Compare commits

..
4 Commits
Author SHA1 Message Date
saherelm b00391517a last ... 2026-10-07 22:40:02 +03:30
saherelm e1e151a834 last ... 2026-10-07 19:38:19 +03:30
saherelm cd2b06b913 add required extensions for DI Registration ... 2026-10-06 21:31:36 +03:30
saherelm 48395457e6 last ... 2026-10-06 17:47:27 +03:30
25 changed files with 753 additions and 137 deletions
+5
View File
@@ -5,6 +5,11 @@ namespace xIds.Configurations
/// </summary> /// </summary>
public class XApiKeyConfiguration public class XApiKeyConfiguration
{ {
/// <summary>
/// Generated Api Keys Prefix ...
/// </summary>
public string ApiKeyPrefix { get; set; }
/// <summary> /// <summary>
/// Default expiration in minutes (e.g., 43200 = 30 days) /// Default expiration in minutes (e.g., 43200 = 30 days)
/// </summary> /// </summary>
@@ -1,12 +1,12 @@
using System; using System;
using System.Collections.Generic;
using System.Threading.Tasks;
using Microsoft.AspNetCore.Authorization;
using Microsoft.AspNetCore.Mvc;
using xIdentityHelper; using xIdentityHelper;
using xCommons.Attributes; using xCommons.Attributes;
using xCommons.Extensions; using xCommons.Extensions;
using xIdentityModels.Dtos; using xIdentityModels.Dtos;
using System.Threading.Tasks;
using Microsoft.AspNetCore.Mvc;
using System.Collections.Generic;
using Microsoft.AspNetCore.Authorization;
using static IdentityServer4.IdentityServerConstants; using static IdentityServer4.IdentityServerConstants;
namespace xIds.Controllers namespace xIds.Controllers
@@ -1,17 +1,17 @@
using System; using System;
using System.Threading.Tasks;
using IdentityModel.Client;
using Microsoft.AspNetCore.Authorization;
using Microsoft.AspNetCore.Mvc;
using xIdentityHelper; using xIdentityHelper;
using xCommons.Attributes; using xCommons.Attributes;
using xCommons.Extensions; using xCommons.Extensions;
using IdentityModel.Client;
using xExceptions.Constants; using xExceptions.Constants;
using xIdentityModels.Extensions; using System.Threading.Tasks;
using xIdentityModels.Models; using xIdentityModels.Models;
using static IdentityServer4.IdentityServerConstants; using Microsoft.AspNetCore.Mvc;
using static xIdentityHelper.XApiScopeHelper; using xIdentityModels.Extensions;
using Microsoft.Extensions.Logging; using Microsoft.Extensions.Logging;
using Microsoft.AspNetCore.Authorization;
using static xIdentityHelper.XApiScopeHelper;
using static IdentityServer4.IdentityServerConstants;
namespace xIds.Controllers namespace xIds.Controllers
{ {
@@ -1,17 +1,17 @@
using System; using System;
using System.Collections.Generic;
using System.Linq; using System.Linq;
using System.Threading.Tasks; using xModels.Dtos;
using Microsoft.AspNetCore.Authorization; using xIdentityHelper;
using Microsoft.AspNetCore.Mvc;
using xCommons.Attributes; using xCommons.Attributes;
using xCommons.Extensions; using xCommons.Extensions;
using xExceptions.Constants;
using xIdentityHelper;
using xIdentityModels.Constants;
using xIdentityModels.Dtos; using xIdentityModels.Dtos;
using xExceptions.Constants;
using System.Threading.Tasks;
using Microsoft.AspNetCore.Mvc;
using xIdentityModels.Constants;
using System.Collections.Generic;
using xIdentityModels.Navigations; using xIdentityModels.Navigations;
using xModels.Dtos; using Microsoft.AspNetCore.Authorization;
using static IdentityServer4.IdentityServerConstants; using static IdentityServer4.IdentityServerConstants;
namespace xIds.Controllers namespace xIds.Controllers
@@ -1,10 +1,10 @@
using System; using System;
using System.Threading.Tasks;
using Microsoft.AspNetCore.Authorization;
using Microsoft.AspNetCore.Mvc;
using xCommons.Attributes;
using xCommons.Constants; using xCommons.Constants;
using xCommons.Attributes;
using xIdentityModels.Dtos; using xIdentityModels.Dtos;
using System.Threading.Tasks;
using Microsoft.AspNetCore.Mvc;
using Microsoft.AspNetCore.Authorization;
namespace xIds.Controllers namespace xIds.Controllers
{ {
@@ -1,17 +1,17 @@
using System; using System;
using System.Collections.Generic;
using System.Collections.ObjectModel;
using System.Linq; using System.Linq;
using System.Threading.Tasks; using xModels.Dtos;
using Microsoft.AspNetCore.Authorization;
using Microsoft.AspNetCore.Http;
using Microsoft.AspNetCore.Mvc;
using xIdentityHelper; using xIdentityHelper;
using xCommons.Attributes; using xCommons.Attributes;
using xCommons.Extensions; using xCommons.Extensions;
using xIdentityModels.Dtos; using xIdentityModels.Dtos;
using System.Threading.Tasks;
using xIdentityModels.Models; using xIdentityModels.Models;
using xModels.Dtos; using Microsoft.AspNetCore.Mvc;
using Microsoft.AspNetCore.Http;
using System.Collections.Generic;
using System.Collections.ObjectModel;
using Microsoft.AspNetCore.Authorization;
using static IdentityServer4.IdentityServerConstants; using static IdentityServer4.IdentityServerConstants;
namespace xIds.Controllers namespace xIds.Controllers
@@ -1,11 +1,11 @@
using System; using System;
using System.Threading.Tasks; using xModels.Dtos;
using Microsoft.AspNetCore.Authorization; using xIdentityHelper;
using Microsoft.AspNetCore.Mvc;
using xCommons.Attributes; using xCommons.Attributes;
using xCommons.Extensions; using xCommons.Extensions;
using xIdentityHelper; using System.Threading.Tasks;
using xModels.Dtos; using Microsoft.AspNetCore.Mvc;
using Microsoft.AspNetCore.Authorization;
using static IdentityServer4.IdentityServerConstants; using static IdentityServer4.IdentityServerConstants;
namespace xIds.Controllers namespace xIds.Controllers
@@ -1,15 +1,15 @@
using System; using System;
using System.Collections.Generic;
using System.Threading.Tasks;
using Microsoft.AspNetCore.Authorization;
using Microsoft.AspNetCore.Http;
using Microsoft.AspNetCore.Mvc;
using xIdentityHelper; using xIdentityHelper;
using xCommons.Attributes; using xCommons.Attributes;
using xCommons.Extensions; using xCommons.Extensions;
using xExceptions.Constants; using xExceptions.Constants;
using xIdentityModels.Constants; using System.Threading.Tasks;
using xIdentityModels.Models; using xIdentityModels.Models;
using Microsoft.AspNetCore.Mvc;
using Microsoft.AspNetCore.Http;
using xIdentityModels.Constants;
using System.Collections.Generic;
using Microsoft.AspNetCore.Authorization;
using static IdentityServer4.IdentityServerConstants; using static IdentityServer4.IdentityServerConstants;
namespace xIds.Controllers namespace xIds.Controllers
@@ -1,14 +1,14 @@
using System; using System;
using System.Collections.Generic;
using System.Linq; using System.Linq;
using System.Threading.Tasks; using xModels.Dtos;
using Microsoft.AspNetCore.Authorization; using xIdentityHelper;
using Microsoft.AspNetCore.Mvc;
using xCommons.Attributes; using xCommons.Attributes;
using xCommons.Extensions; using xCommons.Extensions;
using xIdentityHelper;
using xIdentityModels.Dtos; using xIdentityModels.Dtos;
using xModels.Dtos; using System.Threading.Tasks;
using Microsoft.AspNetCore.Mvc;
using System.Collections.Generic;
using Microsoft.AspNetCore.Authorization;
using static IdentityServer4.IdentityServerConstants; using static IdentityServer4.IdentityServerConstants;
namespace xIds.Controllers namespace xIds.Controllers
+15 -2
View File
@@ -1,8 +1,8 @@
using System.Linq; using System.Linq;
using Microsoft.AspNetCore.Authorization;
using Microsoft.AspNetCore.Mvc;
using xIdentityHelper; using xIdentityHelper;
using xCommons.Attributes; using xCommons.Attributes;
using Microsoft.AspNetCore.Mvc;
using Microsoft.AspNetCore.Authorization;
using static IdentityServer4.IdentityServerConstants; using static IdentityServer4.IdentityServerConstants;
namespace xIds.Controllers namespace xIds.Controllers
@@ -156,6 +156,19 @@ namespace xIds.Controllers
// //
return Ok(result); return Ok(result);
} }
[RequireXPowered]
[HttpGet("Test/HiApiKeyAccess")]
[Authorize(LocalApi.PolicyName)]
[Authorize(Policy = XPolicies.ApiKeyAccess)]
public ActionResult<string> HiApiKeyAccess()
{
//
var result = $"Hi ApiKey Access, is Passed ...";
//
return Ok(result);
}
#endregion #endregion
} }
} }
+4 -4
View File
@@ -1,9 +1,9 @@
using Microsoft.AspNetCore.Mvc; using xIds.Interfaces;
using Microsoft.Extensions.Logging;
using xCommons.Configurations;
using xCommons.Providers; using xCommons.Providers;
using xIds.Controllers.Base; using xIds.Controllers.Base;
using xIds.Interfaces; using xCommons.Configurations;
using Microsoft.AspNetCore.Mvc;
using Microsoft.Extensions.Logging;
namespace xIds.Controllers namespace xIds.Controllers
{ {
@@ -0,0 +1,9 @@
namespace xIds.Controllers
{
public partial class ApplicationsController
{
//
#region ApiKey ...
#endregion
}
}
@@ -0,0 +1,9 @@
namespace xIds.Controllers
{
public partial class ApplicationsController
{
//
#region ApiKeyUsage ...
#endregion
}
}
@@ -0,0 +1,31 @@
using System;
using xIdentityHelper;
using System.Threading;
using xCommons.Attributes;
using xIdentityModels.Dtos;
using System.Threading.Tasks;
using Microsoft.AspNetCore.Mvc;
using Microsoft.AspNetCore.Authorization;
using static IdentityServer4.IdentityServerConstants;
namespace xIds.Controllers
{
public partial class ApplicationsController
{
//
#region Application ...
[HttpPost]
[RequireXPowered]
[Authorize(LocalApi.PolicyName)]
[Authorize(Policy = XPolicies.EnabledUser)]
public async Task<ActionResult<XApplicationDto>> CreateApplication(
[FromBody] XApplicationDto request,
CancellationToken cancellationToken = default
)
{
//
throw new NotImplementedException("");
}
#endregion
}
}
+29
View File
@@ -0,0 +1,29 @@
using xIds.Interfaces;
using xCommons.Providers;
using xIds.Controllers.Base;
using xCommons.Configurations;
using Microsoft.AspNetCore.Mvc;
using Microsoft.Extensions.Logging;
namespace xIds.Controllers
{
/// <summary>
/// Provide all available tools for manipulating users and accounts
/// </summary>
[ApiController]
public partial class ApplicationsController : XIBaseController
{
public ApplicationsController(
ILogger<ApplicationsController> logger,
XAppConfiguration appConfiguration,
IXIdentityManager identityManager,
XValidationProvider validationProvider
) : base(
logger,
appConfiguration,
identityManager,
validationProvider
)
{ }
}
}
+83 -3
View File
@@ -25,7 +25,9 @@ using xIdentityModels.Configurations;
using Microsoft.AspNetCore.Authorization; using Microsoft.AspNetCore.Authorization;
using Microsoft.AspNetCore.HttpOverrides; using Microsoft.AspNetCore.HttpOverrides;
using Microsoft.Extensions.Configuration; using Microsoft.Extensions.Configuration;
using Microsoft.AspNetCore.Authentication;
using Microsoft.Extensions.DependencyInjection; using Microsoft.Extensions.DependencyInjection;
using xIdentityService.Constants;
namespace xIds.DI namespace xIds.DI
{ {
@@ -147,6 +149,67 @@ namespace xIds.DI
services.AddSingleton<XDataServiceConfiguration>(dataServiceConfiguration); services.AddSingleton<XDataServiceConfiguration>(dataServiceConfiguration);
} }
/// <summary>
/// Add Specified ApiKey Configurations Instance ...
/// </summary>
/// <param name="source"></param>
/// <param name="configuration"></param>
public static void AddXApiKeyConfiguration(
this IServiceCollection source,
XApiKeyConfiguration configuration
)
{
//
if (configuration.IsNull())
{
return;
}
//
source.AddSingleton(configuration);
}
/// <summary>
/// Extract APpi KLey Configurations from app settings
/// and Register in Services ...
/// </summary>
/// <param name="source"></param>
/// <param name="configuration"></param>
public static void AddXApiKeyConfiguration(
this IServiceCollection source,
IConfiguration configuration
)
{
//
var config = configuration.GetXApiKeyConfiguration();
if (config.IsNull())
{
return;
}
//
source.AddXApiKeyConfiguration(config);
}
/// <summary>
/// Register Application Provider ...
/// Managing Applications/ApiKeys/ApiKeyUsages ...
/// </summary>
/// <param name="source"></param>
/// <param name="configuration"></param>
public static void AddXApplicationProvider(
this IServiceCollection source,
IConfiguration configuration
)
{
//
source.AddXApiKeyConfiguration(configuration);
//
source.AddMemoryCache();
source.AddScoped<IXApplicationProvider, XApplicationProvider>();
}
/// <summary> /// <summary>
/// Register All Requirements For XIdentityServer Usage /// Register All Requirements For XIdentityServer Usage
/// </summary> /// </summary>
@@ -336,15 +399,22 @@ namespace xIds.DI
/// </summary> /// </summary>
/// <param name="services"></param> /// <param name="services"></param>
/// <param name="configuration"></param> /// <param name="configuration"></param>
/// <param name="addApiKeyAuthentication"></param>
public static void AddXIdentityServerAuthentication( public static void AddXIdentityServerAuthentication(
this IServiceCollection services, this IServiceCollection services,
IConfiguration configuration IConfiguration configuration,
bool addApiKeyAuthentication = false
) )
{ {
// //
services.AddXIdentityResourceConfiguration(configuration); services.AddXIdentityResourceConfiguration(configuration);
services.AddAuthentication()
.AddJwtBearer(options => //
var authBuilder = services.AddAuthentication();
//
// Add JWT Bearer ...
authBuilder.AddJwtBearer(options =>
{ {
// //
options.SaveToken = true; options.SaveToken = true;
@@ -354,6 +424,16 @@ namespace xIds.DI
options.ForwardDefault = XAuthentication.IDENTITY_SERVER_LOCAL_API; options.ForwardDefault = XAuthentication.IDENTITY_SERVER_LOCAL_API;
}) })
.AddLocalApi(); .AddLocalApi();
//
if (addApiKeyAuthentication)
{
//
authBuilder.AddScheme<AuthenticationSchemeOptions, XApiKeyAuthenticationHandler>(
XAuthenticationScheme.XApiKey.GetStringValue(),
options => {}
);
}
} }
/// <summary> /// <summary>
+24 -19
View File
@@ -9,11 +9,29 @@ namespace xIds.Helpers
/// </summary> /// </summary>
public static class XApiKeyHelper public static class XApiKeyHelper
{ {
/// <summary>
/// Compute Hash of Specified Content using SHA256 ...
/// </summary>
/// <param name="plain"></param>
/// <returns></returns>
public static string ComputeHash(string plain)
{
//
using var sha256 = SHA256.Create();
var hashBytes = sha256.ComputeHash(Encoding.UTF8.GetBytes(plain));
var result = BitConverter.ToString(hashBytes)
.Replace("-", "")
.ToLower();
//
return result;
}
/// <summary> /// <summary>
/// Generate an Api Key ... /// Generate an Api Key ...
/// </summary> /// </summary>
/// <returns></returns> /// <returns></returns>
public static (string plainKey, string hash, string prefix) Generate() public static (string plainKey, string hash, string prefix) Generate(string keyPrefix)
{ {
// //
// Generate 32 bytes of cryptographically secure random data // Generate 32 bytes of cryptographically secure random data
@@ -25,16 +43,12 @@ namespace xIds.Helpers
// //
// Format: xapp_{base64url} // Format: xapp_{base64url}
var plainKey = $"xapp_{Convert.ToBase64String(randomBytes) var plainKey = $"{keyPrefix}_{Convert.ToBase64String(randomBytes)
.Replace("+", "-").Replace("/", "_").TrimEnd('=')}"; .Replace("+", "-").Replace("/", "_").TrimEnd('=')}";
// //
// Hash with SHA256 for storage (never store plain key) // Compute Hash ...
using (var sha256 = SHA256.Create()) var hash = ComputeHash(plainKey);
{
//
var hashBytes = sha256.ComputeHash(Encoding.UTF8.GetBytes(plainKey));
var hash = BitConverter.ToString(hashBytes).Replace("-", "").ToLower();
// //
// Prefix for quick identification (first 12 chars) // Prefix for quick identification (first 12 chars)
@@ -43,7 +57,6 @@ namespace xIds.Helpers
// //
return (plainKey, hash, prefix); return (plainKey, hash, prefix);
} }
}
/// <summary> /// <summary>
/// Verify Generating Api Key ... /// Verify Generating Api Key ...
@@ -57,16 +70,8 @@ namespace xIds.Helpers
) )
{ {
// //
using (var sha256 = SHA256.Create()) var hash = ComputeHash(plainKey);
{ return hash == storedHash;
//
var hashBytes = sha256.ComputeHash(Encoding.UTF8.GetBytes(plainKey));
var computedHash = BitConverter.ToString(hashBytes)
.Replace("-", "").ToLower();
//
return computedHash == storedHash;
}
} }
} }
} }
+15 -13
View File
@@ -194,7 +194,7 @@ namespace xIds.Interfaces
/// <param name="cancellationToken"></param> /// <param name="cancellationToken"></param>
/// <returns></returns> /// <returns></returns>
Task<XApiKeyDto> UpdateApiKeyAsync( Task<XApiKeyDto> UpdateApiKeyAsync(
int id, Guid id,
XApiKeyDto item, XApiKeyDto item,
XUserClaimsInfoDto userInfo = null, XUserClaimsInfoDto userInfo = null,
CancellationToken cancellationToken = default CancellationToken cancellationToken = default
@@ -209,7 +209,7 @@ namespace xIds.Interfaces
/// <param name="cancellationToken"></param> /// <param name="cancellationToken"></param>
/// <returns></returns> /// <returns></returns>
Task<XApiKeyDto> RemoveApiKeyAsync( Task<XApiKeyDto> RemoveApiKeyAsync(
int id, Guid id,
bool softDelete = true, bool softDelete = true,
XUserClaimsInfoDto userInfo = null, XUserClaimsInfoDto userInfo = null,
CancellationToken cancellationToken = default CancellationToken cancellationToken = default
@@ -225,7 +225,7 @@ namespace xIds.Interfaces
/// <param name="cancellationToken"></param> /// <param name="cancellationToken"></param>
/// <returns></returns> /// <returns></returns>
Task<XApiKeyDto> GetApiKeyAsync( Task<XApiKeyDto> GetApiKeyAsync(
int id, Guid id,
bool ignoreSoftDeleteds = true, bool ignoreSoftDeleteds = true,
XUserClaimsInfoDto userInfo = null, XUserClaimsInfoDto userInfo = null,
Func<IQueryable<XApiKey>, IIncludableQueryable<XApiKey, object>> includeBuilder = null, Func<IQueryable<XApiKey>, IIncludableQueryable<XApiKey, object>> includeBuilder = null,
@@ -348,7 +348,7 @@ namespace xIds.Interfaces
/// <param name="cancellationToken"></param> /// <param name="cancellationToken"></param>
/// <returns></returns> /// <returns></returns>
Task<XApiKeyUsageDto> UpdateApiKeyUsageAsync( Task<XApiKeyUsageDto> UpdateApiKeyUsageAsync(
int id, long id,
XApiKeyUsageDto item, XApiKeyUsageDto item,
XUserClaimsInfoDto userInfo = null, XUserClaimsInfoDto userInfo = null,
CancellationToken cancellationToken = default CancellationToken cancellationToken = default
@@ -363,7 +363,7 @@ namespace xIds.Interfaces
/// <param name="cancellationToken"></param> /// <param name="cancellationToken"></param>
/// <returns></returns> /// <returns></returns>
Task<XApiKeyUsageDto> RemoveApiKeyUsageAsync( Task<XApiKeyUsageDto> RemoveApiKeyUsageAsync(
int id, long id,
bool softDelete = true, bool softDelete = true,
XUserClaimsInfoDto userInfo = null, XUserClaimsInfoDto userInfo = null,
CancellationToken cancellationToken = default CancellationToken cancellationToken = default
@@ -379,7 +379,7 @@ namespace xIds.Interfaces
/// <param name="cancellationToken"></param> /// <param name="cancellationToken"></param>
/// <returns></returns> /// <returns></returns>
Task<XApiKeyUsageDto> GetApiKeyUsageAsync( Task<XApiKeyUsageDto> GetApiKeyUsageAsync(
int id, long id,
bool ignoreSoftDeleteds = true, bool ignoreSoftDeleteds = true,
XUserClaimsInfoDto userInfo = null, XUserClaimsInfoDto userInfo = null,
Func<IQueryable<XApiKeyUsage>, IIncludableQueryable<XApiKeyUsage, object>> includeBuilder = null, Func<IQueryable<XApiKeyUsage>, IIncludableQueryable<XApiKeyUsage, object>> includeBuilder = null,
@@ -547,12 +547,14 @@ namespace xIds.Interfaces
/// </summary> /// </summary>
/// <param name="apiKey"></param> /// <param name="apiKey"></param>
/// <param name="clientIP"></param> /// <param name="clientIP"></param>
/// <param name="requiredScope"></param>
/// <param name="userInfo"></param> /// <param name="userInfo"></param>
/// <param name="cancellationToken"></param> /// <param name="cancellationToken"></param>
/// <returns></returns> /// <returns></returns>
Task<bool> ValidateApiKey( Task<XApiKeyValidationResult> ValidateApiKey(
string apiKey, string apiKey,
string clientIP, string clientIP,
string requiredScope = null,
XUserClaimsInfoDto userInfo = null, XUserClaimsInfoDto userInfo = null,
CancellationToken cancellationToken = default CancellationToken cancellationToken = default
); );
@@ -632,7 +634,7 @@ namespace xIds.Interfaces
/// <param name="sources"></param> /// <param name="sources"></param>
/// <param name="cancellationToken"></param> /// <param name="cancellationToken"></param>
/// <returns></returns> /// <returns></returns>
Task<XApiKeyDto> EnrichRangeAsync( Task<IEnumerable<XApiKeyDto>> EnrichRangeAsync(
IEnumerable<XApiKey> sources, IEnumerable<XApiKey> sources,
CancellationToken cancellationToken = default CancellationToken cancellationToken = default
); );
@@ -643,7 +645,7 @@ namespace xIds.Interfaces
/// <param name="sources"></param> /// <param name="sources"></param>
/// <param name="cancellationToken"></param> /// <param name="cancellationToken"></param>
/// <returns></returns> /// <returns></returns>
Task<XApiKeyDto> EnrichRangeAsync( Task<IEnumerable<XApiKeyDto>> EnrichRangeAsync(
IEnumerable<XApiKeyDto> sources, IEnumerable<XApiKeyDto> sources,
CancellationToken cancellationToken = default CancellationToken cancellationToken = default
); );
@@ -654,7 +656,7 @@ namespace xIds.Interfaces
/// <param name="sources"></param> /// <param name="sources"></param>
/// <param name="cancellationToken"></param> /// <param name="cancellationToken"></param>
/// <returns></returns> /// <returns></returns>
Task<XApiKeyUsageDto> EnrichRangeAsync( Task<IEnumerable<XApiKeyUsageDto>> EnrichRangeAsync(
IEnumerable<XApiKeyUsage> sources, IEnumerable<XApiKeyUsage> sources,
CancellationToken cancellationToken = default CancellationToken cancellationToken = default
); );
@@ -665,7 +667,7 @@ namespace xIds.Interfaces
/// <param name="sources"></param> /// <param name="sources"></param>
/// <param name="cancellationToken"></param> /// <param name="cancellationToken"></param>
/// <returns></returns> /// <returns></returns>
Task<XApplicationDto> EnrichRangeAsync( Task<IEnumerable<XApplicationDto>> EnrichRangeAsync(
IEnumerable<XApplication> sources, IEnumerable<XApplication> sources,
CancellationToken cancellationToken = default CancellationToken cancellationToken = default
); );
@@ -676,7 +678,7 @@ namespace xIds.Interfaces
/// <param name="sources"></param> /// <param name="sources"></param>
/// <param name="cancellationToken"></param> /// <param name="cancellationToken"></param>
/// <returns></returns> /// <returns></returns>
Task<XApiKeyUsageDto> EnrichRangeAsync( Task<IEnumerable<XApiKeyUsageDto>> EnrichRangeAsync(
IEnumerable<XApiKeyUsageDto> sources, IEnumerable<XApiKeyUsageDto> sources,
CancellationToken cancellationToken = default CancellationToken cancellationToken = default
); );
@@ -687,7 +689,7 @@ namespace xIds.Interfaces
/// <param name="sources"></param> /// <param name="sources"></param>
/// <param name="cancellationToken"></param> /// <param name="cancellationToken"></param>
/// <returns></returns> /// <returns></returns>
Task<XApplicationDto> EnrichRangeAsync( Task<IEnumerable<XApplicationDto>> EnrichRangeAsync(
IEnumerable<XApplicationDto> sources, IEnumerable<XApplicationDto> sources,
CancellationToken cancellationToken = default CancellationToken cancellationToken = default
); );
+101
View File
@@ -0,0 +1,101 @@
using System.Linq;
using IdentityModel;
using xIds.Interfaces;
using xCommons.Extensions;
using System.Threading.Tasks;
using System.Security.Claims;
using System.Text.Encodings.Web;
using xIdentityService.Constants;
using Microsoft.Extensions.Options;
using Microsoft.Extensions.Logging;
using Microsoft.AspNetCore.Authentication;
namespace xIds.Providers
{
/// <summary>
/// an Authentication Handler for ApiKey's based App's ...
/// </summary>
public class XApiKeyAuthenticationHandler : AuthenticationHandler<AuthenticationSchemeOptions>
{
private readonly IXApplicationProvider applicationProvider;
//
public string HeaderName { get; } = XHeader.ApiKey.GetStringValue();
public string AuthenticationScheme { get; } = XAuthenticationScheme.XApiKey.GetStringValue();
public XApiKeyAuthenticationHandler(
UrlEncoder encoder,
ISystemClock clock,
ILoggerFactory logger,
IXApplicationProvider applicationProvider,
IOptionsMonitor<AuthenticationSchemeOptions> options
) : base(options, logger, encoder, clock)
{
this.applicationProvider = applicationProvider;
}
/// <summary>
/// Handle Authentication ...
/// </summary>
/// <returns></returns>
protected override async Task<AuthenticateResult> HandleAuthenticateAsync()
{
//
var apiKey =
!Request.Headers.ContainsKey(HeaderName)
? string.Empty
: Request.Headers[HeaderName].ToString();
if (apiKey.IsNullOrEmpty())
{
return AuthenticateResult.NoResult();
}
//
var clientIP = Request.HttpContext.Connection.RemoteIpAddress?.ToString();
//
var validationResult = await applicationProvider.ValidateApiKey(
apiKey: apiKey,
clientIP: clientIP
);
var isValid = !validationResult.Errors.HasChild();
if (!isValid)
{
//
var message = validationResult.Errors.ToListString('\n');
return AuthenticateResult.Fail(message);
}
//
var claims = new[]
{
new Claim(ClaimTypes.Name, validationResult.OwnerId),
new Claim("application_id", validationResult.ApplicationId.ToString()),
new Claim("auth_type", "apikey"),
new Claim(JwtClaimTypes.Scope, "apikey"),
};
//
var scopeClaims = validationResult.Scopes
.Select(s => new Claim(JwtClaimTypes.Scope, s));
//
var identity = new ClaimsIdentity(
claims.Union(scopeClaims),
AuthenticationScheme
);
//
var principal = new ClaimsPrincipal(identity);
//
var ticket = new AuthenticationTicket(
principal,
AuthenticationScheme
);
//
return AuthenticateResult.Success(ticket);
}
}
}
+44 -1
View File
@@ -13,6 +13,7 @@ using System.Linq.Expressions;
using IdentityServer4.Extensions; using IdentityServer4.Extensions;
using xIdentityModels.Extensions; using xIdentityModels.Extensions;
using Microsoft.EntityFrameworkCore.Query; using Microsoft.EntityFrameworkCore.Query;
using Microsoft.Extensions.Caching.Memory;
namespace xIds.Providers namespace xIds.Providers
{ {
@@ -21,6 +22,7 @@ namespace xIds.Providers
/// </summary> /// </summary>
public partial class XApplicationProvider : IXApplicationProvider public partial class XApplicationProvider : IXApplicationProvider
{ {
private readonly IMemoryCache cache;
private readonly string permittedRole; private readonly string permittedRole;
private readonly XIdentityDbContext dbContext; private readonly XIdentityDbContext dbContext;
private readonly IXIdentityManager identityManager; private readonly IXIdentityManager identityManager;
@@ -28,6 +30,7 @@ namespace xIds.Providers
private readonly XApiKeyConfiguration apiKeyConfiguration; private readonly XApiKeyConfiguration apiKeyConfiguration;
public XApplicationProvider( public XApplicationProvider(
IMemoryCache cache,
XIdentityDbContext dbContext, XIdentityDbContext dbContext,
IXIdentityManager identityManager, IXIdentityManager identityManager,
XDataServiceConfiguration configuration, XDataServiceConfiguration configuration,
@@ -36,6 +39,7 @@ namespace xIds.Providers
) )
{ {
// //
this.cache = cache;
this.dbContext = dbContext; this.dbContext = dbContext;
this.permittedRole = permittedRole; this.permittedRole = permittedRole;
this.configuration = configuration; this.configuration = configuration;
@@ -249,7 +253,7 @@ namespace xIds.Providers
{ {
// //
// Global Result ... // Global Result ...
var result = dbContext.ApiKeyUsage.AsQueryable(); var result = dbContext.ApiKeyUsages.AsQueryable();
// //
// Handle Filtering ... // Handle Filtering ...
@@ -276,5 +280,44 @@ namespace xIds.Providers
// Return result ... // Return result ...
return result; return result;
} }
/// <summary>
/// Handle Rate Limit Checking ...
/// </summary>
/// <param name="apiKeyId"></param>
/// <param name="limitPerMinute"></param>
/// <returns></returns>
private bool CheckRateLimit(
Guid apiKeyId,
int limitPerMinute
)
{
//
var cacheKey = $"ratelimit:{apiKeyId}";
var currentCount = cache.GetOrCreate(
cacheKey,
entry =>
{
//
entry.SlidingExpiration = TimeSpan.FromMinutes(1);
return 0;
}
);
//
if (currentCount >= limitPerMinute) {
return false;
}
//
cache.Set(
cacheKey,
currentCount + 1,
TimeSpan.FromMinutes(1)
);
//
return true;
}
} }
} }
@@ -8,7 +8,8 @@ using xExceptions.Constants;
using System.Threading.Tasks; using System.Threading.Tasks;
using xIdentityModels.Models; using xIdentityModels.Models;
using System.Collections.Generic; using System.Collections.Generic;
using System.Security.Cryptography; using xIdentityModels.Extensions;
using Microsoft.EntityFrameworkCore;
namespace xIds.Providers namespace xIds.Providers
{ {
@@ -85,7 +86,7 @@ namespace xIds.Providers
// //
// Generate New Key ... // Generate New Key ...
(string plainKey, string keyHash, string prefix) = XApiKeyHelper.Generate(); (string plainKey, string keyHash, string prefix) = XApiKeyHelper.Generate(apiKeyConfiguration.ApiKeyPrefix);
var expireAt = DateTime.UtcNow.Add(expiration.Value); var expireAt = DateTime.UtcNow.Add(expiration.Value);
// //
@@ -112,7 +113,7 @@ namespace xIds.Providers
// //
// Add Item to Database ... // Add Item to Database ...
result = await AddApiKeyAsync( result = await AddApiKeyAsync(
item: item, item: result,
userInfo: userInfo, userInfo: userInfo,
cancellationToken: cancellationToken cancellationToken: cancellationToken
); );
@@ -323,18 +324,158 @@ namespace xIds.Providers
/// </summary> /// </summary>
/// <param name="apiKey"></param> /// <param name="apiKey"></param>
/// <param name="clientIP"></param> /// <param name="clientIP"></param>
/// <param name="requiredScope"></param>
/// <param name="userInfo"></param> /// <param name="userInfo"></param>
/// <param name="cancellationToken"></param> /// <param name="cancellationToken"></param>
/// <returns></returns> /// <returns></returns>
public async Task<bool> ValidateApiKey( public async Task<XApiKeyValidationResult> ValidateApiKey(
string apiKey, string apiKey,
string clientIP, string clientIP,
string requiredScope = null,
XUserClaimsInfoDto userInfo = null, XUserClaimsInfoDto userInfo = null,
CancellationToken cancellationToken = default CancellationToken cancellationToken = default
) )
{ {
// //
var result = new XApiKeyValidationResult();
//
// Validate ...
var isValid =
!apiKey.IsNullOrEmpty() &&
!clientIP.IsNullOrEmpty();
if (!isValid)
{
return result;
}
//
// Detect Specified Api Key ...
var apiKeyHash = XApiKeyHelper.ComputeHash(apiKey);
var keyModel = await dbContext.ApiKeys
.FirstOrDefaultAsync(
ak => ak.KeyHash == apiKeyHash,
cancellationToken: cancellationToken
);
isValid = !keyModel.IsNullOrDefault();
if (!isValid)
{
//
result.Errors.Add("ApiKey not found ...");
return result;
}
//
// Here we Have to Parse Allowed Ips and Scopes ...
var allowedIps = (keyModel.AllowedIPs ?? string.Empty)
.ParseListString<string>();
var allowedScopes = (keyModel.AllowedScopes ?? string.Empty)
.FromJSON<IEnumerable<string>>();
result.Scopes = [..allowedScopes];
//
// Check Application is Exists and Active ...
var application = await dbContext.Applications
.FirstOrDefaultAsync(x => x.Id == keyModel.ApplicationId);
if (!application.IsNullOrDefault())
{
result.OwnerId = application.OwnerId;
result.ApplicationId = application.Id;
}
//
// Check Application is Exists and Active or not ...
var isApplicationActive =
//
// Application Exists ...
!application.IsNullOrDefault() &&
//
// Check Application is Active ...
application.IsActive
//
;
if (!isApplicationActive)
{
result.Errors.Add("Related Application is Inactive ...");
}
//
// Check Key is Active or not ...
var isKeyActive =
//
// Check Api Key is Active ...
// Not Revoked ...
// Not Expired ...
keyModel.IsActive()
//
;
if (!isKeyActive)
{
//
if (keyModel.IsExpired())
{
result.Errors.Add("ApiKey is Expired ...");
}
//
if (keyModel.IsRevoked())
{
result.Errors.Add("ApiKey is Revoked ...");
}
}
//
// Checking Rate Limit ...
var isRateLimitPassed = CheckRateLimit(keyModel.Id, keyModel.RateLimitPerMinute);
if (!isRateLimitPassed)
{
result.Errors.Add("ApiKey Rate Limit Reached ...");
}
//
// Audit Log ...
//
// Check Scope and IP is Valid or not ...
var isIpValid =
!allowedIps.HasChild() ||
allowedIps.Contains(clientIP);
var isScopeValid =
!allowedScopes.HasChild() ||
requiredScope.IsNullOrEmpty() ||
allowedScopes.Contains(requiredScope);
var isScopeIpValid =
isIpValid &&
isScopeValid
;
if (!isScopeIpValid)
{
//
if (!isIpValid)
{
result.Errors.Add("Client IP not Allowed to Use Resource ...");
}
//
if (!isScopeValid)
{
result.Errors.Add("Required Scoped is Invalid ...");
}
}
//
isValid =
isKeyActive &&
isScopeIpValid &&
isRateLimitPassed &&
isApplicationActive;
if (isValid)
{
result.Errors.Clear();
}
//
return result;
} }
#endregion #endregion
} }
@@ -1,10 +1,11 @@
using System;
using System.Collections.Generic;
using System.Linq; using System.Linq;
using System.Threading; using System.Threading;
using System.Threading.Tasks; using xCommons.Extensions;
using xIdentityModels.Dtos; using xIdentityModels.Dtos;
using System.Threading.Tasks;
using xIdentityModels.Models; using xIdentityModels.Models;
using System.Collections.Generic;
using Microsoft.EntityFrameworkCore;
namespace xIds.Providers namespace xIds.Providers
{ {
@@ -22,7 +23,17 @@ namespace xIds.Providers
XApiKey source, XApiKey source,
CancellationToken cancellationToken = default CancellationToken cancellationToken = default
) )
{ } {
//
var result = source.MapConvert<XApiKeyDto, XApiKey>();
result = await EnrichAsync(
source: result,
cancellationToken: cancellationToken
);
//
return result;
}
/// <summary> /// <summary>
/// Enrich Api Key ... /// Enrich Api Key ...
@@ -34,7 +45,36 @@ namespace xIds.Providers
XApiKeyDto source, XApiKeyDto source,
CancellationToken cancellationToken = default CancellationToken cancellationToken = default
) )
{ } {
//
if (
!source.IsNullOrDefault() &&
!source.Application.IsNullOrDefault()
)
{
//
var application = await dbContext.Applications
.FirstOrDefaultAsync(
x => x.Id == source.ApplicationId,
cancellationToken: cancellationToken
);
if (!application.IsNullOrDefault())
{
//
var dto = await EnrichAsync(
source: application,
cancellationToken: cancellationToken
);
if (!dto.IsNullOrDefault())
{
source.Application = dto;
}
}
}
//
return source;
}
/// <summary> /// <summary>
/// Enrich Api Key Usage ... /// Enrich Api Key Usage ...
@@ -46,7 +86,17 @@ namespace xIds.Providers
XApiKeyUsage source, XApiKeyUsage source,
CancellationToken cancellationToken = default CancellationToken cancellationToken = default
) )
{ } {
//
var result = source.MapConvert<XApiKeyUsageDto, XApiKeyUsage>();
result = await EnrichAsync(
source: result,
cancellationToken: cancellationToken
);
//
return result;
}
/// <summary> /// <summary>
/// Enrich Application ... /// Enrich Application ...
@@ -58,7 +108,17 @@ namespace xIds.Providers
XApplication source, XApplication source,
CancellationToken cancellationToken = default CancellationToken cancellationToken = default
) )
{ } {
//
var result = source.MapConvert<XApplicationDto, XApplication>();
result = await EnrichAsync(
source: result,
cancellationToken: cancellationToken
);
//
return result;
}
/// <summary> /// <summary>
/// Enrich Api Key Usage ... /// Enrich Api Key Usage ...
@@ -70,7 +130,12 @@ namespace xIds.Providers
XApiKeyUsageDto source, XApiKeyUsageDto source,
CancellationToken cancellationToken = default CancellationToken cancellationToken = default
) )
{ } {
//
// There is not any Additional Enrichment ...
var result = await Task.FromResult(source);
return result;
}
/// <summary> /// <summary>
/// Enrich Application ... /// Enrich Application ...
@@ -82,7 +147,24 @@ namespace xIds.Providers
XApplicationDto source, XApplicationDto source,
CancellationToken cancellationToken = default CancellationToken cancellationToken = default
) )
{ } {
//
if (
!source.IsNullOrDefault() &&
!source.OwnerId.IsNullOrEmpty()
)
{
//
var owner = await GetOwner(source.OwnerId);
if (!owner.IsNullOrDefault())
{
source.Owner = owner;
}
}
//
return source;
}
/// <summary> /// <summary>
/// Enrich a Collection of Api Key(s) ... /// Enrich a Collection of Api Key(s) ...
@@ -94,7 +176,17 @@ namespace xIds.Providers
IEnumerable<XApiKey> sources, IEnumerable<XApiKey> sources,
CancellationToken cancellationToken = default CancellationToken cancellationToken = default
) )
{ } {
//
var tasks = sources
.Select(s => EnrichAsync(s, cancellationToken));
//
var result = await Task.WhenAll(tasks);
//
return result;
}
/// <summary> /// <summary>
/// Enrich a Collection of Api Key(s) ... /// Enrich a Collection of Api Key(s) ...
@@ -106,7 +198,17 @@ namespace xIds.Providers
IEnumerable<XApiKeyDto> sources, IEnumerable<XApiKeyDto> sources,
CancellationToken cancellationToken = default CancellationToken cancellationToken = default
) )
{ } {
//
var tasks = sources
.Select(s => EnrichAsync(s, cancellationToken));
//
var result = await Task.WhenAll(tasks);
//
return result;
}
/// <summary> /// <summary>
/// Enrich a Collection of Api Key Usage(s) ... /// Enrich a Collection of Api Key Usage(s) ...
@@ -118,7 +220,17 @@ namespace xIds.Providers
IEnumerable<XApiKeyUsage> sources, IEnumerable<XApiKeyUsage> sources,
CancellationToken cancellationToken = default CancellationToken cancellationToken = default
) )
{ } {
//
var tasks = sources
.Select(s => EnrichAsync(s, cancellationToken));
//
var result = await Task.WhenAll(tasks);
//
return result;
}
/// <summary> /// <summary>
/// Enrich a Collection of Application(s) ... /// Enrich a Collection of Application(s) ...
@@ -130,7 +242,17 @@ namespace xIds.Providers
IEnumerable<XApplication> sources, IEnumerable<XApplication> sources,
CancellationToken cancellationToken = default CancellationToken cancellationToken = default
) )
{ } {
//
var tasks = sources
.Select(s => EnrichAsync(s, cancellationToken));
//
var result = await Task.WhenAll(tasks);
//
return result;
}
/// <summary> /// <summary>
/// Enrich a Collection of Api Key Usage(s) ... /// Enrich a Collection of Api Key Usage(s) ...
@@ -142,7 +264,17 @@ namespace xIds.Providers
IEnumerable<XApiKeyUsageDto> sources, IEnumerable<XApiKeyUsageDto> sources,
CancellationToken cancellationToken = default CancellationToken cancellationToken = default
) )
{ } {
//
var tasks = sources
.Select(s => EnrichAsync(s, cancellationToken));
//
var result = await Task.WhenAll(tasks);
//
return result;
}
/// <summary> /// <summary>
/// Enrich a Collection of Application(s) ... /// Enrich a Collection of Application(s) ...
@@ -154,7 +286,17 @@ namespace xIds.Providers
IEnumerable<XApplicationDto> sources, IEnumerable<XApplicationDto> sources,
CancellationToken cancellationToken = default CancellationToken cancellationToken = default
) )
{ } {
//
var tasks = sources
.Select(s => EnrichAsync(s, cancellationToken));
//
var result = await Task.WhenAll(tasks);
//
return result;
}
#endregion #endregion
} }
} }
+14 -10
View File
@@ -1,20 +1,20 @@
using System; using System;
using xIds.DI;
using System.IO; using System.IO;
using xIds.Constants;
using xIds.Providers;
using Newtonsoft.Json;
using xIds.Interfaces;
using System.Reflection; using System.Reflection;
using xStorageService.DI;
using xCommons.Extensions;
using xCommons.Configurations;
using Microsoft.AspNetCore.Builder; using Microsoft.AspNetCore.Builder;
using Microsoft.AspNetCore.Hosting; using Microsoft.AspNetCore.Hosting;
using Microsoft.Extensions.Configuration;
using Microsoft.Extensions.DependencyInjection;
using Microsoft.Extensions.Hosting; using Microsoft.Extensions.Hosting;
using Microsoft.Extensions.Logging; using Microsoft.Extensions.Logging;
using Newtonsoft.Json; using Microsoft.Extensions.Configuration;
using xCommons.Configurations; using Microsoft.Extensions.DependencyInjection;
using xCommons.Extensions;
using xStorageService.DI;
using xIds.Constants;
using xIds.DI;
using xIds.Interfaces;
using xIds.Providers;
namespace xIds namespace xIds
{ {
@@ -57,6 +57,10 @@ namespace xIds
// services.AddInMemoryXIdentityServer (Configuration); // services.AddInMemoryXIdentityServer (Configuration);
services.AddEfSupportXIdentityServer(Configuration); services.AddEfSupportXIdentityServer(Configuration);
//
// Services Application and Api Key Management Services ...
services.AddXApplicationProvider(Configuration);
// //
services.AddControllers() services.AddControllers()
.AddNewtonsoftJson(x => x.SerializerSettings.ReferenceLoopHandling = ReferenceLoopHandling.Ignore); .AddNewtonsoftJson(x => x.SerializerSettings.ReferenceLoopHandling = ReferenceLoopHandling.Ignore);
+1
View File
@@ -37,6 +37,7 @@
"MaxFileSize": 41943040 "MaxFileSize": 41943040
}, },
"ApiKeyConfiguration": { "ApiKeyConfiguration": {
"ApiPrefix": "xapp",
"DefaultRateLimit": 60, "DefaultRateLimit": 60,
"EnableAuditLog": false, "EnableAuditLog": false,
"MaxKeysPerApplication": "10", "MaxKeysPerApplication": "10",
+1
View File
@@ -36,6 +36,7 @@
<!-- Project Dependencies --> <!-- Project Dependencies -->
<ItemGroup> <ItemGroup>
<ProjectReference Include="..\Modules\xIdentityHelper\xIdentityHelper.csproj" /> <ProjectReference Include="..\Modules\xIdentityHelper\xIdentityHelper.csproj" />
<ProjectReference Include="..\Modules\xIdentityService\xIdentityService.csproj" />
</ItemGroup> </ItemGroup>
<!-- IdentityServer --> <!-- IdentityServer -->