Implement admin API key provider
This commit is contained in:
parent
a98ce86c09
commit
b02c644e64
|
|
@ -5,6 +5,7 @@ using Elsa.Features.Attributes;
|
|||
using Elsa.Features.Services;
|
||||
using Elsa.Identity.Providers;
|
||||
using Elsa.Requirements;
|
||||
using Microsoft.AspNetCore.Authentication;
|
||||
using Microsoft.AspNetCore.Authentication.JwtBearer;
|
||||
using Microsoft.AspNetCore.Authorization;
|
||||
using Microsoft.Extensions.DependencyInjection;
|
||||
|
|
@ -18,19 +19,42 @@ namespace Elsa.Identity.Features;
|
|||
public class DefaultAuthenticationFeature : FeatureBase
|
||||
{
|
||||
private const string MultiScheme = "Jwt-or-ApiKey";
|
||||
private Func<AuthenticationBuilder, AuthenticationBuilder> _configureApiKeyAuthorization = builder => builder.AddApiKeyInAuthorizationHeader<DefaultApiKeyProvider>();
|
||||
|
||||
/// <inheritdoc />
|
||||
public DefaultAuthenticationFeature(IModule module) : base(module)
|
||||
{
|
||||
}
|
||||
|
||||
/// <summary>
|
||||
/// Gets or sets the <see cref="ApiKeyProviderType"/>.
|
||||
/// </summary>
|
||||
public Type ApiKeyProviderType { get; set; } = typeof(DefaultApiKeyProvider);
|
||||
|
||||
/// <summary>
|
||||
/// Configures the API key provider type.
|
||||
/// </summary>
|
||||
/// <typeparam name="T">The type of the API key provider.</typeparam>
|
||||
/// <returns>The current <see cref="DefaultAuthenticationFeature"/>.</returns>
|
||||
public DefaultAuthenticationFeature UseApiKeyAuthorization<T>() where T : class, IApiKeyProvider
|
||||
{
|
||||
_configureApiKeyAuthorization = builder => builder.AddApiKeyInAuthorizationHeader<T>();
|
||||
return this;
|
||||
}
|
||||
|
||||
/// <summary>
|
||||
/// Configures the API key provider type to <see cref="AdminApiKeyProvider"/>.
|
||||
/// </summary>
|
||||
/// <returns>The current <see cref="DefaultAuthenticationFeature"/>.</returns>
|
||||
public DefaultAuthenticationFeature UseAdminApiKeyAuthorization() => UseApiKeyAuthorization<AdminApiKeyProvider>();
|
||||
|
||||
/// <inheritdoc />
|
||||
public override void Apply()
|
||||
{
|
||||
Services.ConfigureOptions<ConfigureJwtBearerOptions>();
|
||||
Services.ConfigureOptions<ValidateIdentityTokenOptions>();
|
||||
|
||||
Services
|
||||
var authBuilder = Services
|
||||
.AddAuthentication(MultiScheme)
|
||||
.AddPolicyScheme(MultiScheme, MultiScheme, options =>
|
||||
{
|
||||
|
|
@ -41,10 +65,13 @@ public class DefaultAuthenticationFeature : FeatureBase
|
|||
: JwtBearerDefaults.AuthenticationScheme;
|
||||
};
|
||||
})
|
||||
.AddJwtBearer()
|
||||
.AddApiKeyInAuthorizationHeader<DefaultApiKeyProvider>();
|
||||
.AddJwtBearer();
|
||||
|
||||
_configureApiKeyAuthorization(authBuilder);
|
||||
|
||||
Services.AddSingleton<IAuthorizationHandler, LocalHostRequirementHandler>();
|
||||
Services.AddSingleton(ApiKeyProviderType);
|
||||
Services.AddSingleton<IApiKeyProvider>(sp => (IApiKeyProvider)sp.GetRequiredService(ApiKeyProviderType));
|
||||
Services.AddAuthorization(options => options.AddPolicy(IdentityPolicyNames.SecurityRoot, policy => policy.AddRequirements(new LocalHostRequirement())));
|
||||
}
|
||||
}
|
||||
|
|
@ -179,9 +179,6 @@ public class IdentityFeature : FeatureBase
|
|||
.AddSingleton<AdminRoleProvider>()
|
||||
.AddSingleton<StoreBasedRoleProvider>()
|
||||
.AddSingleton<ConfigurationBasedRoleProvider>();
|
||||
|
||||
// API Key.
|
||||
Services.AddSingleton<IApiKeyProvider, DefaultApiKeyProvider>();
|
||||
|
||||
// Services.
|
||||
Services
|
||||
|
|
|
|||
27
src/modules/Elsa.Identity/Providers/AdminApiKeyProvider.cs
Normal file
27
src/modules/Elsa.Identity/Providers/AdminApiKeyProvider.cs
Normal file
|
|
@ -0,0 +1,27 @@
|
|||
using System.Security.Claims;
|
||||
using AspNetCore.Authentication.ApiKey;
|
||||
using Elsa.Identity.Models;
|
||||
|
||||
namespace Elsa.Identity.Providers;
|
||||
|
||||
/// <summary>
|
||||
/// Provides an <see cref="IApiKey"/> with admin privileges for the default admin API key.
|
||||
/// </summary>
|
||||
public class AdminApiKeyProvider : IApiKeyProvider
|
||||
{
|
||||
/// <summary>
|
||||
/// The default admin API key.
|
||||
/// </summary>
|
||||
public static readonly string DefaultApiKey = Guid.Empty.ToString();
|
||||
|
||||
/// <inheritdoc />
|
||||
public Task<IApiKey?> ProvideAsync(string key)
|
||||
{
|
||||
if(key != DefaultApiKey)
|
||||
return Task.FromResult<IApiKey?>(null);
|
||||
|
||||
var claims = new List<Claim> { new("permissions", "*") };
|
||||
var apiKey = new ApiKey(key, "admin", claims);
|
||||
return Task.FromResult<IApiKey>(apiKey)!;
|
||||
}
|
||||
}
|
||||
|
|
@ -40,7 +40,7 @@ builder.Services.AddElsa(elsa =>
|
|||
});
|
||||
|
||||
// Use default authentication (JWT).
|
||||
elsa.UseDefaultAuthentication();
|
||||
elsa.UseDefaultAuthentication(auth => auth.UseAdminApiKeyAuthorization());
|
||||
|
||||
// Register custom activities.
|
||||
elsa.AddActivity<ConsoleGreeter>();
|
||||
|
|
|
|||
Loading…
Reference in a new issue