Compare commits
	
		
			17 Commits
		
	
	
		
			main
			...
			feature/re
		
	
	| Author | SHA1 | Date | |
|---|---|---|---|
| cbeeebd5a6 | |||
| 0f7567ec67 | |||
|   | aeab9548b8 | ||
| 3eb6bfc60f | |||
|   | 33c0cd2642 | ||
| 8ac0eb0bf0 | |||
| 8d954c9a09 | |||
| f82ebb5e69 | |||
|   | 44ccda0736 | ||
| fd31d5dd00 | |||
|   | 57f0f39614 | ||
|   | 3acdf880f6 | ||
|   | 4fdd80db55 | ||
|   | 5b3cd5589d | ||
|   | 042588097e | ||
|   | 37dc22a114 | ||
|   | e761335737 | 
| @@ -1,95 +0,0 @@ | |||||||
| // *********************************************************************** |  | ||||||
| // <copyright file="PermissionAdapter.cs"> |  | ||||||
| //     Heath |  | ||||||
| // </copyright> |  | ||||||
| // *********************************************************************** |  | ||||||
|  |  | ||||||
| using Core.Cerberos.Adapters.Common.Constants; |  | ||||||
| using Core.Cerberos.Adapters.Common.Enums; |  | ||||||
| using MongoDB.Bson; |  | ||||||
| using MongoDB.Bson.Serialization.Attributes; |  | ||||||
| using System.Text.Json.Serialization; |  | ||||||
|  |  | ||||||
| namespace Core.Cerberos.Adapters |  | ||||||
| { |  | ||||||
|     /// <summary> |  | ||||||
|     /// Adapter for representing a permission. |  | ||||||
|     /// </summary> |  | ||||||
|     public class PermissionAdapter |  | ||||||
|     { |  | ||||||
|         /// <summary> |  | ||||||
|         /// Gets or sets the ID of the entity. |  | ||||||
|         /// </summary> |  | ||||||
|         [BsonId] |  | ||||||
|         [BsonElement("_id")] |  | ||||||
|         [BsonRepresentation(BsonType.ObjectId)] |  | ||||||
|         [JsonPropertyName("id")] |  | ||||||
|         public string Id { get; set; } = null!; |  | ||||||
|  |  | ||||||
|         /// <summary> |  | ||||||
|         /// Gets or sets the name of the entity. |  | ||||||
|         /// </summary> |  | ||||||
|         [BsonElement("name")] |  | ||||||
|         [BsonRepresentation(BsonType.String)] |  | ||||||
|         [JsonPropertyName("name")] |  | ||||||
|         public string Name { get; set; } = null!; |  | ||||||
|  |  | ||||||
|         /// <summary> |  | ||||||
|         /// Gets or sets the description of the entity. |  | ||||||
|         /// </summary> |  | ||||||
|         [BsonElement("description")] |  | ||||||
|         [BsonRepresentation(BsonType.String)] |  | ||||||
|         [JsonPropertyName("description")] |  | ||||||
|         public string? Description { get; set; } |  | ||||||
|  |  | ||||||
|         /// <summary> |  | ||||||
|         /// Gets or sets the status of the entity object. |  | ||||||
|         /// </summary> |  | ||||||
|         [BsonElement("accessLevel")] |  | ||||||
|         [BsonRepresentation(BsonType.String)] |  | ||||||
|         [JsonPropertyName("accessLevel")] |  | ||||||
|         [JsonConverter(typeof(JsonStringEnumConverter))] |  | ||||||
|         public AccessLevelEnum? AccessLevel { get; set; } = null!; |  | ||||||
|  |  | ||||||
|         /// <summary> |  | ||||||
|         /// Gets or sets the date and time when the entity was created. |  | ||||||
|         /// </summary> |  | ||||||
|         [BsonElement("createdAt")] |  | ||||||
|         [BsonRepresentation(BsonType.DateTime)] |  | ||||||
|         [JsonPropertyName("createdAt")] |  | ||||||
|         public DateTime CreatedAt { get; set; } = DateTime.UtcNow; |  | ||||||
|  |  | ||||||
|         /// <summary> |  | ||||||
|         /// Gets or sets the user who created the entity. |  | ||||||
|         /// </summary> |  | ||||||
|         [BsonElement("createdBy")] |  | ||||||
|         [BsonRepresentation(BsonType.String)] |  | ||||||
|         [JsonPropertyName("createdBy")] |  | ||||||
|         public string? CreatedBy { get; set; } |  | ||||||
|  |  | ||||||
|         /// <summary> |  | ||||||
|         /// Gets or sets the date and time when the entity was last updated. |  | ||||||
|         /// </summary> |  | ||||||
|         [BsonElement("updatedAt")] |  | ||||||
|         [BsonRepresentation(BsonType.DateTime)] |  | ||||||
|         [JsonPropertyName("updatedAt")] |  | ||||||
|         public DateTime? UpdatedAt { get; set; } = null; |  | ||||||
|  |  | ||||||
|         /// <summary> |  | ||||||
|         /// Gets or sets the user who last updated the entity. |  | ||||||
|         /// </summary> |  | ||||||
|         [BsonElement("updatedBy")] |  | ||||||
|         [BsonRepresentation(BsonType.String)] |  | ||||||
|         [JsonPropertyName("updatedBy")] |  | ||||||
|         public string? UpdatedBy { get; set; } = null; |  | ||||||
|  |  | ||||||
|         /// <summary> |  | ||||||
|         /// Gets or sets the status of the entity. |  | ||||||
|         /// </summary> |  | ||||||
|         [BsonElement("status")] |  | ||||||
|         [BsonRepresentation(BsonType.String)] |  | ||||||
|         [JsonPropertyName("status")] |  | ||||||
|         [JsonConverter(typeof(JsonStringEnumConverter))] |  | ||||||
|         public StatusEnum Status { get; set; } = StatusEnum.Active; |  | ||||||
|     } |  | ||||||
| } |  | ||||||
| @@ -1,107 +0,0 @@ | |||||||
| // *********************************************************************** |  | ||||||
| // <copyright file="RoleAdapter.cs"> |  | ||||||
| //     Heath |  | ||||||
| // </copyright> |  | ||||||
| // *********************************************************************** |  | ||||||
|  |  | ||||||
| using Core.Cerberos.Adapters.Common.Enums; |  | ||||||
| using MongoDB.Bson; |  | ||||||
| using MongoDB.Bson.Serialization.Attributes; |  | ||||||
| using System.Text.Json.Serialization; |  | ||||||
|  |  | ||||||
| namespace Core.Cerberos.Adapters |  | ||||||
| { |  | ||||||
|     /// <summary> |  | ||||||
|     /// Adapter representing a role. |  | ||||||
|     /// </summary> |  | ||||||
|     public class RoleAdapter |  | ||||||
|     { |  | ||||||
|         /// <summary> |  | ||||||
|         /// Gets or sets the unique identifier of the role. |  | ||||||
|         /// </summary> |  | ||||||
|         [BsonId] |  | ||||||
|         [BsonElement("_id")] |  | ||||||
|         [BsonRepresentation(BsonType.ObjectId)] |  | ||||||
|         [JsonPropertyName("id")] |  | ||||||
|         public string Id { get; set; } = null!; |  | ||||||
|  |  | ||||||
|         /// <summary> |  | ||||||
|         /// Gets or sets the name of the role. |  | ||||||
|         /// </summary> |  | ||||||
|         [BsonElement("name")] |  | ||||||
|         [BsonRepresentation(BsonType.String)] |  | ||||||
|         [JsonPropertyName("name")] |  | ||||||
|         public string Name { get; set; } = null!; |  | ||||||
|  |  | ||||||
|         /// <summary> |  | ||||||
|         /// Gets or sets the description of the role. |  | ||||||
|         /// </summary> |  | ||||||
|         [BsonElement("description")] |  | ||||||
|         [BsonRepresentation(BsonType.String)] |  | ||||||
|         [JsonPropertyName("description")] |  | ||||||
|         public string? Description { get; set; } |  | ||||||
|  |  | ||||||
|         /// <summary> |  | ||||||
|         /// Gets or sets the status of the entity. |  | ||||||
|         /// </summary> |  | ||||||
|         [BsonElement("applications")] |  | ||||||
|         [JsonPropertyName("applications")] |  | ||||||
|         [JsonConverter(typeof(EnumArrayJsonConverter<ApplicationsEnum>))] |  | ||||||
|         public ApplicationsEnum[]? Applications { get; set; } |  | ||||||
|  |  | ||||||
|         /// <summary> |  | ||||||
|         /// Gets or sets the modules of the role. |  | ||||||
|         /// </summary> |  | ||||||
|         [BsonElement("modules")] |  | ||||||
|         [JsonPropertyName("modules")] |  | ||||||
|         public string[] Modules { get; set; } = null!; |  | ||||||
|  |  | ||||||
|         /// <summary> |  | ||||||
|         /// Gets or sets the permissions of the role. |  | ||||||
|         /// </summary> |  | ||||||
|         [BsonElement("permissions")] |  | ||||||
|         [JsonPropertyName("permissions")] |  | ||||||
|         public string[] Permissions { get; set; } = null!; |  | ||||||
|  |  | ||||||
|         /// <summary> |  | ||||||
|         /// Gets or sets the date and time when the entity was created. |  | ||||||
|         /// </summary> |  | ||||||
|         [BsonElement("createdAt")] |  | ||||||
|         [BsonRepresentation(BsonType.DateTime)] |  | ||||||
|         [JsonPropertyName("createdAt")] |  | ||||||
|         public DateTime CreatedAt { get; set; } = DateTime.UtcNow; |  | ||||||
|  |  | ||||||
|         /// <summary> |  | ||||||
|         /// Gets or sets the user who created the entity. |  | ||||||
|         /// </summary> |  | ||||||
|         [BsonElement("createdBy")] |  | ||||||
|         [BsonRepresentation(BsonType.String)] |  | ||||||
|         [JsonPropertyName("createdBy")] |  | ||||||
|         public string? CreatedBy { get; set; } |  | ||||||
|  |  | ||||||
|         /// <summary> |  | ||||||
|         /// Gets or sets the date and time when the entity was last updated. |  | ||||||
|         /// </summary> |  | ||||||
|         [BsonElement("updatedAt")] |  | ||||||
|         [BsonRepresentation(BsonType.DateTime)] |  | ||||||
|         [JsonPropertyName("updatedAt")] |  | ||||||
|         public DateTime? UpdatedAt { get; set; } = null; |  | ||||||
|  |  | ||||||
|         /// <summary> |  | ||||||
|         /// Gets or sets the user who last updated the entity. |  | ||||||
|         /// </summary> |  | ||||||
|         [BsonElement("updatedBy")] |  | ||||||
|         [BsonRepresentation(BsonType.String)] |  | ||||||
|         [JsonPropertyName("updatedBy")] |  | ||||||
|         public string? UpdatedBy { get; set; } = null; |  | ||||||
|  |  | ||||||
|         /// <summary> |  | ||||||
|         /// Gets or sets the status of the entity. |  | ||||||
|         /// </summary> |  | ||||||
|         [BsonElement("status")] |  | ||||||
|         [BsonRepresentation(BsonType.String)] |  | ||||||
|         [JsonPropertyName("status")] |  | ||||||
|         [JsonConverter(typeof(JsonStringEnumConverter))] |  | ||||||
|         public StatusEnum Status { get; set; } = StatusEnum.Active; |  | ||||||
|     } |  | ||||||
| } |  | ||||||
							
								
								
									
										24
									
								
								Core.Cerberos.Adapters/Common/Constants/Policies.cs
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										24
									
								
								Core.Cerberos.Adapters/Common/Constants/Policies.cs
									
									
									
									
									
										Normal file
									
								
							| @@ -0,0 +1,24 @@ | |||||||
|  | using System; | ||||||
|  | using System.Collections.Generic; | ||||||
|  | namespace Core.Thalos.BuildingBlocks.Common.Constants | ||||||
|  | { | ||||||
|  |     /// <summary> | ||||||
|  |     /// Constants for policy. | ||||||
|  |     /// </summary> | ||||||
|  |     public class Policies | ||||||
|  |     { | ||||||
|  |         /// <summary> | ||||||
|  |         /// Defines the access policy for reading mobile-related data.  | ||||||
|  |         /// This policy grants read-only permissions for retrieving mobile device information,  | ||||||
|  |         /// user mobile settings, or related data as per the application's authorization scope. | ||||||
|  |         /// </summary> | ||||||
|  |         public const string Read = "Read"; | ||||||
|  |  | ||||||
|  |         /// <summary> | ||||||
|  |         /// Defines the access policy for writing mobile-related data.  | ||||||
|  |         /// This policy grants permissions to modify, update, or store mobile device information,  | ||||||
|  |         /// user mobile settings, or related data as per the application's authorization scope. | ||||||
|  |         /// </summary> | ||||||
|  |         public const string Write = "Write"; | ||||||
|  |     } | ||||||
|  | } | ||||||
							
								
								
									
										15
									
								
								Core.Cerberos.Adapters/Common/Constants/Roles.cs
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										15
									
								
								Core.Cerberos.Adapters/Common/Constants/Roles.cs
									
									
									
									
									
										Normal file
									
								
							| @@ -0,0 +1,15 @@ | |||||||
|  | namespace Core.Thalos.BuildingBlocks.Common.Constants | ||||||
|  | { | ||||||
|  |     public class Roles | ||||||
|  |     { | ||||||
|  |         /// <summary> | ||||||
|  |         /// The role for Guest. | ||||||
|  |         /// </summary> | ||||||
|  |         public const string Guest = "684909c4826cd093b4f61c11"; | ||||||
|  |  | ||||||
|  |         /// <summary> | ||||||
|  |         /// The role for Admin. | ||||||
|  |         /// </summary> | ||||||
|  |         public const string Admin = "68407642ec46a0e6fe1e8ec9"; | ||||||
|  |     } | ||||||
|  | } | ||||||
| @@ -1,52 +0,0 @@ | |||||||
| using Azure.Identity; |  | ||||||
| using Core.Cerberos.Adapters.Common.Constants; |  | ||||||
| using Microsoft.AspNetCore.Builder; |  | ||||||
| using Microsoft.Extensions.Configuration; |  | ||||||
| using Microsoft.Extensions.Configuration.AzureAppConfiguration; |  | ||||||
| using Microsoft.Extensions.Logging; |  | ||||||
|  |  | ||||||
| namespace Core.Cerberos.Adapters.Helpers |  | ||||||
| { |  | ||||||
|     public static class AuthHelper |  | ||||||
|     { |  | ||||||
|         private static readonly ILogger logger = LoggerFactory.Create(builder => |  | ||||||
|         { |  | ||||||
|             builder.AddConsole(); |  | ||||||
|         }).CreateLogger("AuthHelper"); |  | ||||||
|  |  | ||||||
|  |  | ||||||
|         public static AuthSettings GetAuthSettings(WebApplicationBuilder builder, string appConfigLabel) |  | ||||||
|         { |  | ||||||
|             builder.Configuration.AddAzureAppConfiguration(options => |  | ||||||
|             { |  | ||||||
|                 var endpoint = builder.Configuration.GetSection("Endpoints:AppConfigurationURI").Value; |  | ||||||
|  |  | ||||||
|                 if (string.IsNullOrEmpty(endpoint)) |  | ||||||
|                     throw new ArgumentException("The app configuration is missing"); |  | ||||||
|  |  | ||||||
|                 options.Connect(new Uri(endpoint), new DefaultAzureCredential()) |  | ||||||
|                        .Select(KeyFilter.Any, "cerberos_common") |  | ||||||
|                        .Select(KeyFilter.Any, appConfigLabel); |  | ||||||
|  |  | ||||||
|                 options.ConfigureKeyVault(keyVaultOptions => |  | ||||||
|                 { |  | ||||||
|                     keyVaultOptions.SetCredential(new DefaultAzureCredential()); |  | ||||||
|                 }); |  | ||||||
|             }); |  | ||||||
|  |  | ||||||
|             return new AuthSettings |  | ||||||
|             { |  | ||||||
|                 AzureADInstance = builder.Configuration.GetSection(Secrets.AzureADInstance).Value, |  | ||||||
|                 AzureADTenantId = builder.Configuration.GetSection(Secrets.AzureADTenantId).Value, |  | ||||||
|                 AzureADClientId = builder.Configuration.GetSection(Secrets.AzureADClientId).Value, |  | ||||||
|                 AzureADClientSecret = builder.Configuration.GetSection(Secrets.AzureADClientSecret).Value, |  | ||||||
|                 HeathCerberosAppAuthorizationUrl = builder.Configuration.GetSection(Secrets.HeathCerberosAppAuthorizationUrl).Value, |  | ||||||
|                 HeathCerberosAppTokenUrl = builder.Configuration.GetSection(Secrets.HeathCerberosAppTokenUrl).Value, |  | ||||||
|                 HeathCerberosAppClientId = builder.Configuration.GetSection(Secrets.HeathCerberosAppClientId).Value, |  | ||||||
|                 HeathCerberosAppScope = builder.Configuration.GetSection(Secrets.HeathCerberosAppScope).Value, |  | ||||||
|                 PrivateKey = builder.Configuration.GetSection(Secrets.PrivateKey).Value, |  | ||||||
|                 PublicKey = builder.Configuration.GetSection(Secrets.PublicKey).Value, |  | ||||||
|             }; |  | ||||||
|         } |  | ||||||
|     } |  | ||||||
| } |  | ||||||
| @@ -1,25 +0,0 @@ | |||||||
| // *********************************************************************** |  | ||||||
| // <copyright file="AuthSettings.cs"> |  | ||||||
| //     Heath |  | ||||||
| // </copyright> |  | ||||||
| // *********************************************************************** |  | ||||||
|  |  | ||||||
| public class AuthSettings |  | ||||||
| { |  | ||||||
|     // Azure AD Settings |  | ||||||
|     public string? AzureADInstance { get; set; } |  | ||||||
|     public string? AzureADTenantId { get; set; } |  | ||||||
|     public string? AzureADClientId { get; set; } |  | ||||||
|     public string? AzureADClientSecret { get; set; } |  | ||||||
|  |  | ||||||
|     // Heath Cerberos App Settings |  | ||||||
|     public string? HeathCerberosAppAuthorizationUrl { get; set; } |  | ||||||
|     public string? HeathCerberosAppTokenUrl { get; set; } |  | ||||||
|     public string? HeathCerberosAppClientId { get; set; } |  | ||||||
|     public string? HeathCerberosAppScope { get; set; } |  | ||||||
|  |  | ||||||
|     // Token Keys |  | ||||||
|     public string? PrivateKey { get; set; } |  | ||||||
|     public string? PublicKey { get; set; } |  | ||||||
| } |  | ||||||
|  |  | ||||||
| @@ -3,7 +3,7 @@ Microsoft Visual Studio Solution File, Format Version 12.00 | |||||||
| # Visual Studio Version 17 | # Visual Studio Version 17 | ||||||
| VisualStudioVersion = 17.10.34928.147 | VisualStudioVersion = 17.10.34928.147 | ||||||
| MinimumVisualStudioVersion = 10.0.40219.1 | MinimumVisualStudioVersion = 10.0.40219.1 | ||||||
| Project("{9A19103F-16F7-4668-BE54-9A1E7A4F7556}") = "Core.Cerberos.Adapters", "Core.Cerberos.Adapters\Core.Cerberos.Adapters.csproj", "{C902AB37-E6D1-4CE7-B271-0E3969C989F3}" | Project("{9A19103F-16F7-4668-BE54-9A1E7A4F7556}") = "Core.Thalos.BuildingBlocks", "Core.Thalos.BuildingBlocks\Core.Thalos.BuildingBlocks.csproj", "{C902AB37-E6D1-4CE7-B271-0E3969C989F3}" | ||||||
| EndProject | EndProject | ||||||
| Global | Global | ||||||
| 	GlobalSection(SolutionConfigurationPlatforms) = preSolution | 	GlobalSection(SolutionConfigurationPlatforms) = preSolution | ||||||
| @@ -1,11 +1,6 @@ | |||||||
| using System; | using System.Text.Json; | ||||||
| using System.Collections.Generic; |  | ||||||
| using System.Linq; |  | ||||||
| using System.Text; |  | ||||||
| using System.Text.Json; |  | ||||||
| using System.Threading.Tasks; |  | ||||||
| 
 | 
 | ||||||
| namespace Core.Cerberos.Adapters | namespace Core.Thalos.BuildingBlocks | ||||||
| { | { | ||||||
|     public class BaseAdapterResponse |     public class BaseAdapterResponse | ||||||
|     { |     { | ||||||
| @@ -1,30 +1,22 @@ | |||||||
| // *********************************************************************** | // *********************************************************************** | ||||||
| // <copyright file="ModuleAdapter.cs"> | // <copyright file="ModuleAdapter.cs"> | ||||||
| //     Heath | //     AgileWebs | ||||||
| // </copyright> | // </copyright> | ||||||
| // *********************************************************************** | // *********************************************************************** | ||||||
| 
 | 
 | ||||||
| using Core.Cerberos.Adapters.Common.Enums; | using Core.Blueprint.Mongo; | ||||||
| using MongoDB.Bson; | using MongoDB.Bson; | ||||||
| using MongoDB.Bson.Serialization.Attributes; | using MongoDB.Bson.Serialization.Attributes; | ||||||
| using System.Text.Json.Serialization; | using System.Text.Json.Serialization; | ||||||
| 
 | 
 | ||||||
| namespace Core.Cerberos.Adapters | namespace Core.Thalos.BuildingBlocks | ||||||
| { | { | ||||||
|     /// <summary> |     /// <summary> | ||||||
|     /// Adapter for representing a module. |     /// Adapter for representing a module. | ||||||
|     /// </summary> |     /// </summary> | ||||||
|     public class ModuleAdapter |     [CollectionAttributeName("Modules")] | ||||||
|  |     public class ModuleAdapter : Document | ||||||
|     { |     { | ||||||
|         /// <summary> |  | ||||||
|         /// Gets or sets the ID of the module. |  | ||||||
|         /// </summary> |  | ||||||
|         [BsonId] |  | ||||||
|         [BsonElement("_id")] |  | ||||||
|         [BsonRepresentation(BsonType.ObjectId)] |  | ||||||
|         [JsonPropertyName("id")] |  | ||||||
|         public string Id { get; set; } = null!; |  | ||||||
| 
 |  | ||||||
|         /// <summary> |         /// <summary> | ||||||
|         /// Gets or sets the name of the module. |         /// Gets or sets the name of the module. | ||||||
|         /// </summary> |         /// </summary> | ||||||
| @@ -73,46 +65,5 @@ namespace Core.Cerberos.Adapters | |||||||
|         [JsonPropertyName("application")] |         [JsonPropertyName("application")] | ||||||
|         [JsonConverter(typeof(JsonStringEnumConverter))] |         [JsonConverter(typeof(JsonStringEnumConverter))] | ||||||
|         public ApplicationsEnum? Application { get; set; } = null!; |         public ApplicationsEnum? Application { get; set; } = null!; | ||||||
| 
 |  | ||||||
|         /// <summary> |  | ||||||
|         /// Gets or sets the date and time when the module was created. |  | ||||||
|         /// </summary> |  | ||||||
|         [BsonElement("createdAt")] |  | ||||||
|         [BsonRepresentation(BsonType.DateTime)] |  | ||||||
|         [JsonPropertyName("createdAt")] |  | ||||||
|         public DateTime CreatedAt { get; set; } = DateTime.UtcNow; |  | ||||||
| 
 |  | ||||||
|         /// <summary> |  | ||||||
|         /// Gets or sets the user who created the module. |  | ||||||
|         /// </summary> |  | ||||||
|         [BsonElement("createdBy")] |  | ||||||
|         [BsonRepresentation(BsonType.String)] |  | ||||||
|         [JsonPropertyName("createdBy")] |  | ||||||
|         public string? CreatedBy { get; set; } |  | ||||||
| 
 |  | ||||||
|         /// <summary> |  | ||||||
|         /// Gets or sets the date and time when the module was last updated. |  | ||||||
|         /// </summary> |  | ||||||
|         [BsonElement("updatedAt")] |  | ||||||
|         [BsonRepresentation(BsonType.DateTime)] |  | ||||||
|         [JsonPropertyName("updatedAt")] |  | ||||||
|         public DateTime? UpdatedAt { get; set; } = null; |  | ||||||
| 
 |  | ||||||
|         /// <summary> |  | ||||||
|         /// Gets or sets the user who last updated the module. |  | ||||||
|         /// </summary> |  | ||||||
|         [BsonElement("updatedBy")] |  | ||||||
|         [BsonRepresentation(BsonType.String)] |  | ||||||
|         [JsonPropertyName("updatedBy")] |  | ||||||
|         public string? UpdatedBy { get; set; } = null; |  | ||||||
| 
 |  | ||||||
|         /// <summary> |  | ||||||
|         /// Gets or sets the status of the module. |  | ||||||
|         /// </summary> |  | ||||||
|         [BsonElement("status")] |  | ||||||
|         [BsonRepresentation(BsonType.String)] |  | ||||||
|         [JsonPropertyName("status")] |  | ||||||
|         [JsonConverter(typeof(JsonStringEnumConverter))] |  | ||||||
|         public StatusEnum Status { get; set; } = StatusEnum.Active; |  | ||||||
|     } |     } | ||||||
| } | } | ||||||
							
								
								
									
										45
									
								
								Core.Thalos.BuildingBlocks/Adapters/PermissionAdapter.cs
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										45
									
								
								Core.Thalos.BuildingBlocks/Adapters/PermissionAdapter.cs
									
									
									
									
									
										Normal file
									
								
							| @@ -0,0 +1,45 @@ | |||||||
|  | // *********************************************************************** | ||||||
|  | // <copyright file="PermissionAdapter.cs"> | ||||||
|  | //     AgileWebs | ||||||
|  | // </copyright> | ||||||
|  | // *********************************************************************** | ||||||
|  |  | ||||||
|  | using Core.Blueprint.Mongo; | ||||||
|  | using MongoDB.Bson; | ||||||
|  | using MongoDB.Bson.Serialization.Attributes; | ||||||
|  | using System.Text.Json.Serialization; | ||||||
|  |  | ||||||
|  | namespace Core.Thalos.BuildingBlocks | ||||||
|  | { | ||||||
|  |     /// <summary> | ||||||
|  |     /// Adapter for representing a permission. | ||||||
|  |     /// </summary> | ||||||
|  |     [CollectionAttributeName("Permissions")] | ||||||
|  |     public class PermissionAdapter : Document | ||||||
|  |     { | ||||||
|  |         /// <summary> | ||||||
|  |         /// Gets or sets the name of the entity. | ||||||
|  |         /// </summary> | ||||||
|  |         [BsonElement("name")] | ||||||
|  |         [BsonRepresentation(BsonType.String)] | ||||||
|  |         [JsonPropertyName("name")] | ||||||
|  |         public string Name { get; set; } = null!; | ||||||
|  |  | ||||||
|  |         /// <summary> | ||||||
|  |         /// Gets or sets the description of the entity. | ||||||
|  |         /// </summary> | ||||||
|  |         [BsonElement("description")] | ||||||
|  |         [BsonRepresentation(BsonType.String)] | ||||||
|  |         [JsonPropertyName("description")] | ||||||
|  |         public string? Description { get; set; } | ||||||
|  |  | ||||||
|  |         /// <summary> | ||||||
|  |         /// Gets or sets the status of the entity object. | ||||||
|  |         /// </summary> | ||||||
|  |         [BsonElement("accessLevel")] | ||||||
|  |         [BsonRepresentation(BsonType.String)] | ||||||
|  |         [JsonPropertyName("accessLevel")] | ||||||
|  |         [JsonConverter(typeof(JsonStringEnumConverter))] | ||||||
|  |         public AccessLevelEnum? AccessLevel { get; set; } = null!; | ||||||
|  |     } | ||||||
|  | } | ||||||
| @@ -1,6 +1,6 @@ | |||||||
| using Microsoft.AspNetCore.Authorization; | using Microsoft.AspNetCore.Authorization; | ||||||
| 
 | 
 | ||||||
| namespace Core.Cerberos.Adapters.Handlers.Adapters | namespace Core.Thalos.BuildingBlocks | ||||||
| { | { | ||||||
|     public class PermissionsAuthorizationAdapter : IAuthorizationRequirement |     public class PermissionsAuthorizationAdapter : IAuthorizationRequirement | ||||||
|     { |     { | ||||||
							
								
								
									
										58
									
								
								Core.Thalos.BuildingBlocks/Adapters/RoleAdapter.cs
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										58
									
								
								Core.Thalos.BuildingBlocks/Adapters/RoleAdapter.cs
									
									
									
									
									
										Normal file
									
								
							| @@ -0,0 +1,58 @@ | |||||||
|  | // *********************************************************************** | ||||||
|  | // <copyright file="RoleAdapter.cs"> | ||||||
|  | //     AgileWebs | ||||||
|  | // </copyright> | ||||||
|  | // *********************************************************************** | ||||||
|  |  | ||||||
|  | using Core.Blueprint.Mongo; | ||||||
|  | using MongoDB.Bson; | ||||||
|  | using MongoDB.Bson.Serialization.Attributes; | ||||||
|  | using System.Text.Json.Serialization; | ||||||
|  |  | ||||||
|  | namespace Core.Thalos.BuildingBlocks | ||||||
|  | { | ||||||
|  |     /// <summary> | ||||||
|  |     /// Adapter representing a role. | ||||||
|  |     /// </summary> | ||||||
|  |     [CollectionAttributeName("Roles")] | ||||||
|  |     public class RoleAdapter : Document | ||||||
|  |     { | ||||||
|  |         /// <summary> | ||||||
|  |         /// Gets or sets the name of the role. | ||||||
|  |         /// </summary> | ||||||
|  |         [BsonElement("name")] | ||||||
|  |         [BsonRepresentation(BsonType.String)] | ||||||
|  |         [JsonPropertyName("name")] | ||||||
|  |         public string Name { get; set; } = null!; | ||||||
|  |  | ||||||
|  |         /// <summary> | ||||||
|  |         /// Gets or sets the description of the role. | ||||||
|  |         /// </summary> | ||||||
|  |         [BsonElement("description")] | ||||||
|  |         [BsonRepresentation(BsonType.String)] | ||||||
|  |         [JsonPropertyName("description")] | ||||||
|  |         public string? Description { get; set; } | ||||||
|  |  | ||||||
|  |         /// <summary> | ||||||
|  |         /// Gets or sets the status of the entity. | ||||||
|  |         /// </summary> | ||||||
|  |         [BsonElement("applications")] | ||||||
|  |         [JsonPropertyName("applications")] | ||||||
|  |         [JsonConverter(typeof(EnumArrayJsonConverter<ApplicationsEnum>))] | ||||||
|  |         public ApplicationsEnum[]? Applications { get; set; } | ||||||
|  |  | ||||||
|  |         /// <summary> | ||||||
|  |         /// Gets or sets the modules of the role. | ||||||
|  |         /// </summary> | ||||||
|  |         [BsonElement("modules")] | ||||||
|  |         [JsonPropertyName("modules")] | ||||||
|  |         public string[] Modules { get; set; } = null!; | ||||||
|  |  | ||||||
|  |         /// <summary> | ||||||
|  |         /// Gets or sets the permissions of the role. | ||||||
|  |         /// </summary> | ||||||
|  |         [BsonElement("permissions")] | ||||||
|  |         [JsonPropertyName("permissions")] | ||||||
|  |         public string[] Permissions { get; set; } = null!; | ||||||
|  |     } | ||||||
|  | } | ||||||
| @@ -1,10 +1,10 @@ | |||||||
| // *********************************************************************** | // *********************************************************************** | ||||||
| // <copyright file="TokenAdapter.cs"> | // <copyright file="TokenAdapter.cs"> | ||||||
| //     Heath | //     AgileWebs | ||||||
| // </copyright> | // </copyright> | ||||||
| // *********************************************************************** | // *********************************************************************** | ||||||
| 
 | 
 | ||||||
| namespace Core.Cerberos.Adapters | namespace Core.Thalos.BuildingBlocks | ||||||
| { | { | ||||||
|     public class TokenAdapter |     public class TokenAdapter | ||||||
|     { |     { | ||||||
| @@ -13,6 +13,6 @@ namespace Core.Cerberos.Adapters | |||||||
|         public RoleAdapter? Role { get; set; } |         public RoleAdapter? Role { get; set; } | ||||||
| 
 | 
 | ||||||
|         public IEnumerable<PermissionAdapter>? Permissions { get; set; } |         public IEnumerable<PermissionAdapter>? Permissions { get; set; } | ||||||
|         public IEnumerable<ModuleAdapter>? Modules { get; set; } |         public IEnumerable<ModuleAdapter> Modules { get; set; } = null!; | ||||||
|     } |     } | ||||||
| } | } | ||||||
| @@ -1,29 +1,21 @@ | |||||||
| // *********************************************************************** | // *********************************************************************** | ||||||
| // <copyright file="UserAdapter.cs"> | // <copyright file="UserAdapter.cs"> | ||||||
| //     Heath | //     AgileWebs | ||||||
| // </copyright> | // </copyright> | ||||||
| // *********************************************************************** | // *********************************************************************** | ||||||
| using Core.Cerberos.Adapters.Common.Enums; | using Core.Blueprint.Mongo; | ||||||
| using MongoDB.Bson; | using MongoDB.Bson; | ||||||
| using MongoDB.Bson.Serialization.Attributes; | using MongoDB.Bson.Serialization.Attributes; | ||||||
| using System.Text.Json.Serialization; | using System.Text.Json.Serialization; | ||||||
| 
 | 
 | ||||||
| namespace Core.Cerberos.Adapters | namespace Core.Thalos.BuildingBlocks | ||||||
| { | { | ||||||
|     /// <summary> |     /// <summary> | ||||||
|     /// Adapter representing a user. |     /// Adapter representing a user. | ||||||
|     /// </summary> |     /// </summary> | ||||||
|     public class UserAdapter : BaseAdapterResponse |     [CollectionAttributeName("Users")] | ||||||
|  |     public class UserAdapter : Document | ||||||
|     { |     { | ||||||
|         /// <summary> |  | ||||||
|         /// Gets or sets the unique identifier of the user. |  | ||||||
|         /// </summary> |  | ||||||
|         [BsonId] |  | ||||||
|         [BsonElement("_id")] |  | ||||||
|         [BsonRepresentation(BsonType.ObjectId)] |  | ||||||
|         [JsonPropertyName("id")] |  | ||||||
|         public string Id { get; set; } = null!; |  | ||||||
| 
 |  | ||||||
|         /// <summary> |         /// <summary> | ||||||
|         /// Gets or sets the guid of the user. |         /// Gets or sets the guid of the user. | ||||||
|         /// </summary> |         /// </summary> | ||||||
| @@ -126,46 +118,5 @@ namespace Core.Cerberos.Adapters | |||||||
|         [BsonRepresentation(BsonType.String)] |         [BsonRepresentation(BsonType.String)] | ||||||
|         [JsonPropertyName("token")] |         [JsonPropertyName("token")] | ||||||
|         public string? Token { get; set; } = null; |         public string? Token { get; set; } = null; | ||||||
| 
 |  | ||||||
|         /// <summary> |  | ||||||
|         /// Gets or sets the date and time when the entity was created. |  | ||||||
|         /// </summary> |  | ||||||
|         [BsonElement("createdAt")] |  | ||||||
|         [BsonRepresentation(BsonType.DateTime)] |  | ||||||
|         [JsonPropertyName("createdAt")] |  | ||||||
|         public DateTime CreatedAt { get; set; } = DateTime.UtcNow; |  | ||||||
| 
 |  | ||||||
|         /// <summary> |  | ||||||
|         /// Gets or sets the user who created the entity. |  | ||||||
|         /// </summary> |  | ||||||
|         [BsonElement("createdBy")] |  | ||||||
|         [BsonRepresentation(BsonType.String)] |  | ||||||
|         [JsonPropertyName("createdBy")] |  | ||||||
|         public string? CreatedBy { get; set; } |  | ||||||
| 
 |  | ||||||
|         /// <summary> |  | ||||||
|         /// Gets or sets the date and time when the entity was last updated. |  | ||||||
|         /// </summary> |  | ||||||
|         [BsonElement("updatedAt")] |  | ||||||
|         [BsonRepresentation(BsonType.DateTime)] |  | ||||||
|         [JsonPropertyName("updatedAt")] |  | ||||||
|         public DateTime? UpdatedAt { get; set; } = null; |  | ||||||
| 
 |  | ||||||
|         /// <summary> |  | ||||||
|         /// Gets or sets the user who last updated the entity. |  | ||||||
|         /// </summary> |  | ||||||
|         [BsonElement("updatedBy")] |  | ||||||
|         [BsonRepresentation(BsonType.String)] |  | ||||||
|         [JsonPropertyName("updatedBy")] |  | ||||||
|         public string? UpdatedBy { get; set; } = null; |  | ||||||
| 
 |  | ||||||
|         /// <summary> |  | ||||||
|         /// Gets or sets the status of the entity. |  | ||||||
|         /// </summary> |  | ||||||
|         [BsonElement("status")] |  | ||||||
|         [BsonRepresentation(BsonType.String)] |  | ||||||
|         [JsonPropertyName("status")] |  | ||||||
|         [JsonConverter(typeof(JsonStringEnumConverter))] |  | ||||||
|         public StatusEnum Status { get; set; } = StatusEnum.Active; |  | ||||||
|     } |     } | ||||||
| } | } | ||||||
| @@ -1,12 +1,12 @@ | |||||||
| // *********************************************************************** | // *********************************************************************** | ||||||
| // <copyright file="UserExistenceAdapter.cs"> | // <copyright file="UserExistenceAdapter.cs"> | ||||||
| //     Heath | //     AgileWebs | ||||||
| // </copyright> | // </copyright> | ||||||
| // *********************************************************************** | // *********************************************************************** | ||||||
| 
 | 
 | ||||||
| using System.Text.Json.Serialization; | using System.Text.Json.Serialization; | ||||||
| 
 | 
 | ||||||
| namespace Core.Cerberos.Adapters | namespace Core.Thalos.BuildingBlocks | ||||||
| { | { | ||||||
|     /// <summary> |     /// <summary> | ||||||
|     /// Adapter representing a user. |     /// Adapter representing a user. | ||||||
| @@ -1,4 +1,4 @@ | |||||||
| namespace Core.Cerberos.Adapters | namespace Core.Thalos.BuildingBlocks | ||||||
| { | { | ||||||
|     public class Permission |     public class Permission | ||||||
|     { |     { | ||||||
| @@ -2,7 +2,7 @@ | |||||||
| using Microsoft.AspNetCore.Mvc; | using Microsoft.AspNetCore.Mvc; | ||||||
| using Microsoft.AspNetCore.Mvc.Filters; | using Microsoft.AspNetCore.Mvc.Filters; | ||||||
| 
 | 
 | ||||||
| namespace Core.Cerberos.Adapters.Attributes | namespace Core.Thalos.BuildingBlocks | ||||||
| { | { | ||||||
|     /// <summary> |     /// <summary> | ||||||
|     /// Custom authorization attribute that checks if the user has any of the required permissions. |     /// Custom authorization attribute that checks if the user has any of the required permissions. | ||||||
| @@ -0,0 +1,37 @@ | |||||||
|  | using Google.Apis.Auth.OAuth2; | ||||||
|  | using Google.Apis.Auth.OAuth2.Flows; | ||||||
|  | using Microsoft.Extensions.Configuration; | ||||||
|  |  | ||||||
|  | namespace Core.Thalos.BuildingBlocks | ||||||
|  | { | ||||||
|  |     public class GoogleAuthorization( | ||||||
|  |         IGoogleAuthHelper googleHelper, IConfiguration config) : IGoogleAuthorization | ||||||
|  |     { | ||||||
|  |         private string RedirectUrl = config["Authentication:Google:RedirectUri"]!; | ||||||
|  |  | ||||||
|  |         public async Task<UserCredential> ExchangeCodeForToken(string code) | ||||||
|  |         { | ||||||
|  |             var flow = new GoogleAuthorizationCodeFlow( | ||||||
|  |                 new GoogleAuthorizationCodeFlow.Initializer | ||||||
|  |                 { | ||||||
|  |                     ClientSecrets = googleHelper.GetClientSecrets(), | ||||||
|  |                     Scopes = googleHelper.GetScopes() | ||||||
|  |                 }); | ||||||
|  |  | ||||||
|  |             var token = await flow.ExchangeCodeForTokenAsync( | ||||||
|  |                 "user", code, RedirectUrl, CancellationToken.None); | ||||||
|  |  | ||||||
|  |             return new UserCredential(flow, "user", token); | ||||||
|  |         } | ||||||
|  |  | ||||||
|  |         public string GetAuthorizationUrl() => | ||||||
|  |             new GoogleAuthorizationCodeFlow( | ||||||
|  |                 new GoogleAuthorizationCodeFlow.Initializer | ||||||
|  |                 { | ||||||
|  |  | ||||||
|  |                     ClientSecrets = googleHelper.GetClientSecrets(), | ||||||
|  |                     Scopes = googleHelper.GetScopes(), | ||||||
|  |                     Prompt = "consent" | ||||||
|  |                 }).CreateAuthorizationCodeRequest(RedirectUrl).Build().ToString(); | ||||||
|  |     } | ||||||
|  | } | ||||||
| @@ -0,0 +1,10 @@ | |||||||
|  | using Google.Apis.Auth.OAuth2; | ||||||
|  |  | ||||||
|  | namespace Core.Thalos.BuildingBlocks | ||||||
|  | { | ||||||
|  |     public interface IGoogleAuthorization | ||||||
|  |     { | ||||||
|  |         string GetAuthorizationUrl(); | ||||||
|  |         Task<UserCredential> ExchangeCodeForToken(string code); | ||||||
|  |     } | ||||||
|  | } | ||||||
| @@ -1,12 +1,12 @@ | |||||||
| // *********************************************************************** | // *********************************************************************** | ||||||
| // <copyright file="AccessLevelEnum.cs"> | // <copyright file="AccessLevelEnum.cs"> | ||||||
| //     Heath | //     AgileWebs | ||||||
| // </copyright> | // </copyright> | ||||||
| // *********************************************************************** | // *********************************************************************** | ||||||
| 
 | 
 | ||||||
| using System.Text.Json.Serialization; | using System.Text.Json.Serialization; | ||||||
| 
 | 
 | ||||||
| namespace Core.Cerberos.Adapters.Common.Constants | namespace Core.Thalos.BuildingBlocks | ||||||
| { | { | ||||||
|     /// <summary> |     /// <summary> | ||||||
|     /// Specifies different access level for a permission. |     /// Specifies different access level for a permission. | ||||||
| @@ -1,9 +1,9 @@ | |||||||
| // *********************************************************************** | // *********************************************************************** | ||||||
| // <copyright file="AzureAd.cs"> | // <copyright file="AzureAd.cs"> | ||||||
| //     Heath | //     AgileWebs | ||||||
| // </copyright> | // </copyright> | ||||||
| // *********************************************************************** | // *********************************************************************** | ||||||
| namespace Core.Cerberos.Adapters.Common.Constants | namespace Core.Thalos.BuildingBlocks | ||||||
| { | { | ||||||
|     /// <summary> |     /// <summary> | ||||||
|     /// Constants for Azure Active Directory. |     /// Constants for Azure Active Directory. | ||||||
| @@ -1,9 +1,9 @@ | |||||||
| // *********************************************************************** | // *********************************************************************** | ||||||
| // <copyright file="Claims.cs"> | // <copyright file="Claims.cs"> | ||||||
| //     Heath | //     AgileWebs | ||||||
| // </copyright> | // </copyright> | ||||||
| // *********************************************************************** | // *********************************************************************** | ||||||
| namespace Core.Cerberos.Adapters.Common.Constants | namespace Core.Thalos.BuildingBlocks | ||||||
| { | { | ||||||
|     /// <summary> |     /// <summary> | ||||||
|     /// Constants for claims used in JWT tokens. |     /// Constants for claims used in JWT tokens. | ||||||
| @@ -1,4 +1,4 @@ | |||||||
| namespace Core.Cerberos.Adapters.Common.Constants | namespace Core.Thalos.BuildingBlocks | ||||||
| { | { | ||||||
|     public static class CollectionNames |     public static class CollectionNames | ||||||
|     { |     { | ||||||
| @@ -1,10 +1,10 @@ | |||||||
| // *********************************************************************** | // *********************************************************************** | ||||||
| // <copyright file="EnvironmentVariables.cs"> | // <copyright file="EnvironmentVariables.cs"> | ||||||
| //     Heath | //     AgileWebs | ||||||
| // </copyright> | // </copyright> | ||||||
| // *********************************************************************** | // *********************************************************************** | ||||||
| 
 | 
 | ||||||
| namespace Core.Cerberos.Adapters.Common.Constants | namespace Core.Thalos.BuildingBlocks | ||||||
| { | { | ||||||
|     /// <summary> |     /// <summary> | ||||||
|     /// Constants of the environment variables for this service. |     /// Constants of the environment variables for this service. | ||||||
| @@ -1,9 +1,9 @@ | |||||||
| // *********************************************************************** | // *********************************************************************** | ||||||
| // <copyright file="KeyVaultConfiguration.cs"> | // <copyright file="KeyVaultConfiguration.cs"> | ||||||
| //     Heath | //     AgileWebs | ||||||
| // </copyright> | // </copyright> | ||||||
| // *********************************************************************** | // *********************************************************************** | ||||||
| namespace Core.Cerberos.Adapters.Common.Constants | namespace Core.Thalos.BuildingBlocks | ||||||
| { | { | ||||||
|     /// <summary> |     /// <summary> | ||||||
|     /// Constants for Key Vault configuration. |     /// Constants for Key Vault configuration. | ||||||
| @@ -6,7 +6,7 @@ | |||||||
| 
 | 
 | ||||||
| using System.Globalization; | using System.Globalization; | ||||||
| 
 | 
 | ||||||
| namespace Core.Cerberos.Adapters.Common.Constants | namespace Core.Thalos.BuildingBlocks | ||||||
| { | { | ||||||
|     /// <summary> |     /// <summary> | ||||||
|     /// Constants for the mime types. |     /// Constants for the mime types. | ||||||
							
								
								
									
										24
									
								
								Core.Thalos.BuildingBlocks/Common/Constants/Policies.cs
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										24
									
								
								Core.Thalos.BuildingBlocks/Common/Constants/Policies.cs
									
									
									
									
									
										Normal file
									
								
							| @@ -0,0 +1,24 @@ | |||||||
|  | using System; | ||||||
|  | using System.Collections.Generic; | ||||||
|  | namespace Core.Thalos.BuildingBlocks | ||||||
|  | { | ||||||
|  |     /// <summary> | ||||||
|  |     /// Constants for policy. | ||||||
|  |     /// </summary> | ||||||
|  |     public class Policies | ||||||
|  |     { | ||||||
|  |         /// <summary> | ||||||
|  |         /// Defines the access policy for reading mobile-related data.  | ||||||
|  |         /// This policy grants read-only permissions for retrieving mobile device information,  | ||||||
|  |         /// user mobile settings, or related data as per the application's authorization scope. | ||||||
|  |         /// </summary> | ||||||
|  |         public const string Read = "Read"; | ||||||
|  |  | ||||||
|  |         /// <summary> | ||||||
|  |         /// Defines the access policy for writing mobile-related data.  | ||||||
|  |         /// This policy grants permissions to modify, update, or store mobile device information,  | ||||||
|  |         /// user mobile settings, or related data as per the application's authorization scope. | ||||||
|  |         /// </summary> | ||||||
|  |         public const string Write = "Write"; | ||||||
|  |     } | ||||||
|  | } | ||||||
							
								
								
									
										15
									
								
								Core.Thalos.BuildingBlocks/Common/Constants/Roles.cs
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										15
									
								
								Core.Thalos.BuildingBlocks/Common/Constants/Roles.cs
									
									
									
									
									
										Normal file
									
								
							| @@ -0,0 +1,15 @@ | |||||||
|  | namespace Core.Thalos.BuildingBlocks | ||||||
|  | { | ||||||
|  |     public class Roles | ||||||
|  |     { | ||||||
|  |         /// <summary> | ||||||
|  |         /// The role for Guest. | ||||||
|  |         /// </summary> | ||||||
|  |         public const string Guest = "684909c4826cd093b4f61c11"; | ||||||
|  |  | ||||||
|  |         /// <summary> | ||||||
|  |         /// The role for Admin. | ||||||
|  |         /// </summary> | ||||||
|  |         public const string Admin = "68407642ec46a0e6fe1e8ec9"; | ||||||
|  |     } | ||||||
|  | } | ||||||
| @@ -1,10 +1,10 @@ | |||||||
| // *********************************************************************** | // *********************************************************************** | ||||||
| // <copyright file="Routes.cs"> | // <copyright file="Routes.cs"> | ||||||
| //     Heath | //     AgileWebs | ||||||
| // </copyright> | // </copyright> | ||||||
| // *********************************************************************** | // *********************************************************************** | ||||||
| 
 | 
 | ||||||
| namespace Core.Cerberos.Adapters.Common.Constants | namespace Core.Thalos.BuildingBlocks | ||||||
| { | { | ||||||
|     /// <summary> |     /// <summary> | ||||||
|     /// Constants of the routes of this service. |     /// Constants of the routes of this service. | ||||||
| @@ -1,4 +1,4 @@ | |||||||
| namespace Core.Cerberos.Adapters.Common.Constants | namespace Core.Thalos.BuildingBlocks | ||||||
| { | { | ||||||
|     /// <summary> |     /// <summary> | ||||||
|     /// Constants for schemes. |     /// Constants for schemes. | ||||||
| @@ -6,13 +6,18 @@ | |||||||
|     public class Schemes |     public class Schemes | ||||||
|     { |     { | ||||||
|         /// <summary> |         /// <summary> | ||||||
|         /// The heath scheme. |         /// The default scheme. | ||||||
|         /// </summary> |         /// </summary> | ||||||
|         public const string HeathScheme = "HeathScheme"; |         public const string DefaultScheme = "DefaultScheme"; | ||||||
| 
 | 
 | ||||||
|         /// <summary> |         /// <summary> | ||||||
|         /// The azure scheme. |         /// The azure scheme. | ||||||
|         /// </summary> |         /// </summary> | ||||||
|         public const string AzureScheme = "AzureScheme"; |         public const string AzureScheme = "AzureScheme"; | ||||||
|  | 
 | ||||||
|  |         /// <summary> | ||||||
|  |         /// The google scheme. | ||||||
|  |         /// </summary> | ||||||
|  |         public const string GoogleScheme = "GoogleScheme"; | ||||||
|     } |     } | ||||||
| } | } | ||||||
| @@ -1,9 +1,9 @@ | |||||||
| // *********************************************************************** | // *********************************************************************** | ||||||
| // <copyright file="AppSettings.cs"> | // <copyright file="AppSettings.cs"> | ||||||
| //     Heath | //     AgileWebs | ||||||
| // </copyright> | // </copyright> | ||||||
| // *********************************************************************** | // *********************************************************************** | ||||||
| namespace Core.Cerberos.Adapters.Common.Constants | namespace Core.Thalos.BuildingBlocks | ||||||
| { | { | ||||||
|     /// <summary> |     /// <summary> | ||||||
|     /// Constants for secrets in azure key vault. |     /// Constants for secrets in azure key vault. | ||||||
| @@ -23,12 +23,12 @@ namespace Core.Cerberos.Adapters.Common.Constants | |||||||
|         /// <summary> |         /// <summary> | ||||||
|         /// The Issuer parameter for JWT settings. |         /// The Issuer parameter for JWT settings. | ||||||
|         /// </summary> |         /// </summary> | ||||||
|         public const string Issuer = "Issuer"; |         public const string Issuer = "JWTIssuer"; | ||||||
| 
 | 
 | ||||||
|         /// <summary> |         /// <summary> | ||||||
|         /// The Audience parameter for JWT settings. |         /// The Audience parameter for JWT settings. | ||||||
|         /// </summary> |         /// </summary> | ||||||
|         public const string Audience = "Audience"; |         public const string Audience = "JWTAudience"; | ||||||
| 
 | 
 | ||||||
|         /// <summary> |         /// <summary> | ||||||
|         /// The TokenExpirationInMinutes parameter for JWT settings. |         /// The TokenExpirationInMinutes parameter for JWT settings. | ||||||
| @@ -49,11 +49,14 @@ namespace Core.Cerberos.Adapters.Common.Constants | |||||||
|         public const string AzureADTenantId = "B2C:TenantId"; |         public const string AzureADTenantId = "B2C:TenantId"; | ||||||
|         public const string AzureADClientId = "B2C:ClientId"; |         public const string AzureADClientId = "B2C:ClientId"; | ||||||
|         public const string AzureADClientSecret = "B2C:ClientSecret"; |         public const string AzureADClientSecret = "B2C:ClientSecret"; | ||||||
|         public const string HeathCerberosAppAuthorizationUrl = "Swagger:AuthorizationUri"; |         public const string ThalosAppAuthorizationUrl = "Swagger:AuthorizationUri"; | ||||||
|         public const string HeathCerberosAppTokenUrl = "Swagger:TokenUri"; |         public const string ThalosAppTokenUrl = "Swagger:TokenUri"; | ||||||
|         public const string HeathCerberosAppClientId = "Swagger:ClientId"; |         public const string ThalosAppClientId = "Swagger:ClientId"; | ||||||
|         public const string HeathCerberosAppScope = "Swagger:Scope"; |         public const string ThalosAppScope = "Swagger:Scope"; | ||||||
|         public const string PrivateKey = "B2C:JwtIssuerOptions:TokenPrivateKey"; |         public const string PrivateKey = "JwtTokenPrivateKey"; | ||||||
|         public const string PublicKey = "B2C:JwtIssuerOptions:TokenPublicKey"; |         public const string PublicKey = "JwtTokenPublicKey"; | ||||||
|  |         public const string GoogleClientId = "GoogleClientId"; | ||||||
|  |         public const string GoogleClientSecret = "GoogleClientSecret"; | ||||||
|  |         public const string GoogleRedirectUri = "GoogleRedirectUri"; | ||||||
|     } |     } | ||||||
| } | } | ||||||
| @@ -1,12 +1,12 @@ | |||||||
| // *********************************************************************** | // *********************************************************************** | ||||||
| // <copyright file="ApplicationsEnum.cs"> | // <copyright file="ApplicationsEnum.cs"> | ||||||
| //     Heath | //     AgileWebs | ||||||
| // </copyright> | // </copyright> | ||||||
| // *********************************************************************** | // *********************************************************************** | ||||||
| 
 | 
 | ||||||
| using System.Text.Json.Serialization; | using System.Text.Json.Serialization; | ||||||
| 
 | 
 | ||||||
| namespace Core.Cerberos.Adapters.Common.Enums | namespace Core.Thalos.BuildingBlocks | ||||||
| { | { | ||||||
|     /// <summary> |     /// <summary> | ||||||
|     /// Defines the applications associated with the role. |     /// Defines the applications associated with the role. | ||||||
| @@ -15,28 +15,13 @@ namespace Core.Cerberos.Adapters.Common.Enums | |||||||
|     public enum ApplicationsEnum |     public enum ApplicationsEnum | ||||||
|     { |     { | ||||||
|         /// <summary> |         /// <summary> | ||||||
|         /// LSA Web Portal application. |         /// Thalos application. | ||||||
|         /// </summary> |         /// </summary> | ||||||
|         LSAWebPortal = 0, |         Thalos = 0, | ||||||
| 
 | 
 | ||||||
|         /// <summary> |         /// <summary> | ||||||
|         /// Customer DashBoard application. |         /// DreamViewer application. | ||||||
|         /// </summary> |         /// </summary> | ||||||
|         CustomerDashboard = 1, |         DreamViewer = 1, | ||||||
| 
 |  | ||||||
|         /// <summary> |  | ||||||
|         /// Discover application. |  | ||||||
|         /// </summary> |  | ||||||
|         Discover = 2, |  | ||||||
| 
 |  | ||||||
|         /// <summary> |  | ||||||
|         /// LSA Mobile application. |  | ||||||
|         /// </summary> |  | ||||||
|         LSAMobile = 3, |  | ||||||
| 
 |  | ||||||
|         /// <summary> |  | ||||||
|         /// BluePrint application. |  | ||||||
|         /// </summary> |  | ||||||
|         BluePrint = 4, |  | ||||||
|     } |     } | ||||||
| } | } | ||||||
| @@ -1,12 +1,12 @@ | |||||||
| // *********************************************************************** | // *********************************************************************** | ||||||
| // <copyright file="StatusEnum.cs"> | // <copyright file="StatusEnum.cs"> | ||||||
| //     Heath | //     AgileWebs | ||||||
| // </copyright> | // </copyright> | ||||||
| // *********************************************************************** | // *********************************************************************** | ||||||
| 
 | 
 | ||||||
| using System.Text.Json.Serialization; | using System.Text.Json.Serialization; | ||||||
| 
 | 
 | ||||||
| namespace Core.Cerberos.Adapters.Common.Enums | namespace Core.Thalos.BuildingBlocks | ||||||
| { | { | ||||||
|     /// <summary> |     /// <summary> | ||||||
|     /// Defines the status of an entity. |     /// Defines the status of an entity. | ||||||
| @@ -1,6 +1,6 @@ | |||||||
| // *********************************************************************** | // *********************************************************************** | ||||||
| // <copyright file="EnumSchemaFilter.cs"> | // <copyright file="EnumSchemaFilter.cs"> | ||||||
| //     Heath | //     AgileWebs | ||||||
| // </copyright> | // </copyright> | ||||||
| // *********************************************************************** | // *********************************************************************** | ||||||
| 
 | 
 | ||||||
							
								
								
									
										11
									
								
								Core.Thalos.BuildingBlocks/Contracts/IGoogleAuthHelper.cs
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										11
									
								
								Core.Thalos.BuildingBlocks/Contracts/IGoogleAuthHelper.cs
									
									
									
									
									
										Normal file
									
								
							| @@ -0,0 +1,11 @@ | |||||||
|  | using Google.Apis.Auth.OAuth2; | ||||||
|  |  | ||||||
|  | namespace Core.Thalos.BuildingBlocks | ||||||
|  | { | ||||||
|  |     public interface IGoogleAuthHelper | ||||||
|  |     { | ||||||
|  |         string[] GetScopes(); | ||||||
|  |         string ScopeToString(); | ||||||
|  |         ClientSecrets GetClientSecrets(); | ||||||
|  |     } | ||||||
|  | } | ||||||
| @@ -1,10 +1,10 @@ | |||||||
| // *********************************************************************** | // *********************************************************************** | ||||||
| // <copyright file="ITokenProvider.cs"> | // <copyright file="ITokenProvider.cs"> | ||||||
| //     Heath | //     AgileWebs | ||||||
| // </copyright> | // </copyright> | ||||||
| // *********************************************************************** | // *********************************************************************** | ||||||
| 
 | 
 | ||||||
| namespace Core.Cerberos.Adapters.Contracts | namespace Core.Thalos.BuildingBlocks | ||||||
| { | { | ||||||
|     /// <summary> |     /// <summary> | ||||||
|     /// Interface for token provider. |     /// Interface for token provider. | ||||||
| @@ -1,13 +1,13 @@ | |||||||
| // *********************************************************************** | // *********************************************************************** | ||||||
| // <copyright file="ITokenService.cs"> | // <copyright file="ITokenService.cs"> | ||||||
| //     Heath | //     AgileWebs | ||||||
| // </copyright> | // </copyright> | ||||||
| // *********************************************************************** | // *********************************************************************** | ||||||
| 
 | 
 | ||||||
| using Microsoft.AspNetCore.Http; | using Microsoft.AspNetCore.Http; | ||||||
| using Microsoft.AspNetCore.Mvc; | using Microsoft.AspNetCore.Mvc; | ||||||
| 
 | 
 | ||||||
| namespace Core.Cerberos.Adapters.Contracts | namespace Core.Thalos.BuildingBlocks | ||||||
| { | { | ||||||
|     /// <summary> |     /// <summary> | ||||||
|     /// Interface for authenticacion service. |     /// Interface for authenticacion service. | ||||||
| @@ -17,7 +17,7 @@ namespace Core.Cerberos.Adapters.Contracts | |||||||
|         /// <summary> |         /// <summary> | ||||||
|         /// Refreshes the access token. |         /// Refreshes the access token. | ||||||
|         /// </summary> |         /// </summary> | ||||||
|         string GenerateAccessToken(TokenAdapter adapter); |         (string, IEnumerable<ModuleAdapter>) GenerateAccessToken(TokenAdapter adapter); | ||||||
| 
 | 
 | ||||||
|         /// <summary> |         /// <summary> | ||||||
|         /// Refreshes the access token. |         /// Refreshes the access token. | ||||||
| @@ -8,23 +8,35 @@ | |||||||
|     <TargetFramework>net8.0</TargetFramework> |     <TargetFramework>net8.0</TargetFramework> | ||||||
|     <ImplicitUsings>enable</ImplicitUsings> |     <ImplicitUsings>enable</ImplicitUsings> | ||||||
|     <Nullable>enable</Nullable> |     <Nullable>enable</Nullable> | ||||||
|  | 	<VersionPrefix>1.0.5</VersionPrefix> | ||||||
|  | 	<VersionSuffix>$(Date:yyyyMMddHHmm)</VersionSuffix> | ||||||
|   </PropertyGroup> |   </PropertyGroup> | ||||||
| 
 | 
 | ||||||
|   <ItemGroup> |   <ItemGroup> | ||||||
|     <PackageReference Include="Asp.Versioning.Mvc.ApiExplorer" Version="8.1.0" /> |     <PackageReference Include="Asp.Versioning.Mvc.ApiExplorer" Version="8.1.0" /> | ||||||
|  |     <PackageReference Include="Core.Blueprint.KeyVault" Version="1.0.3" /> | ||||||
|  |     <PackageReference Include="Core.Blueprint.Mongo" Version="1.0.0" /> | ||||||
|  |     <PackageReference Include="Google.Apis.Auth" Version="1.70.0" /> | ||||||
|  |     <PackageReference Include="Google.Apis.Oauth2.v2" Version="1.68.0.1869" /> | ||||||
|  |     <PackageReference Include="Microsoft.AspNetCore.Authentication.Google" Version="8.0.18" /> | ||||||
|     <PackageReference Include="Microsoft.AspNetCore.Authentication.JwtBearer" Version="8.0.10" /> |     <PackageReference Include="Microsoft.AspNetCore.Authentication.JwtBearer" Version="8.0.10" /> | ||||||
|     <PackageReference Include="Microsoft.Extensions.Configuration.AzureAppConfiguration" Version="8.0.0" /> |     <PackageReference Include="Microsoft.Extensions.Configuration.AzureAppConfiguration" Version="8.2.0" /> | ||||||
|     <PackageReference Include="Microsoft.Identity.Web" Version="3.2.2" /> |     <PackageReference Include="Microsoft.Extensions.Options" Version="9.0.7" /> | ||||||
|     <PackageReference Include="Microsoft.Identity.Web.MicrosoftGraph" Version="3.2.2" /> |     <PackageReference Include="Microsoft.Identity.Web" Version="3.9.1" /> | ||||||
|     <PackageReference Include="MongoDB.Bson" Version="3.0.0" /> |     <PackageReference Include="Microsoft.Identity.Web.MicrosoftGraph" Version="3.9.1" /> | ||||||
|     <PackageReference Include="OpenTelemetry" Version="1.9.0" /> |     <PackageReference Include="MongoDB.Bson" Version="3.4.0" /> | ||||||
|     <PackageReference Include="OpenTelemetry.Exporter.Console" Version="1.9.0" /> |     <PackageReference Include="OpenTelemetry" Version="1.12.0" /> | ||||||
|     <PackageReference Include="OpenTelemetry.Extensions.Hosting" Version="1.9.0" /> |     <PackageReference Include="OpenTelemetry.Exporter.Console" Version="1.12.0" /> | ||||||
|     <PackageReference Include="OpenTelemetry.Instrumentation.AspNetCore" Version="1.9.0" /> |     <PackageReference Include="OpenTelemetry.Extensions.Hosting" Version="1.12.0" /> | ||||||
|     <PackageReference Include="OpenTelemetry.Instrumentation.Http" Version="1.9.0" /> |     <PackageReference Include="OpenTelemetry.Instrumentation.AspNetCore" Version="1.12.0" /> | ||||||
|  |     <PackageReference Include="OpenTelemetry.Instrumentation.Http" Version="1.12.0" /> | ||||||
|     <PackageReference Include="Portable.BouncyCastle" Version="1.9.0" /> |     <PackageReference Include="Portable.BouncyCastle" Version="1.9.0" /> | ||||||
|     <PackageReference Include="Swashbuckle.AspNetCore" Version="6.9.0" /> |     <PackageReference Include="Swashbuckle.AspNetCore" Version="8.1.1" /> | ||||||
|     <PackageReference Include="System.Text.Json" Version="8.0.5" /> |     <PackageReference Include="System.Text.Json" Version="9.0.5" /> | ||||||
|  |   </ItemGroup> | ||||||
|  | 
 | ||||||
|  |   <ItemGroup> | ||||||
|  |     <Folder Include="Handlers\Adapters\" /> | ||||||
|   </ItemGroup> |   </ItemGroup> | ||||||
| 
 | 
 | ||||||
| </Project> | </Project> | ||||||
| @@ -1,23 +1,20 @@ | |||||||
| // *********************************************************************** | // *********************************************************************** | ||||||
| // <copyright file="AuthExtension.cs"> | // <copyright file="AuthExtension.cs"> | ||||||
| //     Heath | //     AgileWebs | ||||||
| // </copyright> | // </copyright> | ||||||
| // *********************************************************************** | // *********************************************************************** | ||||||
| 
 | 
 | ||||||
| using Core.Cerberos.Adapters.Common.Constants; | using Microsoft.AspNetCore.Authentication; | ||||||
| using Core.Cerberos.Adapters.Contracts; |  | ||||||
| using Core.Cerberos.Adapters.Handlers; |  | ||||||
| using Core.Cerberos.Adapters.Options; |  | ||||||
| using Core.Cerberos.Adapters.Services; |  | ||||||
| using Microsoft.AspNetCore.Authentication.JwtBearer; | using Microsoft.AspNetCore.Authentication.JwtBearer; | ||||||
| using Microsoft.AspNetCore.Authorization; | using Microsoft.AspNetCore.Authorization; | ||||||
| using Microsoft.Extensions.Configuration; | using Microsoft.Extensions.Configuration; | ||||||
| using Microsoft.Extensions.DependencyInjection; | using Microsoft.Extensions.DependencyInjection; | ||||||
|  | using Microsoft.Extensions.Options; | ||||||
| using Microsoft.Identity.Web; | using Microsoft.Identity.Web; | ||||||
| using Microsoft.IdentityModel.Tokens; | using Microsoft.IdentityModel.Tokens; | ||||||
| using System.Security.Cryptography; | using System.Security.Cryptography; | ||||||
| 
 | 
 | ||||||
| namespace Core.Cerberos.Adapters.Extensions | namespace Core.Thalos.BuildingBlocks.Configuration | ||||||
| { | { | ||||||
|     /// <summary> |     /// <summary> | ||||||
|     /// Extension methods for configuring authentication with various Azure AD setups. |     /// Extension methods for configuring authentication with various Azure AD setups. | ||||||
| @@ -33,42 +30,44 @@ namespace Core.Cerberos.Adapters.Extensions | |||||||
|         { |         { | ||||||
|             var environment = Environment.GetEnvironmentVariable("ASPNETCORE_ENVIRONMENT") ?? string.Empty; |             var environment = Environment.GetEnvironmentVariable("ASPNETCORE_ENVIRONMENT") ?? string.Empty; | ||||||
| 
 | 
 | ||||||
|             var azureAdInMemorySettings = new Dictionary<string, string?> |             var identityProviders = new IdentityProviders(); | ||||||
|  |             configuration.GetSection("IdentityProviders").Bind(identityProviders); | ||||||
|  | 
 | ||||||
|  |             AddCustomAuthentication(services, authSettings.Token); | ||||||
|  | 
 | ||||||
|  |             if (identityProviders.Azure) | ||||||
|  |                 AddAzureAuthentication(authSettings, configuration, services); | ||||||
|  | 
 | ||||||
|  |             if (identityProviders.Google) | ||||||
|  |                 AddGoogleAuthentication(services, authSettings.Google); | ||||||
|  | 
 | ||||||
|  |             services.AddAuthorization(); | ||||||
|  |             services.AddTransient<IAuthorizationHandler, PermissionsAuthorizationHandler>(); | ||||||
|  |             services.AddTransient<ITokenService, TokenService>(); | ||||||
|  |         } | ||||||
|  | 
 | ||||||
|  |         public static void AddCustomAuthentication(IServiceCollection services, TokenAuthSettings tokenAuthSettings) | ||||||
|         { |         { | ||||||
|                 { "AzureAdB2C:Instance",  authSettings.AzureADInstance ?? string.Empty }, |  | ||||||
|                 { "AzureAdB2C:TenantId", authSettings.AzureADTenantId ?? string.Empty }, |  | ||||||
|                 { "AzureAdB2C:ClientId", authSettings.AzureADClientId ?? string.Empty }, |  | ||||||
|                 { "AzureAdB2C:ClientSecret", authSettings.AzureADClientSecret ?? string.Empty } |  | ||||||
|             }; |  | ||||||
| 
 |  | ||||||
|             var configurationBuilder = new ConfigurationBuilder() |  | ||||||
|                 .AddConfiguration(configuration) |  | ||||||
|                 .AddInMemoryCollection(azureAdInMemorySettings); |  | ||||||
| 
 |  | ||||||
|             var combinedConfiguration = configurationBuilder.Build(); |  | ||||||
| 
 |  | ||||||
|             services.AddAuthentication(JwtBearerDefaults.AuthenticationScheme) |  | ||||||
|                .AddMicrosoftIdentityWebApi(combinedConfiguration.GetSection("AzureAdB2C"), Schemes.AzureScheme) |  | ||||||
|                .EnableTokenAcquisitionToCallDownstreamApi() |  | ||||||
|                .AddMicrosoftGraph(configuration.GetSection("MicrosoftGraph")) |  | ||||||
|                .AddInMemoryTokenCaches(); |  | ||||||
| 
 |  | ||||||
|             var rsa = RSA.Create(); |             var rsa = RSA.Create(); | ||||||
|             rsa.ImportFromPem(authSettings.PrivateKey?.ToCharArray()); |             rsa.ImportFromPem(tokenAuthSettings.PrivateKey?.ToCharArray()); | ||||||
|             var rsaPrivateKey = new RsaSecurityKey(rsa); |             var rsaPrivateKey = new RsaSecurityKey(rsa); | ||||||
| 
 | 
 | ||||||
|             var rsaPublic = RSA.Create(); |             var rsaPublic = RSA.Create(); | ||||||
|             rsaPublic.ImportFromPem(authSettings.PublicKey?.ToCharArray()); |             rsaPublic.ImportFromPem(tokenAuthSettings.PublicKey?.ToCharArray()); | ||||||
|             var rsaPublicKey = new RsaSecurityKey(rsaPublic); |             var rsaPublicKey = new RsaSecurityKey(rsaPublic); | ||||||
| 
 | 
 | ||||||
|             var jwtAppSettingOptions = configuration.GetSection("B2C:JwtIssuerOptions"); | 
 | ||||||
|             var jwtIssuerOptions = jwtAppSettingOptions.Get<JwtIssuerOptions>(); |             var jwtIssuerOptions = new JwtIssuerOptions | ||||||
|  |             { | ||||||
|  |                 Audience = tokenAuthSettings.Audience, | ||||||
|  |                 Issuer = tokenAuthSettings.Issuer, | ||||||
|  |             }; | ||||||
| 
 | 
 | ||||||
|             if (string.IsNullOrEmpty(jwtIssuerOptions?.Issuer) || string.IsNullOrEmpty(jwtIssuerOptions.Audience)) |             if (string.IsNullOrEmpty(jwtIssuerOptions?.Issuer) || string.IsNullOrEmpty(jwtIssuerOptions.Audience)) | ||||||
|                 throw new InvalidOperationException("JwtIssuerOptions are not configured correctly."); |                 throw new InvalidOperationException("JwtIssuerOptions are not configured correctly."); | ||||||
| 
 | 
 | ||||||
|             services.AddAuthentication(JwtBearerDefaults.AuthenticationScheme) |             services.AddAuthentication(JwtBearerDefaults.AuthenticationScheme) | ||||||
|             .AddJwtBearer(Schemes.HeathScheme, x => |             .AddJwtBearer(Schemes.DefaultScheme, x => | ||||||
|             { |             { | ||||||
|                 x.TokenValidationParameters = new TokenValidationParameters |                 x.TokenValidationParameters = new TokenValidationParameters | ||||||
|                 { |                 { | ||||||
| @@ -89,9 +88,51 @@ namespace Core.Cerberos.Adapters.Extensions | |||||||
|                 options.SigningCredentials = new SigningCredentials(rsaPrivateKey, SecurityAlgorithms.RsaSha256); |                 options.SigningCredentials = new SigningCredentials(rsaPrivateKey, SecurityAlgorithms.RsaSha256); | ||||||
|             }); |             }); | ||||||
| 
 | 
 | ||||||
|             services.AddSingleton(jwtAppSettingOptions); |             services.AddSingleton<IOptions<JwtIssuerOptions>>(Microsoft.Extensions.Options.Options.Create(jwtIssuerOptions)); | ||||||
|             services.AddTransient<IAuthorizationHandler, PermissionsAuthorizationHandler>(); |         } | ||||||
|             services.AddTransient<ITokenService, TokenService>(); | 
 | ||||||
|  |         public static void AddAzureAuthentication(AuthSettings authSettings, IConfiguration configuration, IServiceCollection services) | ||||||
|  |         { | ||||||
|  |             var azureAdInMemorySettings = new Dictionary<string, string?> | ||||||
|  |             { | ||||||
|  |                 { "AzureAdB2C:Instance",  authSettings.Azure.Instance ?? string.Empty }, | ||||||
|  |                 { "AzureAdB2C:TenantId", authSettings.Azure.TenantId ?? string.Empty }, | ||||||
|  |                 { "AzureAdB2C:ClientId", authSettings.Azure.ClientId ?? string.Empty }, | ||||||
|  |                 { "AzureAdB2C:ClientSecret", authSettings.Azure.ClientSecret ?? string.Empty } | ||||||
|  |             }; | ||||||
|  | 
 | ||||||
|  |             var configurationBuilder = new ConfigurationBuilder() | ||||||
|  |                 .AddConfiguration(configuration) | ||||||
|  |                 .AddInMemoryCollection(azureAdInMemorySettings); | ||||||
|  | 
 | ||||||
|  |             var combinedConfiguration = configurationBuilder.Build(); | ||||||
|  | 
 | ||||||
|  |             services.AddAuthentication(JwtBearerDefaults.AuthenticationScheme) | ||||||
|  |                .AddMicrosoftIdentityWebApi(combinedConfiguration.GetSection("AzureAdB2C"), Schemes.AzureScheme) | ||||||
|  |                .EnableTokenAcquisitionToCallDownstreamApi() | ||||||
|  |                .AddMicrosoftGraph(configuration.GetSection("MicrosoftGraph")) | ||||||
|  |                .AddInMemoryTokenCaches(); | ||||||
|  |         } | ||||||
|  | 
 | ||||||
|  |         public static void AddGoogleAuthentication(IServiceCollection services, GoogleAuthSettings googleAuthSettings) | ||||||
|  |         { | ||||||
|  |             services.AddAuthentication(options => | ||||||
|  |             { | ||||||
|  |                 options.DefaultAuthenticateScheme = Schemes.GoogleScheme; | ||||||
|  |                 options.DefaultChallengeScheme = JwtBearerDefaults.AuthenticationScheme; | ||||||
|  |             }) | ||||||
|  |            .AddScheme<AuthenticationSchemeOptions, | ||||||
|  |             GoogleAccessTokenAuthenticationHandler>(Schemes.GoogleScheme, null) | ||||||
|  |            .AddGoogle(options => | ||||||
|  |            { | ||||||
|  |                options.ClientId = googleAuthSettings.ClientId!; | ||||||
|  |                options.ClientSecret = googleAuthSettings.ClientSecret!; | ||||||
|  |                //options.SaveTokens = true; | ||||||
|  |                options.CallbackPath = $"/{googleAuthSettings.RedirectUri}"; | ||||||
|  |            }); | ||||||
|  | 
 | ||||||
|  |             services.AddScoped<IGoogleAuthHelper, GoogleAuthHelper>(); | ||||||
|  |             services.AddScoped<IGoogleAuthorization, GoogleAuthorization>(); | ||||||
|         } |         } | ||||||
|     } |     } | ||||||
| } | } | ||||||
| @@ -1,12 +1,10 @@ | |||||||
| // *********************************************************************** | // *********************************************************************** | ||||||
| // <copyright file="SwaggerExtensions.cs"> | // <copyright file="SwaggerExtensions.cs"> | ||||||
| //     Heath | //     AgileWebs | ||||||
| // </copyright> | // </copyright> | ||||||
| // *********************************************************************** | // *********************************************************************** | ||||||
| 
 | 
 | ||||||
| using Asp.Versioning.ApiExplorer; | using Asp.Versioning.ApiExplorer; | ||||||
| using Core.Cerberos.Adapters.Common.Constants; |  | ||||||
| using Core.Cerberos.Adapters.Extensions; |  | ||||||
| using Microsoft.AspNetCore.Builder; | using Microsoft.AspNetCore.Builder; | ||||||
| using Microsoft.Extensions.Configuration; | using Microsoft.Extensions.Configuration; | ||||||
| using Microsoft.Extensions.DependencyInjection; | using Microsoft.Extensions.DependencyInjection; | ||||||
| @@ -16,7 +14,7 @@ using Microsoft.OpenApi.Models; | |||||||
| using Swashbuckle.AspNetCore.SwaggerGen; | using Swashbuckle.AspNetCore.SwaggerGen; | ||||||
| using Swashbuckle.AspNetCore.SwaggerUI; | using Swashbuckle.AspNetCore.SwaggerUI; | ||||||
| 
 | 
 | ||||||
| namespace Core.Cerberos.Adapters.Extensions | namespace Core.Thalos.BuildingBlocks.Configuration | ||||||
| { | { | ||||||
|     /// <summary> |     /// <summary> | ||||||
|     /// Extension methods for configuring Swagger documentation and UI. |     /// Extension methods for configuring Swagger documentation and UI. | ||||||
| @@ -40,40 +38,17 @@ namespace Core.Cerberos.Adapters.Extensions | |||||||
|         /// </summary> |         /// </summary> | ||||||
|         /// <param name="services">The <see cref="IServiceCollection"/> to add the services to.</param> |         /// <param name="services">The <see cref="IServiceCollection"/> to add the services to.</param> | ||||||
|         /// <param name="configuration">The <see cref="IConfiguration"/> containing Swagger and OAuth2 configuration settings.</param> |         /// <param name="configuration">The <see cref="IConfiguration"/> containing Swagger and OAuth2 configuration settings.</param> | ||||||
|         public static void AddSwaggerGen(this IServiceCollection services, IConfiguration configuration, string DocumentationFile, AuthSettings authSettings) |         public static void AddSwaggerGen( | ||||||
|  |     this IServiceCollection services, | ||||||
|  |     IConfiguration configuration, | ||||||
|  |     string documentationFile, | ||||||
|  |     AuthSettings authSettings) | ||||||
|         { |         { | ||||||
|  |             var identityProviders = new IdentityProviders(); | ||||||
|  |             configuration.GetSection("IdentityProviders").Bind(identityProviders); | ||||||
|  | 
 | ||||||
|             services.AddSwaggerGen(c => |             services.AddSwaggerGen(c => | ||||||
|             { |             { | ||||||
|                     c.AddSecurityDefinition("oauth2", new OpenApiSecurityScheme |  | ||||||
|                     { |  | ||||||
|                         Description = "OAuth2.0 Authorization Code flow", |  | ||||||
|                         Name = "oauth2.0", |  | ||||||
|                         Type = SecuritySchemeType.OAuth2, |  | ||||||
|                         Flows = new OpenApiOAuthFlows |  | ||||||
|                         { |  | ||||||
|                             AuthorizationCode = new OpenApiOAuthFlow |  | ||||||
|                             { |  | ||||||
|                                 AuthorizationUrl = new Uri(authSettings.HeathCerberosAppAuthorizationUrl ?? string.Empty), |  | ||||||
|                                 TokenUrl = new Uri(authSettings.HeathCerberosAppTokenUrl ?? string.Empty), |  | ||||||
|                                 Scopes = new Dictionary<string, string> |  | ||||||
|                                 { |  | ||||||
|                                 { authSettings.HeathCerberosAppScope ?? string.Empty, "Access API as User" } |  | ||||||
|                                 } |  | ||||||
|                             } |  | ||||||
|                         } |  | ||||||
|                     }); |  | ||||||
| 
 |  | ||||||
|                     c.AddSecurityRequirement(new OpenApiSecurityRequirement |  | ||||||
|                     { |  | ||||||
|                     { |  | ||||||
|                         new OpenApiSecurityScheme |  | ||||||
|                         { |  | ||||||
|                             Reference = new OpenApiReference { Type = ReferenceType.SecurityScheme, Id = "oauth2" } |  | ||||||
|                         }, |  | ||||||
|                         new[] { authSettings.HeathCerberosAppScope } |  | ||||||
|                     } |  | ||||||
|                     }); |  | ||||||
| 
 |  | ||||||
|                 c.AddSecurityDefinition("Bearer", new OpenApiSecurityScheme |                 c.AddSecurityDefinition("Bearer", new OpenApiSecurityScheme | ||||||
|                 { |                 { | ||||||
|                     Description = "JWT Authorization header using the Bearer scheme", |                     Description = "JWT Authorization header using the Bearer scheme", | ||||||
| @@ -99,12 +74,79 @@ namespace Core.Cerberos.Adapters.Extensions | |||||||
|             } |             } | ||||||
|         }); |         }); | ||||||
| 
 | 
 | ||||||
|                     var filePath = Path.Combine(AppContext.BaseDirectory, DocumentationFile); |                 if (identityProviders.Azure) | ||||||
|  |                 { | ||||||
|  |                     const string azureScheme = "oauth2-Azure"; | ||||||
|  | 
 | ||||||
|  |                     c.AddSecurityDefinition(azureScheme, new OpenApiSecurityScheme | ||||||
|  |                     { | ||||||
|  |                         Description = "Azure OAuth2 Authorization Code flow", | ||||||
|  |                         Type = SecuritySchemeType.OAuth2, | ||||||
|  |                         Flows = new OpenApiOAuthFlows | ||||||
|  |                         { | ||||||
|  |                             AuthorizationCode = new OpenApiOAuthFlow | ||||||
|  |                             { | ||||||
|  |                                 AuthorizationUrl = new Uri(authSettings.Azure?.ThalosAppAuthorizationUrl ?? | ||||||
|  |                                     "https://login.microsoftonline.com/common/oauth2/v2.0/authorize"), | ||||||
|  |                                 TokenUrl = new Uri(authSettings.Azure?.ThalosAppTokenUrl ?? | ||||||
|  |                                     "https://login.microsoftonline.com/common/oauth2/v2.0/token"), | ||||||
|  |                                 Scopes = new Dictionary<string, string> | ||||||
|  |                         { | ||||||
|  |                             { authSettings.Azure?.ThalosAppScope ?? "access_as_user", "Access API as User" } | ||||||
|  |                         } | ||||||
|  |                             } | ||||||
|  |                         } | ||||||
|  |                     }); | ||||||
|  | 
 | ||||||
|  |                     c.AddSecurityRequirement(new OpenApiSecurityRequirement | ||||||
|  |                     { | ||||||
|  |                         [new OpenApiSecurityScheme | ||||||
|  |                         { | ||||||
|  |                             Reference = new OpenApiReference { Type = ReferenceType.SecurityScheme, Id = azureScheme } | ||||||
|  |                         }] = new[] { authSettings.Azure?.ThalosAppScope ?? "access_as_user" } | ||||||
|  |                     }); | ||||||
|  |                 } | ||||||
|  | 
 | ||||||
|  |                 if (identityProviders.Google) | ||||||
|  |                 { | ||||||
|  |                     const string googleScheme = "oauth2-Google"; | ||||||
|  | 
 | ||||||
|  |                     c.AddSecurityDefinition(googleScheme, new OpenApiSecurityScheme | ||||||
|  |                     { | ||||||
|  |                         Type = SecuritySchemeType.OAuth2, | ||||||
|  |                         Flows = new OpenApiOAuthFlows | ||||||
|  |                         { | ||||||
|  |                             AuthorizationCode = new OpenApiOAuthFlow | ||||||
|  |                             { | ||||||
|  |                                 AuthorizationUrl = new Uri("https://accounts.google.com/o/oauth2/v2/auth"), | ||||||
|  |                                 TokenUrl = new Uri("https://oauth2.googleapis.com/token"), | ||||||
|  |                                 Scopes = new Dictionary<string, string> | ||||||
|  |                         { | ||||||
|  |                             { "openid",  "OpenID Connect" }, | ||||||
|  |                             { "email",   "Access email" }, | ||||||
|  |                             { "profile", "Access profile" } | ||||||
|  |                         } | ||||||
|  |                             } | ||||||
|  |                         } | ||||||
|  |                     }); | ||||||
|  | 
 | ||||||
|  |                     c.AddSecurityRequirement(new OpenApiSecurityRequirement | ||||||
|  |                     { | ||||||
|  |                         [new OpenApiSecurityScheme | ||||||
|  |                         { | ||||||
|  |                             Reference = new OpenApiReference { Type = ReferenceType.SecurityScheme, Id = googleScheme } | ||||||
|  |                         }] = new[] { "openid", "email", "profile" } | ||||||
|  |                     }); | ||||||
|  |                 } | ||||||
|  | 
 | ||||||
|  |                 // ✅ XML Comments | ||||||
|  |                 var filePath = Path.Combine(AppContext.BaseDirectory, documentationFile); | ||||||
|                 c.IncludeXmlComments(filePath); |                 c.IncludeXmlComments(filePath); | ||||||
|                 c.SchemaFilter<EnumSchemaFilter>(); |                 c.SchemaFilter<EnumSchemaFilter>(); | ||||||
|             }); |             }); | ||||||
|         } |         } | ||||||
| 
 | 
 | ||||||
|  | 
 | ||||||
|         /// <summary> |         /// <summary> | ||||||
|         /// Configures Swagger and Swagger UI for the application. |         /// Configures Swagger and Swagger UI for the application. | ||||||
|         /// </summary> |         /// </summary> | ||||||
| @@ -129,17 +171,38 @@ namespace Core.Cerberos.Adapters.Extensions | |||||||
|         /// </summary> |         /// </summary> | ||||||
|         /// <param name="app">The <see cref="WebApplication"/> instance.</param> |         /// <param name="app">The <see cref="WebApplication"/> instance.</param> | ||||||
|         /// <param name="configuration">The <see cref="IConfiguration"/> containing Swagger UI and OAuth2 configuration settings.</param> |         /// <param name="configuration">The <see cref="IConfiguration"/> containing Swagger UI and OAuth2 configuration settings.</param> | ||||||
|         public static void UseSwaggerUI(this WebApplication app, IConfiguration configuration, AuthSettings authSettings) |         public static void UseSwaggerUI( | ||||||
|  |             this WebApplication app, | ||||||
|  |             IConfiguration configuration, | ||||||
|  |             AuthSettings authSettings) | ||||||
|  |         { | ||||||
|  |             var identityProviders = new IdentityProviders(); | ||||||
|  |             configuration.GetSection("IdentityProviders").Bind(identityProviders); | ||||||
|  | 
 | ||||||
|  |             app.UseSwagger(); | ||||||
|  | 
 | ||||||
|  |             if (identityProviders.Google) | ||||||
|             { |             { | ||||||
|                 app.UseSwaggerUI(options => |                 app.UseSwaggerUI(options => | ||||||
|                 { |                 { | ||||||
|                 options.SwaggerEndpoint("/swagger/v1/swagger.json", "Custom Auth API with Azure AD v1"); |  | ||||||
|                 options.OAuthClientId(authSettings.HeathCerberosAppClientId); |  | ||||||
|                     options.OAuthUsePkce(); |                     options.OAuthUsePkce(); | ||||||
|                     options.OAuthScopeSeparator(" "); |                     options.OAuthScopeSeparator(" "); | ||||||
|  |                     options.OAuthClientId(authSettings.Google?.ClientId); | ||||||
|  |                     options.OAuthClientSecret(authSettings.Google?.ClientSecret); | ||||||
|                 }); |                 }); | ||||||
|             } |             } | ||||||
| 
 | 
 | ||||||
|  |             if (identityProviders.Azure) | ||||||
|  |             { | ||||||
|  |                 app.UseSwaggerUI(options => | ||||||
|  |                 { | ||||||
|  |                     options.OAuthUsePkce(); | ||||||
|  |                     options.OAuthScopeSeparator(" "); | ||||||
|  |                     options.OAuthClientId(authSettings.Azure?.ThalosAppClientId); | ||||||
|  |                 }); | ||||||
|  |             } | ||||||
|  |         } | ||||||
|  | 
 | ||||||
|         /// <summary> |         /// <summary> | ||||||
|         /// Adds API versioning and API explorer to the application. |         /// Adds API versioning and API explorer to the application. | ||||||
|         /// </summary> |         /// </summary> | ||||||
| @@ -4,15 +4,15 @@ using OpenTelemetry.Metrics; | |||||||
| using OpenTelemetry.Resources; | using OpenTelemetry.Resources; | ||||||
| using OpenTelemetry.Trace; | using OpenTelemetry.Trace; | ||||||
| 
 | 
 | ||||||
| namespace Core.Cerberos.Adapters.Extensions | namespace Core.Thalos.BuildingBlocks.Configuration | ||||||
| { | { | ||||||
|     public static class TelemetryExtensions |     public static class TelemetryExtensions | ||||||
|     { |     { | ||||||
|         public static void AddTelemetry(this IServiceCollection services) |         public static void AddTelemetry(this IServiceCollection services, string apiName) | ||||||
|         { |         { | ||||||
|             // Add OpenTelemetry Tracing |             // Add OpenTelemetry Tracing | ||||||
|             services.AddOpenTelemetry() |             services.AddOpenTelemetry() | ||||||
|                     .ConfigureResource(resource => resource.AddService("lsa.dashboard.bff.api")) |                     .ConfigureResource(resource => resource.AddService($"{apiName}")) | ||||||
|                     .WithTracing(tracing => tracing.AddAspNetCoreInstrumentation().AddConsoleExporter()) |                     .WithTracing(tracing => tracing.AddAspNetCoreInstrumentation().AddConsoleExporter()) | ||||||
|                     .WithMetrics(metrics => metrics.AddAspNetCoreInstrumentation().AddConsoleExporter()). |                     .WithMetrics(metrics => metrics.AddAspNetCoreInstrumentation().AddConsoleExporter()). | ||||||
|                      WithLogging(logs => logs.AddConsoleExporter()); |                      WithLogging(logs => logs.AddConsoleExporter()); | ||||||
| @@ -1,6 +1,6 @@ | |||||||
| using Microsoft.AspNetCore.Http; | using Microsoft.AspNetCore.Http; | ||||||
| 
 | 
 | ||||||
| namespace Core.Cerberos.Adapters.Extensions | namespace Core.Thalos.BuildingBlocks.Extensions | ||||||
| { | { | ||||||
|     public sealed class TrackingMechanismExtension : DelegatingHandler |     public sealed class TrackingMechanismExtension : DelegatingHandler | ||||||
|     { |     { | ||||||
| @@ -1,12 +1,11 @@ | |||||||
| // *********************************************************************** | // *********************************************************************** | ||||||
| // <copyright file="AuthenticatedHttpClientHandler.cs"> | // <copyright file="AuthenticatedHttpClientHandler.cs"> | ||||||
| //     Heath | //     AgileWebs | ||||||
| // </copyright> | // </copyright> | ||||||
| // *********************************************************************** | // *********************************************************************** | ||||||
| 
 | 
 | ||||||
| using Core.Cerberos.Adapters.Contracts; |  | ||||||
| 
 | 
 | ||||||
| namespace Core.Cerberos.Adapters.Handlers | namespace Core.Thalos.BuildingBlocks | ||||||
| { | { | ||||||
|     /// <summary> |     /// <summary> | ||||||
|     /// Class to inject the token in all requests. |     /// Class to inject the token in all requests. | ||||||
| @@ -0,0 +1,62 @@ | |||||||
|  | using Google.Apis.Auth; | ||||||
|  | using Microsoft.AspNetCore.Authentication; | ||||||
|  | using Microsoft.Extensions.Configuration; | ||||||
|  | using Microsoft.Extensions.Logging; | ||||||
|  | using Microsoft.Extensions.Options; | ||||||
|  | using System.Security.Claims; | ||||||
|  | using System.Text.Encodings.Web; | ||||||
|  |  | ||||||
|  | namespace Core.Thalos.BuildingBlocks | ||||||
|  | { | ||||||
|  |     public class GoogleAccessTokenAuthenticationHandler(IOptionsMonitor<AuthenticationSchemeOptions> options, | ||||||
|  |          ILoggerFactory logger, | ||||||
|  |          UrlEncoder encoder, | ||||||
|  |          IConfiguration config) : AuthenticationHandler<AuthenticationSchemeOptions>(options, logger, encoder) | ||||||
|  |     { | ||||||
|  |         protected override async Task<AuthenticateResult> HandleAuthenticateAsync() | ||||||
|  |         { | ||||||
|  |             if (!Request.Headers.ContainsKey("Authorization")) | ||||||
|  |                 return AuthenticateResult.Fail("Missing Authorization header"); | ||||||
|  |  | ||||||
|  |             var authHeader = Request.Headers.Authorization.ToString(); | ||||||
|  |             if (!authHeader.StartsWith("Bearer ", StringComparison.OrdinalIgnoreCase)) | ||||||
|  |                 return AuthenticateResult.Fail("Invalid Authorization header"); | ||||||
|  |  | ||||||
|  |             var idToken = authHeader["Bearer ".Length..].Trim(); | ||||||
|  |  | ||||||
|  |             GoogleJsonWebSignature.Payload payload; | ||||||
|  |             try | ||||||
|  |             { | ||||||
|  |                 payload = await GoogleJsonWebSignature.ValidateAsync( | ||||||
|  |                     idToken, | ||||||
|  |                     new GoogleJsonWebSignature.ValidationSettings | ||||||
|  |                     { | ||||||
|  |                         Audience = new[] { config["Authentication:Google:ClientId"]! } | ||||||
|  |                     }); | ||||||
|  |             } | ||||||
|  |             catch (InvalidJwtException) | ||||||
|  |             { | ||||||
|  |                 return AuthenticateResult.Fail("Invalid Google token"); | ||||||
|  |             } | ||||||
|  |  | ||||||
|  |             var claims = new List<Claim> | ||||||
|  |             { | ||||||
|  |                 new Claim(ClaimTypes.NameIdentifier, payload.Subject), | ||||||
|  |                 new Claim(ClaimTypes.Email,          payload.Email), | ||||||
|  |                 new Claim(ClaimTypes.Name,           payload.Name ?? "") | ||||||
|  |             }; | ||||||
|  |  | ||||||
|  |             var identity = new ClaimsIdentity(claims, Schemes.GoogleScheme); | ||||||
|  |             var principal = new ClaimsPrincipal(identity); | ||||||
|  |  | ||||||
|  |             var userEmail = principal.FindFirst(ClaimTypes.Email)?.Value; | ||||||
|  |  | ||||||
|  |             if (string.IsNullOrEmpty(userEmail) || | ||||||
|  |                 !userEmail.EndsWith("@agilewebs.com", StringComparison.OrdinalIgnoreCase)) | ||||||
|  |                 return AuthenticateResult.Fail("Unauthorized Access"); | ||||||
|  |  | ||||||
|  |             var ticket = new AuthenticationTicket(principal, Schemes.GoogleScheme); | ||||||
|  |             return AuthenticateResult.Success(ticket); | ||||||
|  |         } | ||||||
|  |     } | ||||||
|  | } | ||||||
| @@ -1,7 +1,6 @@ | |||||||
| using Core.Cerberos.Adapters.Handlers.Adapters; | using Microsoft.AspNetCore.Authorization; | ||||||
| using Microsoft.AspNetCore.Authorization; |  | ||||||
| 
 | 
 | ||||||
| namespace Core.Cerberos.Adapters.Handlers | namespace Core.Thalos.BuildingBlocks | ||||||
| { | { | ||||||
|     public class PermissionsAuthorizationHandler : AuthorizationHandler<PermissionsAuthorizationAdapter> |     public class PermissionsAuthorizationHandler : AuthorizationHandler<PermissionsAuthorizationAdapter> | ||||||
|     { |     { | ||||||
							
								
								
									
										128
									
								
								Core.Thalos.BuildingBlocks/Helpers/AuthHelper.cs
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										128
									
								
								Core.Thalos.BuildingBlocks/Helpers/AuthHelper.cs
									
									
									
									
									
										Normal file
									
								
							| @@ -0,0 +1,128 @@ | |||||||
|  | using Azure.Identity; | ||||||
|  | using Core.Blueprint.KeyVault; | ||||||
|  | using Microsoft.AspNetCore.Builder; | ||||||
|  | using Microsoft.Extensions.Configuration; | ||||||
|  | using Microsoft.Extensions.Configuration.AzureAppConfiguration; | ||||||
|  | using Microsoft.Extensions.DependencyInjection; | ||||||
|  | using Microsoft.Extensions.Logging; | ||||||
|  |  | ||||||
|  | namespace Core.Thalos.BuildingBlocks | ||||||
|  | { | ||||||
|  |     public static class AuthHelper | ||||||
|  |     { | ||||||
|  |         private static readonly ILogger logger = LoggerFactory.Create(builder => | ||||||
|  |         { | ||||||
|  |             builder.AddConsole(); | ||||||
|  |         }).CreateLogger("AuthHelper"); | ||||||
|  |  | ||||||
|  |  | ||||||
|  |         public static async Task<AuthSettings> GetAuthSettings(this IServiceCollection services, WebApplicationBuilder builder, string appConfigLabel) | ||||||
|  |         { | ||||||
|  |             var environment = Environment.GetEnvironmentVariable("ASPNETCORE_ENVIRONMENT") ?? string.Empty; | ||||||
|  |             var authSettings = new AuthSettings(); | ||||||
|  |  | ||||||
|  |             var identityProviders = new IdentityProviders(); | ||||||
|  |             builder.Configuration.GetSection("IdentityProviders").Bind(identityProviders); | ||||||
|  |  | ||||||
|  |             using var serviceProvider = services.BuildServiceProvider(); | ||||||
|  |             var keyVaultProvider = serviceProvider.GetRequiredService<IKeyVaultProvider>(); | ||||||
|  |  | ||||||
|  |             if (environment != "Local") | ||||||
|  |             { | ||||||
|  |                 builder.Configuration.AddAzureAppConfiguration(options => | ||||||
|  |                 { | ||||||
|  |                     var endpoint = builder.Configuration.GetSection("Endpoints:AppConfigurationURI").Value; | ||||||
|  |  | ||||||
|  |                     if (string.IsNullOrEmpty(endpoint)) | ||||||
|  |                         throw new ArgumentException("The app configuration is missing"); | ||||||
|  |  | ||||||
|  |                     options.Connect(new Uri(endpoint), new DefaultAzureCredential()) | ||||||
|  |                            .Select(KeyFilter.Any, "thalos_common") | ||||||
|  |                            .Select(KeyFilter.Any, appConfigLabel); | ||||||
|  |  | ||||||
|  |                     options.ConfigureKeyVault(keyVaultOptions => | ||||||
|  |                     { | ||||||
|  |                         keyVaultOptions.SetCredential(new DefaultAzureCredential()); | ||||||
|  |                     }); | ||||||
|  |                 }); | ||||||
|  |             } | ||||||
|  |  | ||||||
|  |             if (identityProviders.Google) | ||||||
|  |                 authSettings.Google = await GetGoogleSettings(keyVaultProvider, builder); | ||||||
|  |  | ||||||
|  |             if (identityProviders.Azure) | ||||||
|  |                 authSettings.Azure = GetAzureSettings(builder); | ||||||
|  |  | ||||||
|  |             authSettings.Token = await GetTokenSettings(keyVaultProvider, builder); | ||||||
|  |  | ||||||
|  |             return authSettings; | ||||||
|  |         } | ||||||
|  |  | ||||||
|  |         private async static ValueTask<TokenAuthSettings> GetTokenSettings(IKeyVaultProvider keyVaultProvider, WebApplicationBuilder builder) | ||||||
|  |         { | ||||||
|  |             var environment = Environment.GetEnvironmentVariable("ASPNETCORE_ENVIRONMENT") ?? string.Empty; | ||||||
|  |  | ||||||
|  |             var tokenSettings = new TokenAuthSettings(); | ||||||
|  |  | ||||||
|  |             if (environment == "Local") | ||||||
|  |             { | ||||||
|  |                 tokenSettings.PublicKey = (await keyVaultProvider.GetSecretAsync(Secrets.PublicKey, new CancellationToken { })).Secret.Value; | ||||||
|  |                 tokenSettings.PrivateKey = (await keyVaultProvider.GetSecretAsync(Secrets.PrivateKey, new CancellationToken { })).Secret.Value; | ||||||
|  |                 tokenSettings.Issuer = (await keyVaultProvider.GetSecretAsync(Secrets.Issuer, new CancellationToken { })).Secret.Value; | ||||||
|  |                 tokenSettings.Audience = (await keyVaultProvider.GetSecretAsync(Secrets.Audience, new CancellationToken { })).Secret.Value; | ||||||
|  |             } | ||||||
|  |             else | ||||||
|  |             { | ||||||
|  |                 tokenSettings.PrivateKey = builder.Configuration.GetSection(Secrets.PrivateKey).Value; | ||||||
|  |                 tokenSettings.PublicKey = builder.Configuration.GetSection(Secrets.PublicKey).Value; | ||||||
|  |                 tokenSettings.Issuer = builder.Configuration.GetSection(Secrets.Issuer).Value; | ||||||
|  |                 tokenSettings.Audience = builder.Configuration.GetSection(Secrets.Audience).Value; | ||||||
|  |             } | ||||||
|  |  | ||||||
|  |             if (string.IsNullOrEmpty(tokenSettings.PrivateKey) || string.IsNullOrEmpty(tokenSettings.PublicKey)) | ||||||
|  |             { | ||||||
|  |                 logger.LogError("Settings for token creation are missing or incorrectly formatted."); | ||||||
|  |                 throw new InvalidOperationException("Invalid public or private key."); | ||||||
|  |             } | ||||||
|  |  | ||||||
|  |             return tokenSettings; | ||||||
|  |         } | ||||||
|  |  | ||||||
|  |         private static AzureAuthSettings GetAzureSettings(WebApplicationBuilder builder) | ||||||
|  |         { | ||||||
|  |             return new AzureAuthSettings | ||||||
|  |             { | ||||||
|  |                 Instance = builder.Configuration.GetSection(Secrets.AzureADInstance).Value, | ||||||
|  |                 TenantId = builder.Configuration.GetSection(Secrets.AzureADTenantId).Value, | ||||||
|  |                 ClientId = builder.Configuration.GetSection(Secrets.AzureADClientId).Value, | ||||||
|  |                 ClientSecret = builder.Configuration.GetSection(Secrets.AzureADClientSecret).Value, | ||||||
|  |                 ThalosAppAuthorizationUrl = builder.Configuration.GetSection(Secrets.ThalosAppAuthorizationUrl).Value, | ||||||
|  |                 ThalosAppTokenUrl = builder.Configuration.GetSection(Secrets.ThalosAppTokenUrl).Value, | ||||||
|  |                 ThalosAppClientId = builder.Configuration.GetSection(Secrets.ThalosAppClientId).Value, | ||||||
|  |                 ThalosAppScope = builder.Configuration.GetSection(Secrets.ThalosAppScope).Value, | ||||||
|  |             }; | ||||||
|  |         } | ||||||
|  |  | ||||||
|  |         private static async ValueTask<GoogleAuthSettings> GetGoogleSettings(IKeyVaultProvider keyVaultProvider, WebApplicationBuilder builder) | ||||||
|  |         { | ||||||
|  |             var environment = Environment.GetEnvironmentVariable("ASPNETCORE_ENVIRONMENT"); | ||||||
|  |             var googleSettings = new GoogleAuthSettings(); | ||||||
|  |  | ||||||
|  |             if (environment == "Local") | ||||||
|  |             { | ||||||
|  |                 googleSettings.ClientId = (await keyVaultProvider.GetSecretAsync(Secrets.GoogleClientId, new CancellationToken { })).Secret.Value; ; | ||||||
|  |                 googleSettings.ClientSecret = (await keyVaultProvider.GetSecretAsync(Secrets.GoogleClientSecret, new CancellationToken { })).Secret.Value; | ||||||
|  |                 googleSettings.RedirectUri = (await keyVaultProvider.GetSecretAsync(Secrets.GoogleRedirectUri, new CancellationToken { })).Secret.Value; | ||||||
|  |             } | ||||||
|  |             else | ||||||
|  |             { | ||||||
|  |                 googleSettings.ClientId = builder.Configuration.GetSection(Secrets.GoogleClientId).Value; | ||||||
|  |                 googleSettings.ClientSecret = builder.Configuration.GetSection(Secrets.GoogleClientSecret).Value; | ||||||
|  |                 googleSettings.RedirectUri = builder.Configuration.GetSection(Secrets.GoogleRedirectUri).Value; | ||||||
|  |             } | ||||||
|  |  | ||||||
|  |             return googleSettings; | ||||||
|  |         } | ||||||
|  |     } | ||||||
|  | } | ||||||
|  |  | ||||||
							
								
								
									
										31
									
								
								Core.Thalos.BuildingBlocks/Helpers/GoogleAuthHelper.cs
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										31
									
								
								Core.Thalos.BuildingBlocks/Helpers/GoogleAuthHelper.cs
									
									
									
									
									
										Normal file
									
								
							| @@ -0,0 +1,31 @@ | |||||||
|  | using Google.Apis.Auth.OAuth2; | ||||||
|  | using Google.Apis.Oauth2.v2; | ||||||
|  | using Microsoft.Extensions.Configuration; | ||||||
|  |  | ||||||
|  | namespace Core.Thalos.BuildingBlocks | ||||||
|  | { | ||||||
|  |     public class GoogleAuthHelper(IConfiguration config) : IGoogleAuthHelper | ||||||
|  |     { | ||||||
|  |         public ClientSecrets GetClientSecrets() | ||||||
|  |         { | ||||||
|  |             string clientId = config["Authentication:Google:ClientId"]!; | ||||||
|  |             string clientSecret = config["Authentication:Google:ClientSecret"]!; | ||||||
|  |  | ||||||
|  |             return new() { ClientId = clientId, ClientSecret = clientSecret }; | ||||||
|  |         } | ||||||
|  |  | ||||||
|  |         public string[] GetScopes() | ||||||
|  |         { | ||||||
|  |             var scopes = new[] | ||||||
|  |             { | ||||||
|  |                 Oauth2Service.Scope.Openid, | ||||||
|  |                 Oauth2Service.Scope.UserinfoEmail, | ||||||
|  |                 Oauth2Service.Scope.UserinfoProfile | ||||||
|  |             }; | ||||||
|  |  | ||||||
|  |             return scopes; | ||||||
|  |         } | ||||||
|  |  | ||||||
|  |         public string ScopeToString() => string.Join(", ", GetScopes()); | ||||||
|  |     } | ||||||
|  | } | ||||||
| @@ -1,6 +1,6 @@ | |||||||
| // *********************************************************************** | // *********************************************************************** | ||||||
| // <copyright file="RsaHelper.cs"> | // <copyright file="RsaHelper.cs"> | ||||||
| //     Heath | //     AgileWebs | ||||||
| // </copyright> | // </copyright> | ||||||
| // *********************************************************************** | // *********************************************************************** | ||||||
| using Org.BouncyCastle.Crypto; | using Org.BouncyCastle.Crypto; | ||||||
| @@ -10,7 +10,7 @@ using Org.BouncyCastle.Security; | |||||||
| using System.Security.Cryptography; | using System.Security.Cryptography; | ||||||
| using System.Text; | using System.Text; | ||||||
| 
 | 
 | ||||||
| namespace Core.Cerberos.Adapters.Helpers | namespace Core.Thalos.BuildingBlocks | ||||||
| { | { | ||||||
|     /// <summary> |     /// <summary> | ||||||
|     /// Handles all methods related to RSA encryption"/>. |     /// Handles all methods related to RSA encryption"/>. | ||||||
| @@ -62,7 +62,7 @@ namespace Core.Cerberos.Adapters.Helpers | |||||||
|         /// <returns>The private key.</returns> |         /// <returns>The private key.</returns> | ||||||
|         private RSACryptoServiceProvider GetPrivateKeyFromPemFile() |         private RSACryptoServiceProvider GetPrivateKeyFromPemFile() | ||||||
|         { |         { | ||||||
|             using (TextReader privateKeyTextReader = new StringReader(File.ReadAllText(Path.Combine(exeDirectory, "HeathPrivateKey.pem")))) |             using (TextReader privateKeyTextReader = new StringReader(File.ReadAllText(Path.Combine(exeDirectory, "PrivateKey.pem")))) | ||||||
|             { |             { | ||||||
|                 AsymmetricCipherKeyPair readKeyPair = (AsymmetricCipherKeyPair)new PemReader(privateKeyTextReader).ReadObject(); |                 AsymmetricCipherKeyPair readKeyPair = (AsymmetricCipherKeyPair)new PemReader(privateKeyTextReader).ReadObject(); | ||||||
| 
 | 
 | ||||||
| @@ -79,7 +79,7 @@ namespace Core.Cerberos.Adapters.Helpers | |||||||
|         /// <returns>The public key.</returns> |         /// <returns>The public key.</returns> | ||||||
|         public RSACryptoServiceProvider GetPublicKeyFromPemFile() |         public RSACryptoServiceProvider GetPublicKeyFromPemFile() | ||||||
|         { |         { | ||||||
|             using (TextReader publicKeyTextReader = new StringReader(File.ReadAllText(Path.Combine(exeDirectory, "HeathPublicKey.pem")))) |             using (TextReader publicKeyTextReader = new StringReader(File.ReadAllText(Path.Combine(exeDirectory, "PublicKey.pem")))) | ||||||
|             { |             { | ||||||
|                 RsaKeyParameters publicKeyParam = (RsaKeyParameters)new PemReader(publicKeyTextReader).ReadObject(); |                 RsaKeyParameters publicKeyParam = (RsaKeyParameters)new PemReader(publicKeyTextReader).ReadObject(); | ||||||
| 
 | 
 | ||||||
| @@ -1,6 +1,6 @@ | |||||||
| using Microsoft.IdentityModel.Tokens; | using Microsoft.IdentityModel.Tokens; | ||||||
| 
 | 
 | ||||||
| namespace Core.Cerberos.Adapters.Options | namespace Core.Thalos.BuildingBlocks | ||||||
| { | { | ||||||
|     /// <summary> |     /// <summary> | ||||||
|     /// JWT token Issuer options (used for JWT Factory) |     /// JWT token Issuer options (used for JWT Factory) | ||||||
| @@ -1,11 +1,8 @@ | |||||||
| // *********************************************************************** | // *********************************************************************** | ||||||
| // <copyright file="T5okenService.cs"> | // <copyright file="TokenService.cs"> | ||||||
| //     Heath | //     AgileWebs | ||||||
| // </copyright> | // </copyright> | ||||||
| // *********************************************************************** | // *********************************************************************** | ||||||
| using Core.Cerberos.Adapters.Common.Constants; |  | ||||||
| using Core.Cerberos.Adapters.Contracts; |  | ||||||
| using Core.Cerberos.Adapters.Options; |  | ||||||
| using Microsoft.AspNetCore.Http; | using Microsoft.AspNetCore.Http; | ||||||
| using Microsoft.AspNetCore.Mvc; | using Microsoft.AspNetCore.Mvc; | ||||||
| using Microsoft.Extensions.Configuration; | using Microsoft.Extensions.Configuration; | ||||||
| @@ -16,7 +13,7 @@ using System.IdentityModel.Tokens.Jwt; | |||||||
| using System.Security.Claims; | using System.Security.Claims; | ||||||
| using System.Text.Json; | using System.Text.Json; | ||||||
| 
 | 
 | ||||||
| namespace Core.Cerberos.Adapters.Services | namespace Core.Thalos.BuildingBlocks | ||||||
| { | { | ||||||
|     /// <summary> |     /// <summary> | ||||||
|     /// Service responsible for manage authenticacion. |     /// Service responsible for manage authenticacion. | ||||||
| @@ -74,7 +71,7 @@ namespace Core.Cerberos.Adapters.Services | |||||||
|         /// </summary> |         /// </summary> | ||||||
|         /// <param name="user">The user data.</param> |         /// <param name="user">The user data.</param> | ||||||
|         /// <returns>The user DTO with the generated token.</returns> |         /// <returns>The user DTO with the generated token.</returns> | ||||||
|         public string GenerateAccessToken(TokenAdapter adapter) |         public (string, IEnumerable<ModuleAdapter>) GenerateAccessToken(TokenAdapter adapter) | ||||||
|         { |         { | ||||||
| 
 | 
 | ||||||
| 
 | 
 | ||||||
| @@ -95,9 +92,6 @@ namespace Core.Cerberos.Adapters.Services | |||||||
|                     new Claim(Claims.Role, adapter?.Role?.Name ?? string.Empty), |                     new Claim(Claims.Role, adapter?.Role?.Name ?? string.Empty), | ||||||
|                     new Claim(Claims.RoleId, adapter?.Role?.Id ?? string.Empty), |                     new Claim(Claims.RoleId, adapter?.Role?.Id ?? string.Empty), | ||||||
|                     new Claim(Claims.Applications, JsonSerializer.Serialize(adapter?.Role?.Applications), JsonClaimValueTypes.JsonArray), |                     new Claim(Claims.Applications, JsonSerializer.Serialize(adapter?.Role?.Applications), JsonClaimValueTypes.JsonArray), | ||||||
|                     new Claim(Claims.Modules, JsonSerializer.Serialize(adapter?.Modules?.Select(m => new { m.Name, m.Application, m.Route, m.Icon, m.Order }), jsonOptions), JsonClaimValueTypes.JsonArray), |  | ||||||
|                     new Claim(Claims.Companies, JsonSerializer.Serialize(adapter?.User?.Companies), JsonClaimValueTypes.JsonArray), |  | ||||||
|                     new Claim(Claims.Projects, JsonSerializer.Serialize(adapter?.User?.Projects), JsonClaimValueTypes.JsonArray), |  | ||||||
|                     new Claim(Claims.Permissions, JsonSerializer.Serialize(adapter?.Permissions?.Select(p => $"{p.Name}.{p.AccessLevel}".Replace(" ", "")).ToArray()), JsonClaimValueTypes.JsonArray), |                     new Claim(Claims.Permissions, JsonSerializer.Serialize(adapter?.Permissions?.Select(p => $"{p.Name}.{p.AccessLevel}".Replace(" ", "")).ToArray()), JsonClaimValueTypes.JsonArray), | ||||||
|                 }), |                 }), | ||||||
| 
 | 
 | ||||||
| @@ -109,7 +103,7 @@ namespace Core.Cerberos.Adapters.Services | |||||||
| 
 | 
 | ||||||
|             var token = tokenHandler.CreateEncodedJwt(tokenDescriptor); |             var token = tokenHandler.CreateEncodedJwt(tokenDescriptor); | ||||||
| 
 | 
 | ||||||
|             return token; |             return (token, adapter.Modules); | ||||||
|         } |         } | ||||||
| 
 | 
 | ||||||
|         public ActionResult<TimeSpan> ValidateTokenExpiration(string tokenExpiration) |         public ActionResult<TimeSpan> ValidateTokenExpiration(string tokenExpiration) | ||||||
							
								
								
									
										42
									
								
								Core.Thalos.BuildingBlocks/Settings/AuthSettings.cs
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										42
									
								
								Core.Thalos.BuildingBlocks/Settings/AuthSettings.cs
									
									
									
									
									
										Normal file
									
								
							| @@ -0,0 +1,42 @@ | |||||||
|  | // *********************************************************************** | ||||||
|  | // <copyright file="AuthSettings.cs"> | ||||||
|  | //     AgileWebs | ||||||
|  | // </copyright> | ||||||
|  | // *********************************************************************** | ||||||
|  |  | ||||||
|  | namespace Core.Thalos.BuildingBlocks; | ||||||
|  | public class AuthSettings | ||||||
|  | { | ||||||
|  |     public AzureAuthSettings? Azure { get; set; } | ||||||
|  |     public TokenAuthSettings Token { get; set; } = null!; | ||||||
|  |     public GoogleAuthSettings? Google { get; set; } | ||||||
|  | } | ||||||
|  |  | ||||||
|  | public class AzureAuthSettings | ||||||
|  | { | ||||||
|  |     public string? Instance { get; set; } | ||||||
|  |     public string? TenantId { get; set; } | ||||||
|  |     public string? ClientId { get; set; } | ||||||
|  |     public string? ClientSecret { get; set; } | ||||||
|  |     public string? ThalosAppAuthorizationUrl { get; set; } | ||||||
|  |     public string? ThalosAppTokenUrl { get; set; } | ||||||
|  |     public string? ThalosAppClientId { get; set; } | ||||||
|  |     public string? ThalosAppScope { get; set; } | ||||||
|  | } | ||||||
|  |  | ||||||
|  | public class GoogleAuthSettings | ||||||
|  | { | ||||||
|  |     public string? ClientId { get; set; } | ||||||
|  |     public string? ClientSecret { get; set; } | ||||||
|  |     public string? RedirectUri { get; set; } | ||||||
|  |  | ||||||
|  | } | ||||||
|  |  | ||||||
|  | public class TokenAuthSettings | ||||||
|  | { | ||||||
|  |     public string? PrivateKey { get; set; } | ||||||
|  |     public string? PublicKey { get; set; } | ||||||
|  |     public string? Audience { get; set; } | ||||||
|  |     public string? Issuer { get; set; } | ||||||
|  | } | ||||||
|  |  | ||||||
							
								
								
									
										8
									
								
								Core.Thalos.BuildingBlocks/Settings/IdentityProviders.cs
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										8
									
								
								Core.Thalos.BuildingBlocks/Settings/IdentityProviders.cs
									
									
									
									
									
										Normal file
									
								
							| @@ -0,0 +1,8 @@ | |||||||
|  | namespace Core.Thalos.BuildingBlocks | ||||||
|  | { | ||||||
|  |     public class IdentityProviders | ||||||
|  |     { | ||||||
|  |         public bool Google { get; set; } | ||||||
|  |         public bool Azure { get; set; } | ||||||
|  |     } | ||||||
|  | } | ||||||
| @@ -1,13 +1,12 @@ | |||||||
| // *********************************************************************** | // *********************************************************************** | ||||||
| // <copyright file="HttpContextTokenProvider.cs"> | // <copyright file="HttpContextTokenProvider.cs"> | ||||||
| //     Heath | //     AgileWebs | ||||||
| // </copyright> | // </copyright> | ||||||
| // *********************************************************************** | // *********************************************************************** | ||||||
| 
 | 
 | ||||||
| using Core.Cerberos.Adapters.Contracts; |  | ||||||
| using Microsoft.AspNetCore.Http; | using Microsoft.AspNetCore.Http; | ||||||
| 
 | 
 | ||||||
| namespace Core.Cerberos.Adapters.TokenProvider | namespace Core.Thalos.BuildingBlocks | ||||||
| { | { | ||||||
|     /// <summary> |     /// <summary> | ||||||
|     /// Class to return the access token to controllers. |     /// Class to return the access token to controllers. | ||||||
		Reference in New Issue
	
	Block a user