("/workflow-definitions/{definitionId}/publish");
ConfigurePermissions("publish:workflow-definitions");
}
public override async Task HandleAsync(Request request, CancellationToken cancellationToken)

View file

@ -1,5 +1,6 @@
using System.Threading;
using System.Threading.Tasks;
using Elsa.Abstractions;
using Elsa.Models;
using Elsa.Workflows.Api.Mappers;
using Elsa.Workflows.Api.Models;
@ -9,7 +10,7 @@ using FastEndpoints;
namespace Elsa.Workflows.Api.Endpoints.WorkflowDefinitions.Retract;
public class Retract : Endpoint<Request, WorkflowDefinitionResponse, WorkflowDefinitionMapper>
public class Retract : ElsaEndpoint<Request, WorkflowDefinitionResponse, WorkflowDefinitionMapper>
{
private readonly IWorkflowDefinitionStore _store;
private readonly IWorkflowDefinitionPublisher _workflowDefinitionPublisher;
@ -23,6 +24,7 @@ public class Retract : Endpoint<Request, WorkflowDefinitionResponse, WorkflowDef
public override void Configure()
{
Post("/workflow-definitions/{definitionId}/retract");
ConfigurePermissions("retract:workflow-definitions");
}
public override async Task HandleAsync(Request request, CancellationToken cancellationToken)

View file

@ -2,15 +2,17 @@ using System.Collections.Generic;
using System.Text.Json.Serialization;
using System.Threading;
using System.Threading.Tasks;
using Elsa.Abstractions;
using FastEndpoints;
namespace Elsa.Workflows.Api.Endpoints.WorkflowInstances.BulkCancel;
public class Endpoint : Endpoint<Request, Response>
public class Endpoint : ElsaEndpoint<Request, Response>
{
public override void Configure()
{
Post("/bulk-actions/cancel/workflow-instances/by-id");
ConfigurePermissions("cancel:workflow-instances");
}
public override async Task<Response> ExecuteAsync(Request request, CancellationToken cancellationToken)

View file

@ -1,12 +1,12 @@
using System.Text.Json.Serialization;
using System.Threading;
using System.Threading.Tasks;
using Elsa.Abstractions;
using Elsa.Workflows.Persistence.Services;
using FastEndpoints;
namespace Elsa.Workflows.Api.Endpoints.WorkflowInstances.BulkDelete;
public class BulkDelete : Endpoint<Request, Response>
public class BulkDelete : ElsaEndpoint<Request, Response>
{
private readonly IWorkflowInstanceStore _store;
@ -18,6 +18,7 @@ public class BulkDelete : Endpoint<Request, Response>
public override void Configure()
{
Post("/bulk-actions/delete/workflow-instances/by-id");
ConfigurePermissions("delete:workflow-instances");
}
public override async Task<Response> ExecuteAsync(Request request, CancellationToken cancellationToken)

View file

@ -1,11 +1,12 @@
using System.Threading;
using System.Threading.Tasks;
using Elsa.Abstractions;
using Elsa.Workflows.Persistence.Services;
using FastEndpoints;
namespace Elsa.Workflows.Api.Endpoints.WorkflowInstances.Delete;
public class Delete : Endpoint<Request>
public class Delete : ElsaEndpoint<Request>
{
private readonly IWorkflowInstanceStore _store;
public Delete(IWorkflowInstanceStore store) => _store = store;
@ -13,6 +14,7 @@ public class Delete : Endpoint<Request>
public override void Configure()
{
Delete("/workflow-instances/{id}");
ConfigurePermissions("delete:workflow-instances");
}
public override async Task HandleAsync(Request request, CancellationToken cancellationToken)

View file

@ -1,11 +1,12 @@
using System.Threading;
using System.Threading.Tasks;
using Elsa.Abstractions;
using Elsa.Workflows.Persistence.Services;
using FastEndpoints;
namespace Elsa.Workflows.Api.Endpoints.WorkflowInstances.Get;
public class Get : Endpoint<Request, Response, WorkflowInstanceMapper>
public class Get : ElsaEndpoint<Request, Response, WorkflowInstanceMapper>
{
private readonly IWorkflowInstanceStore _store;
@ -17,6 +18,7 @@ public class Get : Endpoint<Request, Response, WorkflowInstanceMapper>
public override void Configure()
{
Get("/workflow-instances/{id}");
ConfigurePermissions("read:workflow-instances");
}
public override async Task HandleAsync(Request request, CancellationToken cancellationToken)

View file

@ -1,13 +1,14 @@
using System.Linq;
using System.Threading;
using System.Threading.Tasks;
using Elsa.Abstractions;
using Elsa.Models;
using Elsa.Workflows.Persistence.Services;
using FastEndpoints;
namespace Elsa.Workflows.Api.Endpoints.WorkflowInstances.Journal.Get;
public class Get : Endpoint<Request, Response>
public class Get : ElsaEndpoint<Request, Response>
{
private readonly IWorkflowExecutionLogStore _store;
@ -19,6 +20,7 @@ public class Get : Endpoint<Request, Response>
public override void Configure()
{
Get("/workflow-instances/{id}/journal");
ConfigurePermissions("read:workflow-instances");
}
public override async Task<Response> ExecuteAsync(Request request, CancellationToken cancellationToken)

View file

@ -1,16 +1,14 @@
using System.Threading;
using System.Threading.Tasks;
using Elsa.Abstractions;
using Elsa.Models;
using Elsa.Persistence.Common.Entities;
using Elsa.Workflows.Core.Models;
using Elsa.Workflows.Core.Serialization;
using Elsa.Workflows.Persistence.Services;
using FastEndpoints;
using Microsoft.AspNetCore.Mvc;
namespace Elsa.Workflows.Api.Endpoints.WorkflowInstances.List;
public class List : Endpoint<Request, Response>
public class List : ElsaEndpoint<Request, Response>
{
private readonly IWorkflowInstanceStore _store;
@ -22,6 +20,7 @@ public class List : Endpoint<Request, Response>
public override void Configure()
{
Get("/workflow-instances");
ConfigurePermissions("read:workflow-instances");
}
public override async Task<Response> ExecuteAsync(Request request, CancellationToken cancellationToken)

View file

@ -1,4 +1,3 @@
using System;
using System.Collections.Generic;
using Elsa.Workflows.Core.Services;
using Elsa.Workflows.Management.Models;