diff --git a/src/samples/aspnet/Elsa.Samples.HttpEndpointSecurity/Endpoints/Tokens/Create.cs b/src/samples/aspnet/Elsa.Samples.HttpEndpointSecurity/Endpoints/Tokens/Create.cs index 62f299d46..15cf3d69f 100644 --- a/src/samples/aspnet/Elsa.Samples.HttpEndpointSecurity/Endpoints/Tokens/Create.cs +++ b/src/samples/aspnet/Elsa.Samples.HttpEndpointSecurity/Endpoints/Tokens/Create.cs @@ -13,7 +13,7 @@ namespace Elsa.Samples.HttpEndpointSecurity.Endpoints.Tokens [HttpPost] public IActionResult Handle(CreateTokenRequestModel model) { - var token = _tokenService.CreateToken(model.UserName, model.HasMagic); + var token = _tokenService.CreateToken(model.UserName, model.IsAdmin); return Ok(token); } } diff --git a/src/samples/aspnet/Elsa.Samples.HttpEndpointSecurity/Endpoints/Tokens/Models.cs b/src/samples/aspnet/Elsa.Samples.HttpEndpointSecurity/Endpoints/Tokens/Models.cs index b3e3c472a..536b016b5 100644 --- a/src/samples/aspnet/Elsa.Samples.HttpEndpointSecurity/Endpoints/Tokens/Models.cs +++ b/src/samples/aspnet/Elsa.Samples.HttpEndpointSecurity/Endpoints/Tokens/Models.cs @@ -1,4 +1,4 @@ namespace Elsa.Samples.HttpEndpointSecurity.Endpoints.Tokens { - public record CreateTokenRequestModel(string UserName, bool HasMagic); + public record CreateTokenRequestModel(string UserName, bool IsAdmin); } \ No newline at end of file diff --git a/src/samples/aspnet/Elsa.Samples.HttpEndpointSecurity/Services/ITokenService.cs b/src/samples/aspnet/Elsa.Samples.HttpEndpointSecurity/Services/ITokenService.cs index 205ffe3cb..fdd373354 100644 --- a/src/samples/aspnet/Elsa.Samples.HttpEndpointSecurity/Services/ITokenService.cs +++ b/src/samples/aspnet/Elsa.Samples.HttpEndpointSecurity/Services/ITokenService.cs @@ -2,7 +2,7 @@ { public interface ITokenService { - string CreateToken(string userName, bool hasMagic); + string CreateToken(string userName, bool isAdmin); bool ValidateToken(string token); } } diff --git a/src/samples/aspnet/Elsa.Samples.HttpEndpointSecurity/Services/TokenService.cs b/src/samples/aspnet/Elsa.Samples.HttpEndpointSecurity/Services/TokenService.cs index 54e5bf20e..8f02bff1d 100644 --- a/src/samples/aspnet/Elsa.Samples.HttpEndpointSecurity/Services/TokenService.cs +++ b/src/samples/aspnet/Elsa.Samples.HttpEndpointSecurity/Services/TokenService.cs @@ -18,7 +18,7 @@ namespace Elsa.Samples.HttpEndpointSecurity.Services _options = options.Value; } - public string CreateToken(string userName, bool hasMagic) + public string CreateToken(string userName, bool isAdmin) { var claims = new List() { @@ -26,8 +26,8 @@ namespace Elsa.Samples.HttpEndpointSecurity.Services new(JwtRegisteredClaimNames.Jti, Guid.NewGuid().ToString()) }; - if (hasMagic) - claims.Add(new Claim("has-magic", "true")); + if (isAdmin) + claims.Add(new Claim("is-admin", "true")); var securityKey = new SymmetricSecurityKey(Encoding.UTF8.GetBytes(_options.SecretKey)); var credentials = new SigningCredentials(securityKey, SecurityAlgorithms.HmacSha256); diff --git a/src/samples/aspnet/Elsa.Samples.HttpEndpointSecurity/Startup.cs b/src/samples/aspnet/Elsa.Samples.HttpEndpointSecurity/Startup.cs index eb9a1a4b1..ac63f5844 100644 --- a/src/samples/aspnet/Elsa.Samples.HttpEndpointSecurity/Startup.cs +++ b/src/samples/aspnet/Elsa.Samples.HttpEndpointSecurity/Startup.cs @@ -53,8 +53,8 @@ namespace Elsa.Samples.HttpEndpointSecurity // Add a custom policy. services .AddAuthorization(auth => auth - .AddPolicy("HasMagic", policy => policy - .RequireClaim("has-magic", "true"))); + .AddPolicy("IsAdmin", policy => policy + .RequireClaim("is-admin", "true"))); services.Configure(options => Configuration.GetSection("Jwt").Bind(options)); diff --git a/src/samples/aspnet/Elsa.Samples.HttpEndpointSecurity/Workflows/SecureHelloWorkflow.cs b/src/samples/aspnet/Elsa.Samples.HttpEndpointSecurity/Workflows/SecureHelloWorkflow.cs index 2becf7618..dbbac4c73 100644 --- a/src/samples/aspnet/Elsa.Samples.HttpEndpointSecurity/Workflows/SecureHelloWorkflow.cs +++ b/src/samples/aspnet/Elsa.Samples.HttpEndpointSecurity/Workflows/SecureHelloWorkflow.cs @@ -14,7 +14,7 @@ namespace Elsa.Samples.HttpEndpointSecurity.Workflows .WithPath("/safe-hello") .WithMethod("GET") .WithAuthorize() - .WithPolicy("HasMagic")) + .WithPolicy("IsAdmin")) .WriteHttpResponse(setup => setup.WithStatusCode(HttpStatusCode.OK) .WithContent(context => { diff --git a/src/samples/aspnet/Elsa.Samples.HttpEndpointSecurity/http-requests.http b/src/samples/aspnet/Elsa.Samples.HttpEndpointSecurity/http-requests.http index b33f9ff9a..973d920dd 100644 --- a/src/samples/aspnet/Elsa.Samples.HttpEndpointSecurity/http-requests.http +++ b/src/samples/aspnet/Elsa.Samples.HttpEndpointSecurity/http-requests.http @@ -3,7 +3,7 @@ Content-Type: application/json { "userName": "Jason", - "hasMagic": false + "isAdmin": false } ### @@ -13,19 +13,19 @@ Content-Type: application/json { "userName": "Janet", - "hasMagic": true + "isAdmin": true } ### -# Jason does not have magic. +# Jason is not an admin. GET https://localhost:5001/workflows/safe-hello -Authorization: Bearer eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiJKYXNvbiIsImp0aSI6IjU3ZDUzOGE4LWQwNmYtNDg2Zi05MzAzLTMyODIxMmZlOWI4MCIsImV4cCI6MTY2MDM5NDg3NSwiaXNzIjoieW91ci1pZGVudGl0eS1zZXJ2ZXIiLCJhdWQiOiJ5b3VyLWFwaS1zZXJ2ZXIifQ.-6mjl-AMXLVSKrM7ofySNbGdf7YgvUmWILloAXB56q8 +Authorization: Bearer eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiJKYXNvbiIsImp0aSI6IjdjNzc5ODFiLWM1MWItNDU1Yi1iMzYzLWQyODQ2ZTE2NGZmMyIsImV4cCI6MTY2MDg5NjI2OCwiaXNzIjoieW91ci1pZGVudGl0eS1zZXJ2ZXIiLCJhdWQiOiJ5b3VyLWFwaS1zZXJ2ZXIifQ.n4BdO5MXZhrxQYBCyah_6MEzGg9VIqYHs1aNASS--gg ### -# Janet does have magic. +# Janet is an admin. GET https://localhost:5001/workflows/safe-hello -Authorization: Bearer eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiJKYW5ldCIsImp0aSI6IjNhMmNlZDg5LWQzYWMtNGQ5NC04YzQzLTU2OWZhZmE1YjYwMCIsImhhcy1tYWdpYyI6InRydWUiLCJleHAiOjE2NjAzOTUyNTksImlzcyI6InlvdXItaWRlbnRpdHktc2VydmVyIiwiYXVkIjoieW91ci1hcGktc2VydmVyIn0.bdBXGdqmiWr5mLcgAvjiKVNxcBgr5w63TJ0OLwZ3kf4 +Authorization: Bearer eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiJKYW5ldCIsImp0aSI6IjNkM2Y4ZjFiLTM3MGUtNGY2Yy05NTQ0LTQ1YWM1OTVmZjljMSIsImlzLWFkbWluIjoidHJ1ZSIsImV4cCI6MTY2MDg5NjI5NSwiaXNzIjoieW91ci1pZGVudGl0eS1zZXJ2ZXIiLCJhdWQiOiJ5b3VyLWFwaS1zZXJ2ZXIifQ.Jb_TVHIj_v2yR5CdImGXdzYUt2BSsPMNFXtF_ouMUzk ###