增加了AuthGate

This commit is contained in:
2026-05-12 09:39:23 +08:00
parent aef62a3472
commit 7a2ff896b2
12 changed files with 325 additions and 36 deletions
+169
View File
@@ -0,0 +1,169 @@
using System;
using System.Collections.Generic;
using System.Net.Http;
using System.Net.Http.Json;
using SimApi.Communications;
using static SimApi.Helpers.SimApiError;
namespace SimApi.AuthGate;
public class SimApiAuthGate(SimApiAuthGateClient simapi)
{
#region AuthGate公开接口
/// <summary>
/// 委托AuthCenter进行应用签名验证
/// </summary>
/// <param name="appId"></param>
/// <param name="timestamp"></param>
/// <param name="nonce"></param>
/// <param name="sign"></param>
public void VerifySign(string appId, string timestamp, string nonce, string sign)
{
var http = new HttpClient();
var url = $"{simapi.Server}/api/auth/sign/verify?appId={appId}&timestamp={timestamp}&nonce={nonce}&sign={sign}";
var result = http.PostAsJsonAsync(url, new { }).Result;
var resp = result.Content.ReadFromJsonAsync<SimApiBaseResponse>().Result;
ErrorWhenNull(resp, 400, "签名验证失败");
ErrorWhenFalse(resp.Code == 200, 400, "签名验证失败");
}
/// <summary>
/// 根据关键字,搜索用户Profile,参数支持精准ID,用户手机号,用户邮箱,Profile名称模糊搜索
/// </summary>
/// <param name="keyword"></param>
/// <param name="skip"></param>
/// <param name="take"></param>
/// <returns></returns>
public SimApiAuthGateDto.AppAndProfileItem[]? ProfileSearch(string keyword, int skip = 0, int take = 20)
{
return simapi.SignQuery<SimApiAuthGateDto.AppAndProfileItem[]>("/api/auth/profile/search",
new { keyword, skip, take });
}
/// <summary>
/// 通过id,可以批量获取用户的基本信息
/// </summary>
/// <param name="ids"></param>
/// <returns></returns>
public SimApiAuthGateDto.AppAndProfileItem[]? ProfileList(string[] ids)
{
return simapi.SignQuery<SimApiAuthGateDto.AppAndProfileItem[]>("/api/auth/profile/list", new { ids });
}
#endregion
#region AuthGate内部应用专用 - :
/// <summary>
/// 获取是否为App的拥有者
/// </summary>
/// <param name="profileId"></param>
/// <param name="applicationId"></param>
/// <returns></returns>
public bool CheckIsAppOwner(string profileId, string applicationId)
{
return simapi.SignQuery<bool>("/api/auth/internal/apps/check-owner", new
{
ProfileId = profileId,
AppId = applicationId,
});
}
/// <summary>
/// 获取应用列表,根据用户profileId 和 提供的appIds
/// </summary>
/// <param name="profileId"></param>
/// <param name="appIds"></param>
/// <returns></returns>
public SimApiAuthGateDto.AppAndProfileItem[]? GetAppList(string profileId, IEnumerable<string> appIds)
{
return simapi.SignQuery<SimApiAuthGateDto.AppAndProfileItem[]>("/api/auth/internal/apps/related", new
{
ProfileId = profileId,
AllowedAppIds = appIds,
});
}
#endregion
#region
/// <summary>
/// 获取登录授权CODE
/// </summary>
/// <param name="scene"></param>
/// <param name="data"></param>
/// <param name="backUrl"></param>
/// <returns></returns>
public SimApiAuthGateDto.GetCodeResponse GetAuthCode(string? scene = null, Dictionary<string, object>? data = null,
string? backUrl = null)
{
var code = simapi.SignQuery<string>("/api/auth/confirm/code",
new { scene, data, backUrl });
return new SimApiAuthGateDto.GetCodeResponse()
{
Code = code!,
Server = simapi.Server,
FullUrl = $"{simapi.Server}/auth?code={code}"
};
}
/// <summary>
/// 使用code获取登录信息
/// </summary>
/// <param name="code"></param>
/// <param name="scene"></param>
/// <returns></returns>
public SimApiAuthGateDto.AuthInfoResponse GetAuthInfo(string code, string? scene = null)
{
var resp = simapi.SignQuery<SimApiAuthGateDto.AuthInfoResponse>("/api/auth/confirm/get", new { code });
ErrorWhenNull(resp, 400232, "登录信息获取失败");
ErrorWhen(resp.Scene != scene, 403003, "登录场景不匹配");
return resp;
}
#endregion
#region
/// <summary>
/// 获取安全验证代码
/// </summary>
/// <param name="scene"></param>
/// <param name="userId"></param>
/// <param name="data"></param>
/// <param name="backUrl"></param>
/// <returns></returns>
public SimApiAuthGateDto.GetCodeResponse GetConfirmCode(string scene, string userId,
Dictionary<string, object>? data = null,
string? backUrl = null)
{
var code = simapi.SignQuery<string>("/api/auth/confirm/code",
new { scene, data, backUrl, profileId = userId });
return new SimApiAuthGateDto.GetCodeResponse()
{
Code = code!,
Server = simapi.Server,
FullUrl = $"{simapi.Server}/confirm?code={code}"
};
}
/// <summary>
/// 使用安全验证code 获取验证结果
/// </summary>
/// <param name="code"></param>
/// <param name="scene"></param>
/// <param name="userId"></param>
/// <returns></returns>
public SimApiAuthGateDto.ConfirmResponse Confirm(string code, string scene, string? userId = null)
{
var resp = simapi.SignQuery<SimApiAuthGateDto.ConfirmResponse>("/api/auth/confirm/get", new { code });
ErrorWhenNull(resp, 403001, "安全确认码无效");
ErrorWhen(resp.ProfileId != userId, 403002, "安全确认身份不匹配");
ErrorWhen(resp.Scene != scene, 403003, "安全确认场景不匹配");
return resp;
}
#endregion
}
+11
View File
@@ -0,0 +1,11 @@
using SimApi.Configurations;
using SimApi.Helpers;
namespace SimApi.AuthGate;
public class SimApiAuthGateClient(SimApiOptions apiOptions) : SimApiHttpClient
{
public override string Server { get; init; } = apiOptions.SimApiAuthGateOptions.Server ?? string.Empty;
public override string AppId { get; init; } = apiOptions.SimApiAuthGateOptions.AppId ?? string.Empty;
public override string AppKey { get; init; } = apiOptions.SimApiAuthGateOptions.AppKey ?? string.Empty;
}
+40
View File
@@ -0,0 +1,40 @@
using System;
using System.Collections.Generic;
namespace SimApi.AuthGate;
public class SimApiAuthGateDto
{
public class AppAndProfileItem
{
public string Id { get; set; } = "";
public string Name { get; set; } = "";
public string? Image { get; set; }
public string? Description { get; set; }
}
public class ConfirmResponse
{
public required string ApplicationId { get; set; }
public required string ProfileId { get; set; }
public string? Scene { get; set; }
public Dictionary<string, object>? Data { get; set; }
}
public class AuthInfoResponse
{
public string? Scene { get; set; }
public Dictionary<string, object>? Data { get; set; }
public required string ProfileId { get; set; }
public required string Name { get; set; }
public string? Image { get; set; }
public string? Description { get; set; }
}
public class GetCodeResponse
{
public required string Code { get; set; }
public required string Server { get; set; }
public required string FullUrl { get; set; }
}
}
@@ -1,14 +1,13 @@
using System; using System.Threading.Tasks;
using System.Threading.Tasks;
using Microsoft.AspNetCore.Http; using Microsoft.AspNetCore.Http;
using Microsoft.Extensions.Logging; using Microsoft.Extensions.Logging;
using SimApi.Communications; using SimApi.Communications;
using SimApi.Configurations; using SimApi.Configurations;
using SimApi.Helpers; using SimApi.Helpers;
namespace SimApi.Middlewares; namespace SimApi.AuthGate;
public class SimApiGateAuthMiddleware(RequestDelegate next, ILogger<SimApiGateAuthMiddleware> logger) public class SimApiAuthGateMiddleware(RequestDelegate next, ILogger<SimApiAuthGateMiddleware> logger)
{ {
public Task Invoke(HttpContext httpContext, SimApiOptions simApiOptions) public Task Invoke(HttpContext httpContext, SimApiOptions simApiOptions)
{ {
@@ -17,7 +16,7 @@ public class SimApiGateAuthMiddleware(RequestDelegate next, ILogger<SimApiGateAu
httpContext.Request.Headers.TryGetValue("X-SimApi-Gate-Sign", out var sign)) httpContext.Request.Headers.TryGetValue("X-SimApi-Gate-Sign", out var sign))
{ {
var signStr = var signStr =
$"appId={simApiOptions.SimApiGateAuthOptions.AppId}&auth={auth}&time={time}&appKey={simApiOptions.SimApiGateAuthOptions.AppKey}"; $"appId={simApiOptions.SimApiAuthGateOptions.AppId}&auth={auth}&time={time}&appKey={simApiOptions.SimApiAuthGateOptions.AppKey}";
logger.LogDebug($"签名字符串 => {signStr}"); logger.LogDebug($"签名字符串 => {signStr}");
if (SimApiUtil.Md5(signStr) == sign && !string.IsNullOrEmpty(auth)) if (SimApiUtil.Md5(signStr) == sign && !string.IsNullOrEmpty(auth))
{ {
+45
View File
@@ -0,0 +1,45 @@
using Microsoft.Extensions.Logging;
using static SimApi.Helpers.SimApiError;
namespace SimApi.AuthGate;
public class SimApiIam(SimApiAuthGateClient simapi, ILogger<SimApiIam> logger)
{
/// <summary>
/// 向Iam注册权限
/// </summary>
/// <param name="permissions"></param>
public void RegisterPermissions(SimApiIamDto.PermissionItem[] permissions)
{
var log = $"检测到 {permissions.Length} 个权限接口,正在注册..: ";
foreach (var permission in permissions)
{
log += $"\n |- {permission.Identifier} => [{permission.Group}]{permission.Name} ({permission.Description})";
}
logger.LogInformation(log);
simapi.SignQuery<string>("/api/iam/permission/register", new { permissions });
logger.LogInformation("权限注册完成");
}
/// <summary>
/// 获取拥有的权限标识数组
/// </summary>
/// <param name="profileId"></param>
/// <returns></returns>
public string[] GetPermissionOwned(string profileId)
{
return simapi.SignQuery<string[]>("/api/iam/permission/owned", new { profileId }) ?? [];
}
/// <summary>
/// 检测profileId是否有这个权限
/// </summary>
/// <param name="profileId"></param>
/// <param name="permission"></param>
public void CheckPermission(string profileId, string permission)
{
var ok = simapi.SignQuery<bool>("/api/iam/permission/check", new { profileId, permission });
ErrorWhen(!ok, 403, "没有该权限");
}
}
+12
View File
@@ -0,0 +1,12 @@
namespace SimApi.AuthGate;
public class SimApiIamDto
{
public class PermissionItem
{
public required string Identifier { get; init; }
public required string Name { get; init; }
public required string Group { get; init; }
public required string Description { get; init; }
}
}
+14
View File
@@ -0,0 +1,14 @@
namespace SimApi.Configurations;
public class SimApiAuthGateOptions
{
public string? Server { get; set; }
public string? AppId { get; set; }
public string? AppKey { get; set; }
/// <summary>
/// 开启则使用内部网关透传的Middleware
/// 注意: 只有内部应用需要开启这个,也就是api通过内部网关代理后
/// </summary>
public bool UseMiddleware { get; set; }
}
-8
View File
@@ -1,8 +0,0 @@
namespace SimApi.Configurations;
public class SimApiGateAuthOptions
{
public string? AppId { get; set; }
public string? AppKey { get; set; }
}
+4 -9
View File
@@ -20,12 +20,7 @@ public class SimApiOptions
/// <summary> /// <summary>
/// 启用SimApi网关授权, 基于上层网关透传的身份令牌验证 /// 启用SimApi网关授权, 基于上层网关透传的身份令牌验证
/// </summary> /// </summary>
public bool EnableSimApiGateAuth { get; set; } public bool EnableSimApiAuthGate { get; set; }
/// <summary>
/// 是否使用CoceSdk
/// </summary>
public bool EnableCoceSdk { get; set; }
/// <summary> /// <summary>
/// 开启S3兼容的存储系统。 /// 开启S3兼容的存储系统。
@@ -109,7 +104,7 @@ public class SimApiOptions
public SimApiSynapseOptions SimApiSynapseOptions { get; set; } = new(); public SimApiSynapseOptions SimApiSynapseOptions { get; set; } = new();
public SimApiGateAuthOptions SimApiGateAuthOptions { get; set; } = new(); public SimApiAuthGateOptions SimApiAuthGateOptions { get; set; } = new();
public SimApiHttpClientOptions SimApiHttpClientOptions { get; set; } = new(); public SimApiHttpClientOptions SimApiHttpClientOptions { get; set; } = new();
@@ -145,8 +140,8 @@ public class SimApiOptions
options?.Invoke(SimApiJobOptions); options?.Invoke(SimApiJobOptions);
} }
public void ConfigureSimApiGateAuth(Action<SimApiGateAuthOptions>? options = null) public void ConfigureSimApiAuthGate(Action<SimApiAuthGateOptions>? options = null)
{ {
options?.Invoke(SimApiGateAuthOptions); options?.Invoke(SimApiAuthGateOptions);
} }
} }
+1
View File
@@ -21,4 +21,5 @@ public class SimApiAuthController(SimApiAuth auth) : SimApiBaseController
auth.Logout(value!); auth.Logout(value!);
} }
} }
} }
+8 -8
View File
@@ -12,15 +12,15 @@ namespace SimApi.Helpers;
public class SimApiHttpClient(SimApiOptions? apiOptions = null, ILogger<SimApiHttpClient>? logger = null) public class SimApiHttpClient(SimApiOptions? apiOptions = null, ILogger<SimApiHttpClient>? logger = null)
{ {
public string Server { get; init; } = apiOptions?.SimApiHttpClientOptions.Server ?? string.Empty; public virtual string Server { get; init; } = apiOptions?.SimApiHttpClientOptions.Server ?? string.Empty;
public string AppId { get; init; } = apiOptions?.SimApiHttpClientOptions.AppId ?? string.Empty; public virtual string AppId { get; init; } = apiOptions?.SimApiHttpClientOptions.AppId ?? string.Empty;
public string AppKey { get; init; } = apiOptions?.SimApiHttpClientOptions.AppKey ?? string.Empty; public virtual string AppKey { get; init; } = apiOptions?.SimApiHttpClientOptions.AppKey ?? string.Empty;
public string SignName { get; init; } = "sign"; public virtual string SignName { get; init; } = "sign";
public string TimestampName { get; init; } = "timestamp"; public virtual string TimestampName { get; init; } = "timestamp";
public string NonceName { get; init; } = "nonce"; public virtual string NonceName { get; init; } = "nonce";
public string? AppIdName { get; init; } = "appId"; public virtual string? AppIdName { get; init; } = "appId";
public string[] SignFields { get; init; } = []; public virtual string[] SignFields { get; init; } = [];
/// <summary> /// <summary>
/// 发起签名请求 /// 发起签名请求
+17 -6
View File
@@ -16,6 +16,7 @@ using Microsoft.AspNetCore.Mvc;
using Microsoft.Extensions.Hosting; using Microsoft.Extensions.Hosting;
using Microsoft.Extensions.Logging; using Microsoft.Extensions.Logging;
using SimApi.Attributes; using SimApi.Attributes;
using SimApi.AuthGate;
using SimApi.Configurations; using SimApi.Configurations;
using SimApi.Interfaces; using SimApi.Interfaces;
using SimApi.Logger; using SimApi.Logger;
@@ -328,6 +329,13 @@ public static class SimApiExtensions
}); });
} }
if (simApiOptions.EnableSimApiAuthGate)
{
builder.AddSingleton<SimApiAuthGateClient>();
builder.AddSingleton<SimApiAuthGate>();
builder.AddSingleton<SimApiIam>();
}
builder.AddSingleton(simApiOptions); builder.AddSingleton(simApiOptions);
return builder; return builder;
} }
@@ -411,17 +419,20 @@ public static class SimApiExtensions
logger.LogInformation(msg); logger.LogInformation(msg);
} }
if (options.EnableSimApiGateAuth) if (options.EnableSimApiAuthGate)
{ {
logger.LogInformation("开始配置SimApiGateAuth..."); logger.LogInformation("开始配置SimApiAuthGate...");
if (string.IsNullOrEmpty(options.SimApiGateAuthOptions.AppId) || if (string.IsNullOrEmpty(options.SimApiAuthGateOptions.AppId) ||
string.IsNullOrEmpty(options.SimApiGateAuthOptions.AppKey)) string.IsNullOrEmpty(options.SimApiAuthGateOptions.AppKey))
{ {
logger.LogCritical("必须配置Gate的AppId和AppKey才能启用SimApiGateAuth"); logger.LogCritical("必须配置AuthGate的AppId和AppKey才能启用SimApiAuthGate");
} }
else else
{ {
builder.UseMiddleware<SimApiGateAuthMiddleware>(); if (options.SimApiAuthGateOptions.UseMiddleware)
{
builder.UseMiddleware<SimApiAuthGateMiddleware>();
}
} }
} }