last ...
This commit is contained in:
@@ -0,0 +1,101 @@
|
||||
using System.Linq;
|
||||
using IdentityModel;
|
||||
using xIds.Interfaces;
|
||||
using xCommons.Extensions;
|
||||
using System.Threading.Tasks;
|
||||
using System.Security.Claims;
|
||||
using System.Text.Encodings.Web;
|
||||
using xIdentityService.Constants;
|
||||
using Microsoft.Extensions.Options;
|
||||
using Microsoft.Extensions.Logging;
|
||||
using Microsoft.AspNetCore.Authentication;
|
||||
|
||||
namespace xIds.Providers
|
||||
{
|
||||
/// <summary>
|
||||
/// an Authentication Handler for ApiKey's based App's ...
|
||||
/// </summary>
|
||||
public class XApiKeyAuthenticationHandler : AuthenticationHandler<AuthenticationSchemeOptions>
|
||||
{
|
||||
private readonly IXApplicationProvider applicationProvider;
|
||||
|
||||
//
|
||||
public string HeaderName { get; } = XHeader.ApiKey.GetStringValue();
|
||||
public string AuthenticationScheme { get; } = XAuthenticationScheme.XApiKey.GetStringValue();
|
||||
|
||||
public XApiKeyAuthenticationHandler(
|
||||
UrlEncoder encoder,
|
||||
ISystemClock clock,
|
||||
ILoggerFactory logger,
|
||||
IXApplicationProvider applicationProvider,
|
||||
IOptionsMonitor<AuthenticationSchemeOptions> options
|
||||
) : base(options, logger, encoder, clock)
|
||||
{
|
||||
this.applicationProvider = applicationProvider;
|
||||
}
|
||||
|
||||
/// <summary>
|
||||
/// Handle Authentication ...
|
||||
/// </summary>
|
||||
/// <returns></returns>
|
||||
protected override async Task<AuthenticateResult> HandleAuthenticateAsync()
|
||||
{
|
||||
//
|
||||
var apiKey =
|
||||
!Request.Headers.ContainsKey(HeaderName)
|
||||
? string.Empty
|
||||
: Request.Headers[HeaderName].ToString();
|
||||
if (apiKey.IsNullOrEmpty())
|
||||
{
|
||||
return AuthenticateResult.NoResult();
|
||||
}
|
||||
|
||||
//
|
||||
var clientIP = Request.HttpContext.Connection.RemoteIpAddress?.ToString();
|
||||
|
||||
//
|
||||
var validationResult = await applicationProvider.ValidateApiKey(
|
||||
apiKey: apiKey,
|
||||
clientIP: clientIP
|
||||
);
|
||||
var isValid = !validationResult.Errors.HasChild();
|
||||
if (!isValid)
|
||||
{
|
||||
//
|
||||
var message = validationResult.Errors.ToListString('\n');
|
||||
return AuthenticateResult.Fail(message);
|
||||
}
|
||||
|
||||
//
|
||||
var claims = new[]
|
||||
{
|
||||
new Claim(ClaimTypes.Name, validationResult.OwnerId),
|
||||
new Claim("application_id", validationResult.ApplicationId.ToString()),
|
||||
new Claim("auth_type", "apikey"),
|
||||
new Claim(JwtClaimTypes.Scope, "apikey"),
|
||||
};
|
||||
|
||||
//
|
||||
var scopeClaims = validationResult.Scopes
|
||||
.Select(s => new Claim(JwtClaimTypes.Scope, s));
|
||||
|
||||
//
|
||||
var identity = new ClaimsIdentity(
|
||||
claims.Union(scopeClaims),
|
||||
AuthenticationScheme
|
||||
);
|
||||
|
||||
//
|
||||
var principal = new ClaimsPrincipal(identity);
|
||||
|
||||
//
|
||||
var ticket = new AuthenticationTicket(
|
||||
principal,
|
||||
AuthenticationScheme
|
||||
);
|
||||
|
||||
//
|
||||
return AuthenticateResult.Success(ticket);
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -13,6 +13,7 @@ using System.Linq.Expressions;
|
||||
using IdentityServer4.Extensions;
|
||||
using xIdentityModels.Extensions;
|
||||
using Microsoft.EntityFrameworkCore.Query;
|
||||
using Microsoft.Extensions.Caching.Memory;
|
||||
|
||||
namespace xIds.Providers
|
||||
{
|
||||
@@ -21,6 +22,7 @@ namespace xIds.Providers
|
||||
/// </summary>
|
||||
public partial class XApplicationProvider : IXApplicationProvider
|
||||
{
|
||||
private readonly IMemoryCache cache;
|
||||
private readonly string permittedRole;
|
||||
private readonly XIdentityDbContext dbContext;
|
||||
private readonly IXIdentityManager identityManager;
|
||||
@@ -28,6 +30,7 @@ namespace xIds.Providers
|
||||
private readonly XApiKeyConfiguration apiKeyConfiguration;
|
||||
|
||||
public XApplicationProvider(
|
||||
IMemoryCache cache,
|
||||
XIdentityDbContext dbContext,
|
||||
IXIdentityManager identityManager,
|
||||
XDataServiceConfiguration configuration,
|
||||
@@ -36,6 +39,7 @@ namespace xIds.Providers
|
||||
)
|
||||
{
|
||||
//
|
||||
this.cache = cache;
|
||||
this.dbContext = dbContext;
|
||||
this.permittedRole = permittedRole;
|
||||
this.configuration = configuration;
|
||||
@@ -190,7 +194,7 @@ namespace xIds.Providers
|
||||
// Return result ...
|
||||
return result;
|
||||
}
|
||||
|
||||
|
||||
/// <summary>
|
||||
/// Prepare a Queryable of Items ...
|
||||
/// </summary>
|
||||
@@ -233,7 +237,7 @@ namespace xIds.Providers
|
||||
// Return result ...
|
||||
return result;
|
||||
}
|
||||
|
||||
|
||||
/// <summary>
|
||||
/// Prepare a Queryable of Items ...
|
||||
/// </summary>
|
||||
@@ -249,7 +253,7 @@ namespace xIds.Providers
|
||||
{
|
||||
//
|
||||
// Global Result ...
|
||||
var result = dbContext.ApiKeyUsage.AsQueryable();
|
||||
var result = dbContext.ApiKeyUsages.AsQueryable();
|
||||
|
||||
//
|
||||
// Handle Filtering ...
|
||||
@@ -275,6 +279,45 @@ namespace xIds.Providers
|
||||
//
|
||||
// Return result ...
|
||||
return result;
|
||||
}
|
||||
}
|
||||
|
||||
/// <summary>
|
||||
/// Handle Rate Limit Checking ...
|
||||
/// </summary>
|
||||
/// <param name="apiKeyId"></param>
|
||||
/// <param name="limitPerMinute"></param>
|
||||
/// <returns></returns>
|
||||
private bool CheckRateLimit(
|
||||
Guid apiKeyId,
|
||||
int limitPerMinute
|
||||
)
|
||||
{
|
||||
//
|
||||
var cacheKey = $"ratelimit:{apiKeyId}";
|
||||
var currentCount = cache.GetOrCreate(
|
||||
cacheKey,
|
||||
entry =>
|
||||
{
|
||||
//
|
||||
entry.SlidingExpiration = TimeSpan.FromMinutes(1);
|
||||
return 0;
|
||||
}
|
||||
);
|
||||
|
||||
//
|
||||
if (currentCount >= limitPerMinute) {
|
||||
return false;
|
||||
}
|
||||
|
||||
//
|
||||
cache.Set(
|
||||
cacheKey,
|
||||
currentCount + 1,
|
||||
TimeSpan.FromMinutes(1)
|
||||
);
|
||||
|
||||
//
|
||||
return true;
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -8,7 +8,8 @@ using xExceptions.Constants;
|
||||
using System.Threading.Tasks;
|
||||
using xIdentityModels.Models;
|
||||
using System.Collections.Generic;
|
||||
using System.Security.Cryptography;
|
||||
using xIdentityModels.Extensions;
|
||||
using Microsoft.EntityFrameworkCore;
|
||||
|
||||
namespace xIds.Providers
|
||||
{
|
||||
@@ -85,7 +86,7 @@ namespace xIds.Providers
|
||||
|
||||
//
|
||||
// Generate New Key ...
|
||||
(string plainKey, string keyHash, string prefix) = XApiKeyHelper.Generate();
|
||||
(string plainKey, string keyHash, string prefix) = XApiKeyHelper.Generate(apiKeyConfiguration.ApiKeyPrefix);
|
||||
var expireAt = DateTime.UtcNow.Add(expiration.Value);
|
||||
|
||||
//
|
||||
@@ -112,7 +113,7 @@ namespace xIds.Providers
|
||||
//
|
||||
// Add Item to Database ...
|
||||
result = await AddApiKeyAsync(
|
||||
item: item,
|
||||
item: result,
|
||||
userInfo: userInfo,
|
||||
cancellationToken: cancellationToken
|
||||
);
|
||||
@@ -303,7 +304,7 @@ namespace xIds.Providers
|
||||
{
|
||||
XException.NotAllowed.Throw();
|
||||
}
|
||||
|
||||
|
||||
//
|
||||
var result = await FindManyApiKeyAsync(
|
||||
userInfo: userInfo,
|
||||
@@ -323,18 +324,158 @@ namespace xIds.Providers
|
||||
/// </summary>
|
||||
/// <param name="apiKey"></param>
|
||||
/// <param name="clientIP"></param>
|
||||
/// <param name="requiredScope"></param>
|
||||
/// <param name="userInfo"></param>
|
||||
/// <param name="cancellationToken"></param>
|
||||
/// <returns></returns>
|
||||
public async Task<bool> ValidateApiKey(
|
||||
public async Task<XApiKeyValidationResult> ValidateApiKey(
|
||||
string apiKey,
|
||||
string clientIP,
|
||||
string requiredScope = null,
|
||||
XUserClaimsInfoDto userInfo = null,
|
||||
CancellationToken cancellationToken = default
|
||||
)
|
||||
{
|
||||
//
|
||||
|
||||
var result = new XApiKeyValidationResult();
|
||||
|
||||
//
|
||||
// Validate ...
|
||||
var isValid =
|
||||
!apiKey.IsNullOrEmpty() &&
|
||||
!clientIP.IsNullOrEmpty();
|
||||
if (!isValid)
|
||||
{
|
||||
return result;
|
||||
}
|
||||
|
||||
//
|
||||
// Detect Specified Api Key ...
|
||||
var apiKeyHash = XApiKeyHelper.ComputeHash(apiKey);
|
||||
var keyModel = await dbContext.ApiKeys
|
||||
.FirstOrDefaultAsync(
|
||||
ak => ak.KeyHash == apiKeyHash,
|
||||
cancellationToken: cancellationToken
|
||||
);
|
||||
isValid = !keyModel.IsNullOrDefault();
|
||||
if (!isValid)
|
||||
{
|
||||
//
|
||||
result.Errors.Add("ApiKey not found ...");
|
||||
return result;
|
||||
}
|
||||
|
||||
//
|
||||
// Here we Have to Parse Allowed Ips and Scopes ...
|
||||
var allowedIps = (keyModel.AllowedIPs ?? string.Empty)
|
||||
.ParseListString<string>();
|
||||
var allowedScopes = (keyModel.AllowedScopes ?? string.Empty)
|
||||
.FromJSON<IEnumerable<string>>();
|
||||
result.Scopes = [..allowedScopes];
|
||||
|
||||
//
|
||||
// Check Application is Exists and Active ...
|
||||
var application = await dbContext.Applications
|
||||
.FirstOrDefaultAsync(x => x.Id == keyModel.ApplicationId);
|
||||
if (!application.IsNullOrDefault())
|
||||
{
|
||||
result.OwnerId = application.OwnerId;
|
||||
result.ApplicationId = application.Id;
|
||||
}
|
||||
|
||||
//
|
||||
// Check Application is Exists and Active or not ...
|
||||
var isApplicationActive =
|
||||
//
|
||||
// Application Exists ...
|
||||
!application.IsNullOrDefault() &&
|
||||
//
|
||||
// Check Application is Active ...
|
||||
application.IsActive
|
||||
//
|
||||
;
|
||||
if (!isApplicationActive)
|
||||
{
|
||||
result.Errors.Add("Related Application is Inactive ...");
|
||||
}
|
||||
|
||||
//
|
||||
// Check Key is Active or not ...
|
||||
var isKeyActive =
|
||||
//
|
||||
// Check Api Key is Active ...
|
||||
// Not Revoked ...
|
||||
// Not Expired ...
|
||||
keyModel.IsActive()
|
||||
//
|
||||
;
|
||||
if (!isKeyActive)
|
||||
{
|
||||
//
|
||||
if (keyModel.IsExpired())
|
||||
{
|
||||
result.Errors.Add("ApiKey is Expired ...");
|
||||
}
|
||||
|
||||
//
|
||||
if (keyModel.IsRevoked())
|
||||
{
|
||||
result.Errors.Add("ApiKey is Revoked ...");
|
||||
}
|
||||
}
|
||||
|
||||
//
|
||||
// Checking Rate Limit ...
|
||||
var isRateLimitPassed = CheckRateLimit(keyModel.Id, keyModel.RateLimitPerMinute);
|
||||
if (!isRateLimitPassed)
|
||||
{
|
||||
result.Errors.Add("ApiKey Rate Limit Reached ...");
|
||||
}
|
||||
|
||||
//
|
||||
// Audit Log ...
|
||||
|
||||
//
|
||||
// Check Scope and IP is Valid or not ...
|
||||
var isIpValid =
|
||||
!allowedIps.HasChild() ||
|
||||
allowedIps.Contains(clientIP);
|
||||
var isScopeValid =
|
||||
!allowedScopes.HasChild() ||
|
||||
requiredScope.IsNullOrEmpty() ||
|
||||
allowedScopes.Contains(requiredScope);
|
||||
var isScopeIpValid =
|
||||
isIpValid &&
|
||||
isScopeValid
|
||||
;
|
||||
if (!isScopeIpValid)
|
||||
{
|
||||
//
|
||||
if (!isIpValid)
|
||||
{
|
||||
result.Errors.Add("Client IP not Allowed to Use Resource ...");
|
||||
}
|
||||
|
||||
//
|
||||
if (!isScopeValid)
|
||||
{
|
||||
result.Errors.Add("Required Scoped is Invalid ...");
|
||||
}
|
||||
}
|
||||
|
||||
//
|
||||
isValid =
|
||||
isKeyActive &&
|
||||
isScopeIpValid &&
|
||||
isRateLimitPassed &&
|
||||
isApplicationActive;
|
||||
if (isValid)
|
||||
{
|
||||
result.Errors.Clear();
|
||||
}
|
||||
|
||||
//
|
||||
return result;
|
||||
}
|
||||
#endregion
|
||||
}
|
||||
|
||||
@@ -1,10 +1,11 @@
|
||||
using System;
|
||||
using System.Collections.Generic;
|
||||
using System.Linq;
|
||||
using System.Threading;
|
||||
using System.Threading.Tasks;
|
||||
using xCommons.Extensions;
|
||||
using xIdentityModels.Dtos;
|
||||
using System.Threading.Tasks;
|
||||
using xIdentityModels.Models;
|
||||
using System.Collections.Generic;
|
||||
using Microsoft.EntityFrameworkCore;
|
||||
|
||||
namespace xIds.Providers
|
||||
{
|
||||
@@ -22,7 +23,17 @@ namespace xIds.Providers
|
||||
XApiKey source,
|
||||
CancellationToken cancellationToken = default
|
||||
)
|
||||
{ }
|
||||
{
|
||||
//
|
||||
var result = source.MapConvert<XApiKeyDto, XApiKey>();
|
||||
result = await EnrichAsync(
|
||||
source: result,
|
||||
cancellationToken: cancellationToken
|
||||
);
|
||||
|
||||
//
|
||||
return result;
|
||||
}
|
||||
|
||||
/// <summary>
|
||||
/// Enrich Api Key ...
|
||||
@@ -34,7 +45,36 @@ namespace xIds.Providers
|
||||
XApiKeyDto source,
|
||||
CancellationToken cancellationToken = default
|
||||
)
|
||||
{ }
|
||||
{
|
||||
//
|
||||
if (
|
||||
!source.IsNullOrDefault() &&
|
||||
!source.Application.IsNullOrDefault()
|
||||
)
|
||||
{
|
||||
//
|
||||
var application = await dbContext.Applications
|
||||
.FirstOrDefaultAsync(
|
||||
x => x.Id == source.ApplicationId,
|
||||
cancellationToken: cancellationToken
|
||||
);
|
||||
if (!application.IsNullOrDefault())
|
||||
{
|
||||
//
|
||||
var dto = await EnrichAsync(
|
||||
source: application,
|
||||
cancellationToken: cancellationToken
|
||||
);
|
||||
if (!dto.IsNullOrDefault())
|
||||
{
|
||||
source.Application = dto;
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
//
|
||||
return source;
|
||||
}
|
||||
|
||||
/// <summary>
|
||||
/// Enrich Api Key Usage ...
|
||||
@@ -46,7 +86,17 @@ namespace xIds.Providers
|
||||
XApiKeyUsage source,
|
||||
CancellationToken cancellationToken = default
|
||||
)
|
||||
{ }
|
||||
{
|
||||
//
|
||||
var result = source.MapConvert<XApiKeyUsageDto, XApiKeyUsage>();
|
||||
result = await EnrichAsync(
|
||||
source: result,
|
||||
cancellationToken: cancellationToken
|
||||
);
|
||||
|
||||
//
|
||||
return result;
|
||||
}
|
||||
|
||||
/// <summary>
|
||||
/// Enrich Application ...
|
||||
@@ -58,7 +108,17 @@ namespace xIds.Providers
|
||||
XApplication source,
|
||||
CancellationToken cancellationToken = default
|
||||
)
|
||||
{ }
|
||||
{
|
||||
//
|
||||
var result = source.MapConvert<XApplicationDto, XApplication>();
|
||||
result = await EnrichAsync(
|
||||
source: result,
|
||||
cancellationToken: cancellationToken
|
||||
);
|
||||
|
||||
//
|
||||
return result;
|
||||
}
|
||||
|
||||
/// <summary>
|
||||
/// Enrich Api Key Usage ...
|
||||
@@ -70,7 +130,12 @@ namespace xIds.Providers
|
||||
XApiKeyUsageDto source,
|
||||
CancellationToken cancellationToken = default
|
||||
)
|
||||
{ }
|
||||
{
|
||||
//
|
||||
// There is not any Additional Enrichment ...
|
||||
var result = await Task.FromResult(source);
|
||||
return result;
|
||||
}
|
||||
|
||||
/// <summary>
|
||||
/// Enrich Application ...
|
||||
@@ -82,7 +147,24 @@ namespace xIds.Providers
|
||||
XApplicationDto source,
|
||||
CancellationToken cancellationToken = default
|
||||
)
|
||||
{ }
|
||||
{
|
||||
//
|
||||
if (
|
||||
!source.IsNullOrDefault() &&
|
||||
!source.OwnerId.IsNullOrEmpty()
|
||||
)
|
||||
{
|
||||
//
|
||||
var owner = await GetOwner(source.OwnerId);
|
||||
if (!owner.IsNullOrDefault())
|
||||
{
|
||||
source.Owner = owner;
|
||||
}
|
||||
}
|
||||
|
||||
//
|
||||
return source;
|
||||
}
|
||||
|
||||
/// <summary>
|
||||
/// Enrich a Collection of Api Key(s) ...
|
||||
@@ -94,7 +176,17 @@ namespace xIds.Providers
|
||||
IEnumerable<XApiKey> sources,
|
||||
CancellationToken cancellationToken = default
|
||||
)
|
||||
{ }
|
||||
{
|
||||
//
|
||||
var tasks = sources
|
||||
.Select(s => EnrichAsync(s, cancellationToken));
|
||||
|
||||
//
|
||||
var result = await Task.WhenAll(tasks);
|
||||
|
||||
//
|
||||
return result;
|
||||
}
|
||||
|
||||
/// <summary>
|
||||
/// Enrich a Collection of Api Key(s) ...
|
||||
@@ -106,7 +198,17 @@ namespace xIds.Providers
|
||||
IEnumerable<XApiKeyDto> sources,
|
||||
CancellationToken cancellationToken = default
|
||||
)
|
||||
{ }
|
||||
{
|
||||
//
|
||||
var tasks = sources
|
||||
.Select(s => EnrichAsync(s, cancellationToken));
|
||||
|
||||
//
|
||||
var result = await Task.WhenAll(tasks);
|
||||
|
||||
//
|
||||
return result;
|
||||
}
|
||||
|
||||
/// <summary>
|
||||
/// Enrich a Collection of Api Key Usage(s) ...
|
||||
@@ -118,7 +220,17 @@ namespace xIds.Providers
|
||||
IEnumerable<XApiKeyUsage> sources,
|
||||
CancellationToken cancellationToken = default
|
||||
)
|
||||
{ }
|
||||
{
|
||||
//
|
||||
var tasks = sources
|
||||
.Select(s => EnrichAsync(s, cancellationToken));
|
||||
|
||||
//
|
||||
var result = await Task.WhenAll(tasks);
|
||||
|
||||
//
|
||||
return result;
|
||||
}
|
||||
|
||||
/// <summary>
|
||||
/// Enrich a Collection of Application(s) ...
|
||||
@@ -130,7 +242,17 @@ namespace xIds.Providers
|
||||
IEnumerable<XApplication> sources,
|
||||
CancellationToken cancellationToken = default
|
||||
)
|
||||
{ }
|
||||
{
|
||||
//
|
||||
var tasks = sources
|
||||
.Select(s => EnrichAsync(s, cancellationToken));
|
||||
|
||||
//
|
||||
var result = await Task.WhenAll(tasks);
|
||||
|
||||
//
|
||||
return result;
|
||||
}
|
||||
|
||||
/// <summary>
|
||||
/// Enrich a Collection of Api Key Usage(s) ...
|
||||
@@ -142,7 +264,17 @@ namespace xIds.Providers
|
||||
IEnumerable<XApiKeyUsageDto> sources,
|
||||
CancellationToken cancellationToken = default
|
||||
)
|
||||
{ }
|
||||
{
|
||||
//
|
||||
var tasks = sources
|
||||
.Select(s => EnrichAsync(s, cancellationToken));
|
||||
|
||||
//
|
||||
var result = await Task.WhenAll(tasks);
|
||||
|
||||
//
|
||||
return result;
|
||||
}
|
||||
|
||||
/// <summary>
|
||||
/// Enrich a Collection of Application(s) ...
|
||||
@@ -154,7 +286,17 @@ namespace xIds.Providers
|
||||
IEnumerable<XApplicationDto> sources,
|
||||
CancellationToken cancellationToken = default
|
||||
)
|
||||
{ }
|
||||
{
|
||||
//
|
||||
var tasks = sources
|
||||
.Select(s => EnrichAsync(s, cancellationToken));
|
||||
|
||||
//
|
||||
var result = await Task.WhenAll(tasks);
|
||||
|
||||
//
|
||||
return result;
|
||||
}
|
||||
#endregion
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user