Update sample

This commit is contained in:
Sipke Schoorstra 2021-08-19 14:45:45 +02:00
parent 87132d49c5
commit 9112459d0c
7 changed files with 15 additions and 15 deletions

View file

@ -13,7 +13,7 @@ namespace Elsa.Samples.HttpEndpointSecurity.Endpoints.Tokens
[HttpPost]
public IActionResult Handle(CreateTokenRequestModel model)
{
var token = _tokenService.CreateToken(model.UserName, model.HasMagic);
var token = _tokenService.CreateToken(model.UserName, model.IsAdmin);
return Ok(token);
}
}

View file

@ -1,4 +1,4 @@
namespace Elsa.Samples.HttpEndpointSecurity.Endpoints.Tokens
{
public record CreateTokenRequestModel(string UserName, bool HasMagic);
public record CreateTokenRequestModel(string UserName, bool IsAdmin);
}

View file

@ -2,7 +2,7 @@
{
public interface ITokenService
{
string CreateToken(string userName, bool hasMagic);
string CreateToken(string userName, bool isAdmin);
bool ValidateToken(string token);
}
}

View file

@ -18,7 +18,7 @@ namespace Elsa.Samples.HttpEndpointSecurity.Services
_options = options.Value;
}
public string CreateToken(string userName, bool hasMagic)
public string CreateToken(string userName, bool isAdmin)
{
var claims = new List<Claim>()
{
@ -26,8 +26,8 @@ namespace Elsa.Samples.HttpEndpointSecurity.Services
new(JwtRegisteredClaimNames.Jti, Guid.NewGuid().ToString())
};
if (hasMagic)
claims.Add(new Claim("has-magic", "true"));
if (isAdmin)
claims.Add(new Claim("is-admin", "true"));
var securityKey = new SymmetricSecurityKey(Encoding.UTF8.GetBytes(_options.SecretKey));
var credentials = new SigningCredentials(securityKey, SecurityAlgorithms.HmacSha256);

View file

@ -53,8 +53,8 @@ namespace Elsa.Samples.HttpEndpointSecurity
// Add a custom policy.
services
.AddAuthorization(auth => auth
.AddPolicy("HasMagic", policy => policy
.RequireClaim("has-magic", "true")));
.AddPolicy("IsAdmin", policy => policy
.RequireClaim("is-admin", "true")));
services.Configure<JwtOptions>(options => Configuration.GetSection("Jwt").Bind(options));

View file

@ -14,7 +14,7 @@ namespace Elsa.Samples.HttpEndpointSecurity.Workflows
.WithPath("/safe-hello")
.WithMethod("GET")
.WithAuthorize()
.WithPolicy("HasMagic"))
.WithPolicy("IsAdmin"))
.WriteHttpResponse(setup => setup.WithStatusCode(HttpStatusCode.OK)
.WithContent(context =>
{

View file

@ -3,7 +3,7 @@ Content-Type: application/json
{
"userName": "Jason",
"hasMagic": false
"isAdmin": false
}
###
@ -13,19 +13,19 @@ Content-Type: application/json
{
"userName": "Janet",
"hasMagic": true
"isAdmin": true
}
###
# Jason does not have magic.
# Jason is not an admin.
GET https://localhost:5001/workflows/safe-hello
Authorization: Bearer eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiJKYXNvbiIsImp0aSI6IjU3ZDUzOGE4LWQwNmYtNDg2Zi05MzAzLTMyODIxMmZlOWI4MCIsImV4cCI6MTY2MDM5NDg3NSwiaXNzIjoieW91ci1pZGVudGl0eS1zZXJ2ZXIiLCJhdWQiOiJ5b3VyLWFwaS1zZXJ2ZXIifQ.-6mjl-AMXLVSKrM7ofySNbGdf7YgvUmWILloAXB56q8
Authorization: Bearer eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiJKYXNvbiIsImp0aSI6IjdjNzc5ODFiLWM1MWItNDU1Yi1iMzYzLWQyODQ2ZTE2NGZmMyIsImV4cCI6MTY2MDg5NjI2OCwiaXNzIjoieW91ci1pZGVudGl0eS1zZXJ2ZXIiLCJhdWQiOiJ5b3VyLWFwaS1zZXJ2ZXIifQ.n4BdO5MXZhrxQYBCyah_6MEzGg9VIqYHs1aNASS--gg
###
# Janet does have magic.
# Janet is an admin.
GET https://localhost:5001/workflows/safe-hello
Authorization: Bearer eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiJKYW5ldCIsImp0aSI6IjNhMmNlZDg5LWQzYWMtNGQ5NC04YzQzLTU2OWZhZmE1YjYwMCIsImhhcy1tYWdpYyI6InRydWUiLCJleHAiOjE2NjAzOTUyNTksImlzcyI6InlvdXItaWRlbnRpdHktc2VydmVyIiwiYXVkIjoieW91ci1hcGktc2VydmVyIn0.bdBXGdqmiWr5mLcgAvjiKVNxcBgr5w63TJ0OLwZ3kf4
Authorization: Bearer eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiJKYW5ldCIsImp0aSI6IjNkM2Y4ZjFiLTM3MGUtNGY2Yy05NTQ0LTQ1YWM1OTVmZjljMSIsImlzLWFkbWluIjoidHJ1ZSIsImV4cCI6MTY2MDg5NjI5NSwiaXNzIjoieW91ci1pZGVudGl0eS1zZXJ2ZXIiLCJhdWQiOiJ5b3VyLWFwaS1zZXJ2ZXIifQ.Jb_TVHIj_v2yR5CdImGXdzYUt2BSsPMNFXtF_ouMUzk
###