修改命名空间
This commit is contained in:
@@ -0,0 +1,226 @@
|
||||
using System.Collections.Generic;
|
||||
using System.Net.Http;
|
||||
using System.Net.Http.Json;
|
||||
using SimApi.Communications;
|
||||
using static SimApi.Helpers.SimApiError;
|
||||
|
||||
namespace SimApi.AuthSDK;
|
||||
|
||||
public class SimApiAuthCenter(SimApiAuthClient simapi)
|
||||
{
|
||||
public SimApiAuthClient Client { get; } = simapi;
|
||||
|
||||
#region 公共
|
||||
|
||||
/// <summary>
|
||||
/// 委托AuthCenter进行应用签名验证
|
||||
/// </summary>
|
||||
/// <param name="appId"></param>
|
||||
/// <param name="timestamp"></param>
|
||||
/// <param name="nonce"></param>
|
||||
/// <param name="sign"></param>
|
||||
public void VerifySign(string appId, string timestamp, string nonce, string sign)
|
||||
{
|
||||
var http = new HttpClient();
|
||||
var url = $"{Client.Server}/api/auth/sign/verify?appId={appId}×tamp={timestamp}&nonce={nonce}&sign={sign}";
|
||||
var result = http.PostAsJsonAsync(url, new { }).Result;
|
||||
var resp = result.Content.ReadFromJsonAsync<SimApiBaseResponse>().Result;
|
||||
ErrorWhenNull(resp, 400, "签名验证失败");
|
||||
ErrorWhenFalse(resp.Code == 200, 400, "签名验证失败");
|
||||
}
|
||||
|
||||
#endregion
|
||||
|
||||
|
||||
#region 群组相关
|
||||
|
||||
/// <summary>
|
||||
/// 根据profileId获取群组列表
|
||||
/// </summary>
|
||||
/// <param name="profileId"></param>
|
||||
/// <returns></returns>
|
||||
public SimApiAuthCenterDto.GroupRelatedItem[]? GroupRelated(string profileId)
|
||||
{
|
||||
return Client.SignQuery<SimApiAuthCenterDto.GroupRelatedItem[]>("/api/auth/group/related", new { profileId });
|
||||
}
|
||||
|
||||
/// <summary>
|
||||
/// 根据关键字搜索群组,输入群组ID精准搜索
|
||||
/// </summary>
|
||||
/// <param name="keyword"></param>
|
||||
/// <param name="skip"></param>
|
||||
/// <param name="take"></param>
|
||||
/// <returns></returns>
|
||||
public SimApiAuthCenterDto.AppAndProfileItem[]? GroupSearch(string keyword, int skip = 0, int take = 20)
|
||||
{
|
||||
return Client.SignQuery<SimApiAuthCenterDto.AppAndProfileItem[]>("/api/auth/group/search",
|
||||
new { keyword, skip, take });
|
||||
}
|
||||
|
||||
/// <summary>
|
||||
/// 使用组ID以及组内成员,管理员profile获取组的详细树结构
|
||||
/// </summary>
|
||||
/// <param name="profileId"></param>
|
||||
/// <param name="groupId"></param>
|
||||
/// <returns></returns>
|
||||
public SimApiAuthCenterDto.GroupDetailTreeNode? GroupDetail(string groupId, string profileId)
|
||||
{
|
||||
return Client.SignQuery<SimApiAuthCenterDto.GroupDetailTreeNode>("/api/auth/group/detail",
|
||||
new { profileId, groupId });
|
||||
}
|
||||
|
||||
/// <summary>
|
||||
/// 获取profile在本组的所有子组
|
||||
/// </summary>
|
||||
/// <param name="groupId"></param>
|
||||
/// <param name="profileId"></param>
|
||||
/// <returns></returns>
|
||||
public string[]? GroupRelatedIndex(string groupId, string profileId)
|
||||
{
|
||||
return Client.SignQuery<string[]>("/api/auth/internal/group/get-related-groupid", new { groupId, profileId });
|
||||
}
|
||||
|
||||
#endregion
|
||||
|
||||
#region Profile相关
|
||||
|
||||
/// <summary>
|
||||
/// 根据关键字,搜索用户Profile,参数支持精准ID,用户手机号,用户邮箱,Profile名称模糊搜索
|
||||
/// </summary>
|
||||
/// <param name="keyword"></param>
|
||||
/// <param name="skip"></param>
|
||||
/// <param name="take"></param>
|
||||
/// <returns></returns>
|
||||
public SimApiAuthCenterDto.AppAndProfileItem[]? ProfileSearch(string keyword, int skip = 0, int take = 20)
|
||||
{
|
||||
return Client.SignQuery<SimApiAuthCenterDto.AppAndProfileItem[]>("/api/auth/profile/search",
|
||||
new { keyword, skip, take });
|
||||
}
|
||||
|
||||
/// <summary>
|
||||
/// 通过id,可以批量获取用户的基本信息
|
||||
/// </summary>
|
||||
/// <param name="ids"></param>
|
||||
/// <returns></returns>
|
||||
public SimApiAuthCenterDto.AppAndProfileItem[]? ProfileList(string[] ids)
|
||||
{
|
||||
return Client.SignQuery<SimApiAuthCenterDto.AppAndProfileItem[]>("/api/auth/profile/list", new { ids });
|
||||
}
|
||||
|
||||
#endregion
|
||||
|
||||
#region AuthGate内部应用专用 - 注意: 只有内部应用可以调用
|
||||
|
||||
/// <summary>
|
||||
/// 获取是否为App的拥有者
|
||||
/// </summary>
|
||||
/// <param name="profileId"></param>
|
||||
/// <param name="applicationId"></param>
|
||||
/// <returns></returns>
|
||||
public bool CheckIsAppOwner(string profileId, string applicationId)
|
||||
{
|
||||
return Client.SignQuery<bool>("/api/auth/internal/apps/check-owner", new
|
||||
{
|
||||
ProfileId = profileId,
|
||||
AppId = applicationId,
|
||||
});
|
||||
}
|
||||
|
||||
/// <summary>
|
||||
/// 获取应用列表,根据用户profileId 和 提供的appIds
|
||||
/// </summary>
|
||||
/// <param name="profileId"></param>
|
||||
/// <param name="appIds"></param>
|
||||
/// <returns></returns>
|
||||
public SimApiAuthCenterDto.AppAndProfileItem[]? GetAppList(string profileId, IEnumerable<string> appIds)
|
||||
{
|
||||
return Client.SignQuery<SimApiAuthCenterDto.AppAndProfileItem[]>("/api/auth/internal/apps/related", new
|
||||
{
|
||||
ProfileId = profileId,
|
||||
AllowedAppIds = appIds,
|
||||
});
|
||||
}
|
||||
|
||||
#endregion
|
||||
|
||||
#region 系统登录
|
||||
|
||||
/// <summary>
|
||||
/// 获取登录授权CODE
|
||||
/// </summary>
|
||||
/// <param name="scene"></param>
|
||||
/// <param name="data"></param>
|
||||
/// <param name="backUrl"></param>
|
||||
/// <returns></returns>
|
||||
public SimApiAuthCenterDto.GetCodeResponse GetLoginCode(string? scene = null,
|
||||
Dictionary<string, object>? data = null,
|
||||
string? backUrl = null)
|
||||
{
|
||||
var code = Client.SignQuery<string>("/api/auth/login/code",
|
||||
new { scene, data, backUrl });
|
||||
return new SimApiAuthCenterDto.GetCodeResponse()
|
||||
{
|
||||
Code = code!,
|
||||
Server = Client.Server,
|
||||
FullUrl = $"{Client.Server}/auth?code={code}"
|
||||
};
|
||||
}
|
||||
|
||||
/// <summary>
|
||||
/// 使用code获取登录信息
|
||||
/// </summary>
|
||||
/// <param name="code"></param>
|
||||
/// <param name="scene"></param>
|
||||
/// <returns></returns>
|
||||
public SimApiAuthCenterDto.LoginInfoResponse GetLoginInfo(string code, string? scene = null)
|
||||
{
|
||||
var resp = Client.SignQuery<SimApiAuthCenterDto.LoginInfoResponse>("/api/auth/login/get", new { code });
|
||||
ErrorWhenNull(resp, 400232, "登录信息获取失败");
|
||||
ErrorWhen(resp.Scene != scene, 403003, "登录场景不匹配");
|
||||
return resp;
|
||||
}
|
||||
|
||||
#endregion
|
||||
|
||||
#region 安全验证
|
||||
|
||||
/// <summary>
|
||||
/// 获取安全验证代码
|
||||
/// </summary>
|
||||
/// <param name="scene"></param>
|
||||
/// <param name="userId"></param>
|
||||
/// <param name="data"></param>
|
||||
/// <param name="backUrl"></param>
|
||||
/// <returns></returns>
|
||||
public SimApiAuthCenterDto.GetCodeResponse GetConfirmCode(string scene, string userId,
|
||||
Dictionary<string, object>? data = null,
|
||||
string? backUrl = null)
|
||||
{
|
||||
var code = Client.SignQuery<string>("/api/auth/confirm/code",
|
||||
new { scene, data, backUrl, profileId = userId });
|
||||
return new SimApiAuthCenterDto.GetCodeResponse()
|
||||
{
|
||||
Code = code!,
|
||||
Server = Client.Server,
|
||||
FullUrl = $"{Client.Server}/confirm?code={code}"
|
||||
};
|
||||
}
|
||||
|
||||
/// <summary>
|
||||
/// 使用安全验证code 获取验证结果
|
||||
/// </summary>
|
||||
/// <param name="code"></param>
|
||||
/// <param name="scene"></param>
|
||||
/// <param name="userId"></param>
|
||||
/// <returns></returns>
|
||||
public SimApiAuthCenterDto.ConfirmResponse Confirm(string code, string scene, string? userId = null)
|
||||
{
|
||||
var resp = Client.SignQuery<SimApiAuthCenterDto.ConfirmResponse>("/api/auth/confirm/get", new { code });
|
||||
ErrorWhenNull(resp, 403001, "安全确认码无效");
|
||||
ErrorWhen(resp.ProfileId != userId, 403002, "安全确认身份不匹配");
|
||||
ErrorWhen(resp.Scene != scene, 403003, "安全确认场景不匹配");
|
||||
return resp;
|
||||
}
|
||||
|
||||
#endregion
|
||||
}
|
||||
@@ -0,0 +1,61 @@
|
||||
using System;
|
||||
using System.Collections.Generic;
|
||||
|
||||
namespace SimApi.AuthSDK;
|
||||
|
||||
public class SimApiAuthCenterDto
|
||||
{
|
||||
public class AppAndProfileItem
|
||||
{
|
||||
public required string Id { get; set; }
|
||||
public required string Name { get; set; }
|
||||
public string? Image { get; set; }
|
||||
public string? Description { get; set; }
|
||||
}
|
||||
|
||||
public class ConfirmResponse
|
||||
{
|
||||
public required string ApplicationId { get; set; }
|
||||
public required string ProfileId { get; set; }
|
||||
public string? Scene { get; set; }
|
||||
public Dictionary<string, object>? Data { get; set; }
|
||||
}
|
||||
|
||||
public class LoginInfoResponse
|
||||
{
|
||||
public string? Scene { get; set; }
|
||||
public Dictionary<string, object>? Data { get; set; }
|
||||
public required string ProfileId { get; set; }
|
||||
public required string Name { get; set; }
|
||||
public string? Image { get; set; }
|
||||
public string? Description { get; set; }
|
||||
}
|
||||
|
||||
public class GetCodeResponse
|
||||
{
|
||||
public required string Code { get; set; }
|
||||
public required string Server { get; set; }
|
||||
public required string FullUrl { get; set; }
|
||||
}
|
||||
|
||||
public class GroupRelatedItem
|
||||
{
|
||||
public required string Id { get; set; }
|
||||
public required string Name { get; set; }
|
||||
public string? Image { get; set; }
|
||||
public string? Description { get; set; }
|
||||
public bool IsOwner { get; set; }
|
||||
public bool IsAdmin { get; set; }
|
||||
public bool IsMember { get; set; }
|
||||
}
|
||||
|
||||
public class GroupDetailTreeNode
|
||||
{
|
||||
public required string Id { get; set; }
|
||||
public required string Name { get; set; }
|
||||
public string? Image { get; set; }
|
||||
public string? Description { get; set; }
|
||||
public int Sort { get; set; }
|
||||
public List<GroupDetailTreeNode> Children { get; set; } = [];
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,34 @@
|
||||
using System.Threading.Tasks;
|
||||
using Microsoft.AspNetCore.Http;
|
||||
using Microsoft.Extensions.Logging;
|
||||
using SimApi.Communications;
|
||||
using SimApi.Configurations;
|
||||
using SimApi.Helpers;
|
||||
|
||||
namespace SimApi.AuthSDK;
|
||||
|
||||
public class SimApiAuthCenterMiddleware(RequestDelegate next, ILogger<SimApiAuthCenterMiddleware> logger)
|
||||
{
|
||||
public Task Invoke(HttpContext httpContext, SimApiOptions simApiOptions)
|
||||
{
|
||||
if (httpContext.Request.Headers.TryGetValue("X-SimApi-Gate-Auth", out var auth) &&
|
||||
httpContext.Request.Headers.TryGetValue("X-SimApi-Gate-Time", out var time) &&
|
||||
httpContext.Request.Headers.TryGetValue("X-SimApi-Gate-Sign", out var sign))
|
||||
{
|
||||
var signStr =
|
||||
$"appId={simApiOptions.SimApiAuthGateOptions.AppId}&auth={auth}&time={time}&appKey={simApiOptions.SimApiAuthGateOptions.AppKey}";
|
||||
logger.LogDebug($"签名字符串 => {signStr}");
|
||||
if (SimApiUtil.Md5(signStr) == sign && !string.IsNullOrEmpty(auth))
|
||||
{
|
||||
var login = SimApiUtil.Base64Decode<SimApiLoginItem>(auth!);
|
||||
httpContext.Items.Add("LoginInfo", login);
|
||||
}
|
||||
else
|
||||
{
|
||||
logger.LogDebug("签名不匹配");
|
||||
}
|
||||
}
|
||||
|
||||
return next(httpContext);
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,13 @@
|
||||
using Microsoft.Extensions.Logging;
|
||||
using SimApi.Configurations;
|
||||
using SimApi.Helpers;
|
||||
|
||||
namespace SimApi.AuthSDK;
|
||||
|
||||
public class SimApiAuthClient(SimApiOptions apiOptions, ILogger<SimApiAuthClient> logger)
|
||||
: SimApiHttpClient(apiOptions, logger)
|
||||
{
|
||||
public override string Server { get; init; } = apiOptions.SimApiAuthGateOptions.Server ?? string.Empty;
|
||||
public override string AppId { get; init; } = apiOptions.SimApiAuthGateOptions.AppId ?? string.Empty;
|
||||
public override string AppKey { get; init; } = apiOptions.SimApiAuthGateOptions.AppKey ?? string.Empty;
|
||||
}
|
||||
@@ -0,0 +1,45 @@
|
||||
using Microsoft.Extensions.Logging;
|
||||
using static SimApi.Helpers.SimApiError;
|
||||
|
||||
namespace SimApi.AuthSDK;
|
||||
|
||||
public class SimApiAuthIam(SimApiAuthClient simapi, ILogger<SimApiAuthIam> logger)
|
||||
{
|
||||
/// <summary>
|
||||
/// 向Iam注册权限
|
||||
/// </summary>
|
||||
/// <param name="permissions"></param>
|
||||
public void RegisterPermissions(SimApiAuthIamDto.PermissionItem[] permissions)
|
||||
{
|
||||
var log = $"检测到 {permissions.Length} 个权限接口,正在注册..: ";
|
||||
foreach (var permission in permissions)
|
||||
{
|
||||
log += $"\n |- {permission.Identifier} => [{permission.Group}]{permission.Name} ({permission.Description})";
|
||||
}
|
||||
|
||||
logger.LogInformation(log);
|
||||
simapi.SignQuery<string>("/api/iam/permission/register", new { permissions });
|
||||
logger.LogInformation("权限注册完成");
|
||||
}
|
||||
|
||||
/// <summary>
|
||||
/// 获取拥有的权限标识数组
|
||||
/// </summary>
|
||||
/// <param name="profileId"></param>
|
||||
/// <returns></returns>
|
||||
public string[] GetPermissionOwned(string profileId)
|
||||
{
|
||||
return simapi.SignQuery<string[]>("/api/iam/permission/owned", new { profileId }) ?? [];
|
||||
}
|
||||
|
||||
/// <summary>
|
||||
/// 检测profileId是否有这个权限
|
||||
/// </summary>
|
||||
/// <param name="profileId"></param>
|
||||
/// <param name="permission"></param>
|
||||
public void CheckPermission(string profileId, string permission)
|
||||
{
|
||||
var ok = simapi.SignQuery<bool>("/api/iam/permission/check", new { profileId, permission });
|
||||
ErrorWhen(!ok, 403, "没有该权限");
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,12 @@
|
||||
namespace SimApi.AuthSDK;
|
||||
|
||||
public class SimApiAuthIamDto
|
||||
{
|
||||
public class PermissionItem
|
||||
{
|
||||
public required string Identifier { get; init; }
|
||||
public required string Name { get; init; }
|
||||
public required string Group { get; init; }
|
||||
public required string Description { get; init; }
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user