Compare commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
2499912204 | ||
|
|
dd38f315d5 | ||
|
|
c448381f23 | ||
|
|
8d5b667c88 | ||
|
|
65451d7b80 | ||
|
|
c7373da691 |
@@ -0,0 +1,20 @@
|
|||||||
|
using System;
|
||||||
|
using Microsoft.AspNetCore.Mvc;
|
||||||
|
using Microsoft.AspNetCore.Mvc.ModelBinding;
|
||||||
|
using SimApi.ModelBinders;
|
||||||
|
|
||||||
|
namespace SimApi.Attributes;
|
||||||
|
|
||||||
|
[AttributeUsage(AttributeTargets.Parameter)]
|
||||||
|
public class AesBodyAttribute : ModelBinderAttribute
|
||||||
|
{
|
||||||
|
public Type KeyProvider { get; set; } = typeof(AesBodyProviderBase);
|
||||||
|
public override BindingSource BindingSource => BindingSource.Body;
|
||||||
|
|
||||||
|
public AesBodyAttribute()
|
||||||
|
{
|
||||||
|
// 指定使用自定义的模型绑定器
|
||||||
|
BinderType = typeof(AesBodyModelBinder);
|
||||||
|
Name = KeyProvider.FullName;
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,118 @@
|
|||||||
|
using System;
|
||||||
|
using System.Linq;
|
||||||
|
using Microsoft.AspNetCore.Mvc.Filters;
|
||||||
|
using Microsoft.Extensions.Caching.Distributed;
|
||||||
|
using Microsoft.Extensions.DependencyInjection;
|
||||||
|
using SimApi.Exceptions;
|
||||||
|
using SimApi.Helpers;
|
||||||
|
using SimApi.ModelBinders;
|
||||||
|
|
||||||
|
namespace SimApi.Attributes;
|
||||||
|
|
||||||
|
[AttributeUsage(AttributeTargets.Class | AttributeTargets.Method)]
|
||||||
|
public class SimApiSignAttribute : ActionFilterAttribute
|
||||||
|
{
|
||||||
|
public Type KeyProvider { get; set; } = typeof(SimApiSignProviderBase);
|
||||||
|
|
||||||
|
public override void OnActionExecuting(ActionExecutingContext context)
|
||||||
|
{
|
||||||
|
if (context.HttpContext.RequestServices.GetService(KeyProvider) is not SimApiSignProviderBase keyProvider)
|
||||||
|
{
|
||||||
|
throw new SimApiException(400, "未配置签名器");
|
||||||
|
}
|
||||||
|
|
||||||
|
string? appId = null;
|
||||||
|
if (!string.IsNullOrEmpty(keyProvider.AppIdName))
|
||||||
|
{
|
||||||
|
appId = context.HttpContext.Request.Query[keyProvider.AppIdName]
|
||||||
|
.FirstOrDefault() ?? context.HttpContext.Request.Headers[keyProvider.AppIdName]
|
||||||
|
.FirstOrDefault();
|
||||||
|
|
||||||
|
if (string.IsNullOrEmpty(appId))
|
||||||
|
{
|
||||||
|
throw new SimApiException(400, $"获取{keyProvider.AppIdName}失败");
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// 4. 通过接口获取密钥(解耦的核心:不再直接依赖数据库)
|
||||||
|
var key = keyProvider.GetKey(appId);
|
||||||
|
if (string.IsNullOrEmpty(key))
|
||||||
|
{
|
||||||
|
throw new SimApiException(400, "获取签名KEY失败");
|
||||||
|
}
|
||||||
|
|
||||||
|
var timestamp = context.HttpContext.Request.Query[keyProvider.TimestampName]
|
||||||
|
.FirstOrDefault() ?? context.HttpContext.Request.Headers[keyProvider.TimestampName]
|
||||||
|
.FirstOrDefault();
|
||||||
|
if (string.IsNullOrEmpty(timestamp))
|
||||||
|
{
|
||||||
|
throw new SimApiException(400, $"{keyProvider.TimestampName}不能为空");
|
||||||
|
}
|
||||||
|
|
||||||
|
var nonce = context.HttpContext.Request.Query[keyProvider.NonceName]
|
||||||
|
.FirstOrDefault() ?? context.HttpContext.Request.Headers[keyProvider.NonceName]
|
||||||
|
.FirstOrDefault();
|
||||||
|
if (string.IsNullOrEmpty(nonce))
|
||||||
|
{
|
||||||
|
throw new SimApiException(400, $"{keyProvider.NonceName}不能为空");
|
||||||
|
}
|
||||||
|
|
||||||
|
if (!int.TryParse(timestamp, out var ts))
|
||||||
|
{
|
||||||
|
throw new SimApiException(400, $"{keyProvider.TimestampName}格式错误");
|
||||||
|
}
|
||||||
|
|
||||||
|
if (keyProvider.QueryExpires != 0)
|
||||||
|
{
|
||||||
|
if (ts > SimApiUtil.TimestampNow + 2)
|
||||||
|
{
|
||||||
|
throw new SimApiException(400, "请校准本地时间");
|
||||||
|
}
|
||||||
|
|
||||||
|
if (ts + keyProvider.QueryExpires < SimApiUtil.TimestampNow)
|
||||||
|
{
|
||||||
|
throw new SimApiException(400, "请求已过期");
|
||||||
|
}
|
||||||
|
|
||||||
|
if (keyProvider.DuplicateRequestProtection)
|
||||||
|
{
|
||||||
|
var cache = context.HttpContext.RequestServices.GetRequiredService<IDistributedCache>();
|
||||||
|
if (cache.GetString("SignQuery:" + nonce) == null)
|
||||||
|
{
|
||||||
|
cache.SetString("SignQuery:" + nonce, timestamp, new DistributedCacheEntryOptions()
|
||||||
|
{
|
||||||
|
SlidingExpiration = TimeSpan.FromSeconds(keyProvider.QueryExpires + 2)
|
||||||
|
});
|
||||||
|
}
|
||||||
|
else
|
||||||
|
{
|
||||||
|
throw new SimApiException(400, "重复请求");
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
var signStr = string.Empty;
|
||||||
|
foreach (var item in keyProvider.SignFields)
|
||||||
|
{
|
||||||
|
signStr += $"{item}=";
|
||||||
|
signStr += context.HttpContext.Request.Query[item]
|
||||||
|
.FirstOrDefault() ?? context.HttpContext.Request.Headers[item]
|
||||||
|
.FirstOrDefault();
|
||||||
|
signStr += "&";
|
||||||
|
}
|
||||||
|
|
||||||
|
if (!string.IsNullOrEmpty(keyProvider.AppIdName))
|
||||||
|
{
|
||||||
|
signStr += $"{keyProvider.AppIdName}={appId}&";
|
||||||
|
}
|
||||||
|
|
||||||
|
signStr += $"{keyProvider.TimestampName}={ts}&{keyProvider.NonceName}={nonce}&{key}";
|
||||||
|
var sign = context.HttpContext.Request.Query[keyProvider.SignName]
|
||||||
|
.FirstOrDefault() ?? context.HttpContext.Request.Headers[keyProvider.SignName]
|
||||||
|
.FirstOrDefault();
|
||||||
|
if (SimApiUtil.Md5(signStr) != sign)
|
||||||
|
{
|
||||||
|
throw new SimApiException(400, "签名错误");
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -7,7 +7,7 @@ namespace SimApi.Communications;
|
|||||||
/// </summary>
|
/// </summary>
|
||||||
public class SimApiLoginItem
|
public class SimApiLoginItem
|
||||||
{
|
{
|
||||||
public string Id { get; set; } = null!;
|
public required string Id { get; set; }
|
||||||
public string[] Type { get; set; } = ["user"];
|
public string[] Type { get; set; } = ["user"];
|
||||||
public Dictionary<string, string> Meta { get; set; } = [];
|
public Dictionary<string, string> Meta { get; set; } = [];
|
||||||
public object? Extra { get; set; }
|
public object? Extra { get; set; }
|
||||||
|
|||||||
@@ -4,13 +4,30 @@ public class SimApiJobOptions
|
|||||||
{
|
{
|
||||||
/// <summary>
|
/// <summary>
|
||||||
/// WebUi地址,设置为null表示不启用
|
/// WebUi地址,设置为null表示不启用
|
||||||
|
/// 默认 /jobs
|
||||||
/// </summary>
|
/// </summary>
|
||||||
public string? DashboardUrl { get; set; } = "/jobs";
|
public string? DashboardUrl { get; set; } = "/jobs";
|
||||||
|
|
||||||
|
/// <summary>
|
||||||
|
/// webui 用户
|
||||||
|
/// 默认 admin
|
||||||
|
/// </summary>
|
||||||
public string DashboardAuthUser { get; set; } = "admin";
|
public string DashboardAuthUser { get; set; } = "admin";
|
||||||
|
|
||||||
|
/// <summary>
|
||||||
|
/// webui 密码
|
||||||
|
/// 默认 Admin@123!
|
||||||
|
/// </summary>
|
||||||
public string DashboardAuthPass { get; set; } = "Admin@123!";
|
public string DashboardAuthPass { get; set; } = "Admin@123!";
|
||||||
|
|
||||||
|
/// <summary>
|
||||||
|
/// 设置为null 使用默认redis配置
|
||||||
|
/// </summary>
|
||||||
public string? RedisConfiguration { get; set; }
|
public string? RedisConfiguration { get; set; }
|
||||||
|
|
||||||
|
/// <summary>
|
||||||
|
/// 设置为null 使用默认redis配置
|
||||||
|
/// </summary>
|
||||||
public int? Database { get; set; } = null;
|
public int? Database { get; set; } = null;
|
||||||
public SimApiJobServerConfig[] Servers { get; set; } = [new()];
|
public SimApiJobServerConfig[] Servers { get; set; } = [new()];
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -0,0 +1,67 @@
|
|||||||
|
using System;
|
||||||
|
using System.Collections.Generic;
|
||||||
|
using System.Linq;
|
||||||
|
using System.Net.Http;
|
||||||
|
using System.Net.Http.Json;
|
||||||
|
using SimApi.Communications;
|
||||||
|
|
||||||
|
namespace SimApi.Helpers;
|
||||||
|
|
||||||
|
public class SimApiHttpClient(string? appId, string appKey)
|
||||||
|
{
|
||||||
|
public string SignName { get; init; } = "sign";
|
||||||
|
public string TimestampName { get; init; } = "timestamp";
|
||||||
|
public string NonceName { get; init; } = "nonce";
|
||||||
|
public string? AppIdName { get; init; } = "appId";
|
||||||
|
public string[] SignFields { get; init; } = [];
|
||||||
|
|
||||||
|
|
||||||
|
public T? SignQuery<T>(string url, object body, Dictionary<string, string>? queries = null)
|
||||||
|
{
|
||||||
|
var queryUrl = SignFields.Aggregate(string.Empty,
|
||||||
|
(current, signField) => current + $"{signField}={queries?[signField]}&");
|
||||||
|
if (!string.IsNullOrEmpty(AppIdName))
|
||||||
|
{
|
||||||
|
queryUrl += $"{AppIdName}={appId}&";
|
||||||
|
}
|
||||||
|
|
||||||
|
queryUrl += $"{TimestampName}={(int)SimApiUtil.TimestampNow}&{NonceName}={Guid.NewGuid()}";
|
||||||
|
var signStr = $"{queryUrl}&{appKey}";
|
||||||
|
var path = $"{url}?{queryUrl}&{SignName}={SimApiUtil.Md5(signStr)}";
|
||||||
|
|
||||||
|
if (queries != null)
|
||||||
|
{
|
||||||
|
path = queries.Where(q => !SignFields.Contains(q.Key))
|
||||||
|
.Aggregate(path, (current, q) => current + $"&{q.Key}={q.Value}");
|
||||||
|
}
|
||||||
|
|
||||||
|
var http = new HttpClient();
|
||||||
|
var resp = http.PostAsJsonAsync(path, body).Result;
|
||||||
|
return resp.Content.ReadFromJsonAsync<T>().Result;
|
||||||
|
}
|
||||||
|
|
||||||
|
public T? AesQuery<T>(string url, object body)
|
||||||
|
{
|
||||||
|
if (!string.IsNullOrEmpty(AppIdName))
|
||||||
|
{
|
||||||
|
url += $"?{AppIdName}={appId}";
|
||||||
|
}
|
||||||
|
|
||||||
|
var req = new SimApiOneFieldRequest<string>
|
||||||
|
{
|
||||||
|
Data = SimApiAesUtil.Encrypt(SimApiUtil.Json(body), appKey)
|
||||||
|
};
|
||||||
|
var http = new HttpClient();
|
||||||
|
var resp = http.PostAsJsonAsync(url, req).Result;
|
||||||
|
return resp.Content.ReadFromJsonAsync<T>().Result;
|
||||||
|
}
|
||||||
|
|
||||||
|
public T? AesSignQuery<T>(string url, object body, Dictionary<string, string>? queries = null)
|
||||||
|
{
|
||||||
|
var req = new SimApiOneFieldRequest<string>
|
||||||
|
{
|
||||||
|
Data = SimApiAesUtil.Encrypt(SimApiUtil.Json(body), appKey)
|
||||||
|
};
|
||||||
|
return SignQuery<T>(url, req, queries);
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -11,7 +11,7 @@ public class SimApiJobWebAuth(string user, string pass) : IDashboardAuthorizatio
|
|||||||
public bool Authorize(DashboardContext context)
|
public bool Authorize(DashboardContext context)
|
||||||
{
|
{
|
||||||
var httpContext = context.GetHttpContext();
|
var httpContext = context.GetHttpContext();
|
||||||
var authHeader = httpContext.Request.Headers["Authorization"].FirstOrDefault();
|
var authHeader = httpContext.Request.Headers.Authorization.FirstOrDefault();
|
||||||
if (authHeader != null && authHeader.StartsWith("Basic "))
|
if (authHeader != null && authHeader.StartsWith("Basic "))
|
||||||
{
|
{
|
||||||
var encodedUsernamePassword = authHeader.Split(' ', 2, StringSplitOptions.RemoveEmptyEntries)[1].Trim();
|
var encodedUsernamePassword = authHeader.Split(' ', 2, StringSplitOptions.RemoveEmptyEntries)[1].Trim();
|
||||||
|
|||||||
@@ -24,16 +24,19 @@ public class SimApiExceptionMiddleware(RequestDelegate next, ILogger<SimApiExcep
|
|||||||
try
|
try
|
||||||
{
|
{
|
||||||
await next(context);
|
await next(context);
|
||||||
switch (context.Response.StatusCode)
|
if (!context.Response.HasStarted)
|
||||||
{
|
{
|
||||||
case 200:
|
switch (context.Response.StatusCode)
|
||||||
case 301:
|
{
|
||||||
case 302:
|
case 200:
|
||||||
break;
|
case 301:
|
||||||
case 404:
|
case 302:
|
||||||
throw new SimApiException(context.Response.StatusCode, "请求的接口不存在");
|
break;
|
||||||
default:
|
case 404:
|
||||||
throw new SimApiException(context.Response.StatusCode);
|
throw new SimApiException(context.Response.StatusCode, "请求的接口不存在");
|
||||||
|
default:
|
||||||
|
throw new SimApiException(context.Response.StatusCode);
|
||||||
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
catch (SimApiException ex)
|
catch (SimApiException ex)
|
||||||
|
|||||||
@@ -0,0 +1,106 @@
|
|||||||
|
using System;
|
||||||
|
using System.IO;
|
||||||
|
using System.Linq;
|
||||||
|
using System.Text.Json;
|
||||||
|
using System.Threading.Tasks;
|
||||||
|
using Microsoft.AspNetCore.Http;
|
||||||
|
using Microsoft.AspNetCore.Mvc.ModelBinding;
|
||||||
|
using SimApi.Communications;
|
||||||
|
using SimApi.Helpers;
|
||||||
|
|
||||||
|
namespace SimApi.ModelBinders;
|
||||||
|
|
||||||
|
public class AesBodyModelBinder : IModelBinder
|
||||||
|
{
|
||||||
|
public async Task BindModelAsync(ModelBindingContext bindingContext)
|
||||||
|
{
|
||||||
|
var request = bindingContext.HttpContext.Request;
|
||||||
|
request.EnableBuffering();
|
||||||
|
using var reader = new StreamReader(request.Body, leaveOpen: true);
|
||||||
|
var requestBody = await reader.ReadToEndAsync();
|
||||||
|
request.Body.Position = 0;
|
||||||
|
|
||||||
|
if (string.IsNullOrEmpty(requestBody))
|
||||||
|
{
|
||||||
|
bindingContext.ModelState.AddModelError("", "请求体不能为空");
|
||||||
|
bindingContext.Result = ModelBindingResult.Failed();
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
|
SimApiOneFieldRequest<string>? aesRequest;
|
||||||
|
try
|
||||||
|
{
|
||||||
|
aesRequest = JsonSerializer.Deserialize<SimApiOneFieldRequest<string>>(requestBody, SimApiUtil.JsonOption);
|
||||||
|
}
|
||||||
|
catch (JsonException ex)
|
||||||
|
{
|
||||||
|
bindingContext.ModelState.AddModelError("", $"请求体格式错误:{ex.Message}");
|
||||||
|
bindingContext.Result = ModelBindingResult.Failed();
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
|
if (aesRequest == null || string.IsNullOrEmpty(aesRequest.Data))
|
||||||
|
{
|
||||||
|
bindingContext.ModelState.AddModelError("", "请求体缺少密文Data字段");
|
||||||
|
bindingContext.Result = ModelBindingResult.Failed();
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
|
// 3. 根据配置获取appId(参考上一节代码)
|
||||||
|
var keyProvider =
|
||||||
|
bindingContext.HttpContext.RequestServices.GetService(Type.GetType(bindingContext.BinderModelName!)!) as
|
||||||
|
AesBodyProviderBase;
|
||||||
|
string? appId = null;
|
||||||
|
if (!string.IsNullOrEmpty(keyProvider!.AppIdName))
|
||||||
|
{
|
||||||
|
appId = bindingContext.HttpContext.Request.Query[keyProvider.AppIdName]
|
||||||
|
.FirstOrDefault() ?? bindingContext.HttpContext.Request.Headers[keyProvider.AppIdName]
|
||||||
|
.FirstOrDefault();
|
||||||
|
|
||||||
|
if (string.IsNullOrEmpty(appId))
|
||||||
|
{
|
||||||
|
bindingContext.ModelState.AddModelError("",
|
||||||
|
$"未找到{keyProvider.AppIdName}");
|
||||||
|
bindingContext.Result = ModelBindingResult.Failed();
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// 4. 通过接口获取密钥(解耦的核心:不再直接依赖数据库)
|
||||||
|
var key = keyProvider.GetKey(appId);
|
||||||
|
if (string.IsNullOrEmpty(key))
|
||||||
|
{
|
||||||
|
bindingContext.ModelState.AddModelError("", "获取密钥失败(应用不存在或密钥未配置)");
|
||||||
|
bindingContext.Result = ModelBindingResult.Failed();
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
|
// 5. 解密和反序列化(保持原有逻辑)
|
||||||
|
try
|
||||||
|
{
|
||||||
|
var jsonStr = SimApiAesUtil.Decrypt(aesRequest.Data, key);
|
||||||
|
if (string.IsNullOrEmpty(jsonStr))
|
||||||
|
{
|
||||||
|
bindingContext.ModelState.AddModelError("", "解密失败");
|
||||||
|
bindingContext.Result = ModelBindingResult.Failed();
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
|
var targetType = bindingContext.ModelType;
|
||||||
|
var deserializedModel = JsonSerializer.Deserialize(jsonStr, targetType, SimApiUtil.JsonOption);
|
||||||
|
if (deserializedModel == null)
|
||||||
|
{
|
||||||
|
bindingContext.ModelState.AddModelError("", "反序列化失败");
|
||||||
|
bindingContext.Result = ModelBindingResult.Failed();
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
|
bindingContext.Result = ModelBindingResult.Success(deserializedModel);
|
||||||
|
}
|
||||||
|
catch (Exception ex)
|
||||||
|
{
|
||||||
|
bindingContext.ModelState.AddModelError("", $"处理异常:{ex.Message}");
|
||||||
|
bindingContext.Result = ModelBindingResult.Failed();
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,19 @@
|
|||||||
|
using SimApi.Exceptions;
|
||||||
|
|
||||||
|
namespace SimApi.ModelBinders;
|
||||||
|
|
||||||
|
/// <summary>
|
||||||
|
/// 密钥提供器接口(抽象密钥获取逻辑)
|
||||||
|
/// </summary>
|
||||||
|
public abstract class AesBodyProviderBase
|
||||||
|
{
|
||||||
|
public virtual string? AppIdName { get; set; } = "appId";
|
||||||
|
|
||||||
|
|
||||||
|
/// <summary>
|
||||||
|
/// 根据appId获取对应的密钥
|
||||||
|
/// </summary>
|
||||||
|
/// <param name="appId">应用ID</param>
|
||||||
|
/// <returns>密钥(返回null表示获取失败)</returns>
|
||||||
|
public abstract string? GetKey(string? appId);
|
||||||
|
}
|
||||||
@@ -0,0 +1,45 @@
|
|||||||
|
using SimApi.Exceptions;
|
||||||
|
|
||||||
|
namespace SimApi.ModelBinders;
|
||||||
|
|
||||||
|
public abstract class SimApiSignProviderBase
|
||||||
|
{
|
||||||
|
/// <summary>
|
||||||
|
/// appId字段的名称
|
||||||
|
/// </summary>
|
||||||
|
public virtual string? AppIdName { get; set; } = "appId";
|
||||||
|
|
||||||
|
/// <summary>
|
||||||
|
/// 时间戳的字段名
|
||||||
|
/// </summary>
|
||||||
|
public virtual string TimestampName { get; set; } = "timestamp";
|
||||||
|
|
||||||
|
/// <summary>
|
||||||
|
/// 随机字符串的字段名
|
||||||
|
/// </summary>
|
||||||
|
public virtual string NonceName { get; set; } = "nonce";
|
||||||
|
|
||||||
|
/// <summary>
|
||||||
|
/// 签名的字段名
|
||||||
|
/// </summary>
|
||||||
|
public virtual string SignName { get; set; } = "sign";
|
||||||
|
|
||||||
|
/// <summary>
|
||||||
|
/// 请求过期时间, 如果为0, 不校验timestamp
|
||||||
|
/// </summary>
|
||||||
|
public virtual int QueryExpires { get; set; } = 5;
|
||||||
|
|
||||||
|
/// <summary>
|
||||||
|
/// 如果开启,必须配置redis, 每次请求将会缓存nonce
|
||||||
|
/// </summary>
|
||||||
|
public virtual bool DuplicateRequestProtection { get; set; } = true;
|
||||||
|
|
||||||
|
public virtual string[] SignFields { get; set; } = [];
|
||||||
|
|
||||||
|
/// <summary>
|
||||||
|
/// 根据appId获取对应的密钥
|
||||||
|
/// </summary>
|
||||||
|
/// <param name="appId">应用ID</param>
|
||||||
|
/// <returns>密钥(返回null表示获取失败)</returns>
|
||||||
|
public abstract string? GetKey(string? appId);
|
||||||
|
}
|
||||||
+2
-2
@@ -17,11 +17,11 @@
|
|||||||
<Folder Include="Exceptions\"/>
|
<Folder Include="Exceptions\"/>
|
||||||
</ItemGroup>
|
</ItemGroup>
|
||||||
<ItemGroup>
|
<ItemGroup>
|
||||||
<PackageReference Include="Hangfire.AspNetCore" Version="1.8.21" />
|
<PackageReference Include="Hangfire.AspNetCore" Version="1.8.22" />
|
||||||
<PackageReference Include="Hangfire.Console" Version="1.4.3"/>
|
<PackageReference Include="Hangfire.Console" Version="1.4.3"/>
|
||||||
<PackageReference Include="Hangfire.Redis.StackExchange" Version="1.12.0"/>
|
<PackageReference Include="Hangfire.Redis.StackExchange" Version="1.12.0"/>
|
||||||
<PackageReference Include="Microsoft.Extensions.Caching.StackExchangeRedis" Version="9.0.10" />
|
<PackageReference Include="Microsoft.Extensions.Caching.StackExchangeRedis" Version="9.0.10" />
|
||||||
<PackageReference Include="Minio" Version="6.0.5" />
|
<PackageReference Include="Minio" Version="7.0.0" />
|
||||||
<PackageReference Include="MQTTnet" Version="5.0.1.1416"/>
|
<PackageReference Include="MQTTnet" Version="5.0.1.1416"/>
|
||||||
<PackageReference Include="Swashbuckle.AspNetCore.Annotations" Version="9.0.6" />
|
<PackageReference Include="Swashbuckle.AspNetCore.Annotations" Version="9.0.6" />
|
||||||
<PackageReference Include="Swashbuckle.AspNetCore.SwaggerUI" Version="9.0.6" />
|
<PackageReference Include="Swashbuckle.AspNetCore.SwaggerUI" Version="9.0.6" />
|
||||||
|
|||||||
+5
-2
@@ -19,6 +19,7 @@ using SimApi.Attributes;
|
|||||||
using SimApi.CoceSdk;
|
using SimApi.CoceSdk;
|
||||||
using SimApi.Configurations;
|
using SimApi.Configurations;
|
||||||
using SimApi.Logger;
|
using SimApi.Logger;
|
||||||
|
using SimApi.SwaggerFilters;
|
||||||
|
|
||||||
namespace SimApi;
|
namespace SimApi;
|
||||||
|
|
||||||
@@ -123,7 +124,10 @@ public static class SimApiExtensions
|
|||||||
}
|
}
|
||||||
|
|
||||||
x.CustomSchemaIds(type => type.FullName?.Replace("+", "."));
|
x.CustomSchemaIds(type => type.FullName?.Replace("+", "."));
|
||||||
x.OperationFilter<SimApiResponseSchemaFilter>();
|
x.OperationFilter<SimApiResponseOperationFilter>();
|
||||||
|
x.OperationFilter<SimApiSignOperationFilter>();
|
||||||
|
x.OperationFilter<AesBodyOperationFilter>();
|
||||||
|
x.SchemaFilter<GlobalDynamicObjectSchemaFilter>();
|
||||||
if (simApiOptions.EnableSimApiAuth)
|
if (simApiOptions.EnableSimApiAuth)
|
||||||
{
|
{
|
||||||
x.OperationFilter<SimApiAuthOperationFilter>();
|
x.OperationFilter<SimApiAuthOperationFilter>();
|
||||||
@@ -236,7 +240,6 @@ public static class SimApiExtensions
|
|||||||
if (simApiOptions.EnableSimApiResponseFilter)
|
if (simApiOptions.EnableSimApiResponseFilter)
|
||||||
{
|
{
|
||||||
builder.AddControllers(opt => opt.Filters.Add<SimApiResponseFilter>())
|
builder.AddControllers(opt => opt.Filters.Add<SimApiResponseFilter>())
|
||||||
.AddXmlSerializerFormatters()
|
|
||||||
.AddJsonOptions(opt =>
|
.AddJsonOptions(opt =>
|
||||||
{
|
{
|
||||||
opt.JsonSerializerOptions.PropertyNamingPolicy = JsonNamingPolicy.CamelCase;
|
opt.JsonSerializerOptions.PropertyNamingPolicy = JsonNamingPolicy.CamelCase;
|
||||||
|
|||||||
@@ -0,0 +1,52 @@
|
|||||||
|
using System.Collections.Generic;
|
||||||
|
using System.Linq;
|
||||||
|
using SimApi.Attributes;
|
||||||
|
|
||||||
|
namespace SimApi.SwaggerFilters;
|
||||||
|
|
||||||
|
using Microsoft.OpenApi.Models;
|
||||||
|
using Swashbuckle.AspNetCore.SwaggerGen;
|
||||||
|
using System.Reflection;
|
||||||
|
|
||||||
|
/// <summary>
|
||||||
|
/// 自定义 Swagger 过滤器:将标注 [AesBody] 的参数显示在 Request Body 中
|
||||||
|
/// </summary>
|
||||||
|
public class AesBodyOperationFilter : IOperationFilter
|
||||||
|
{
|
||||||
|
public void Apply(OpenApiOperation operation, OperationFilterContext context)
|
||||||
|
{
|
||||||
|
foreach (var parameter in context.ApiDescription.ParameterDescriptions)
|
||||||
|
{
|
||||||
|
var hasAesBodyAttr = parameter.ParameterInfo()
|
||||||
|
.GetCustomAttribute<AesBodyAttribute>() != null;
|
||||||
|
if (!hasAesBodyAttr) continue;
|
||||||
|
// 1. 移除默认的 Query 参数描述(如果存在)
|
||||||
|
var queryParam = operation.Parameters
|
||||||
|
.FirstOrDefault(p => p.Name == parameter.Name);
|
||||||
|
if (queryParam != null)
|
||||||
|
{
|
||||||
|
operation.Parameters.Remove(queryParam);
|
||||||
|
}
|
||||||
|
|
||||||
|
// 2. 添加 Body 参数描述
|
||||||
|
// 获取参数类型的 Schema(Swagger 模型定义)
|
||||||
|
var schema = context.SchemaGenerator.GenerateSchema(
|
||||||
|
parameter.Type,
|
||||||
|
context.SchemaRepository);
|
||||||
|
|
||||||
|
// 将参数添加到 Request Body
|
||||||
|
operation.RequestBody = new OpenApiRequestBody
|
||||||
|
{
|
||||||
|
Content = new Dictionary<string, OpenApiMediaType>
|
||||||
|
{
|
||||||
|
{
|
||||||
|
"application/json", // 假设使用 JSON 格式
|
||||||
|
new OpenApiMediaType { Schema = schema }
|
||||||
|
}
|
||||||
|
},
|
||||||
|
Description = "内容为加密前内容,需要转换为JSON后使用AES加密后提交,提交格式为 {\"data\":\"AES密文\"}",
|
||||||
|
Required = true // 标记为必填
|
||||||
|
};
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,62 @@
|
|||||||
|
using System;
|
||||||
|
using Microsoft.OpenApi.Models;
|
||||||
|
using Swashbuckle.AspNetCore.SwaggerGen;
|
||||||
|
using System.Collections;
|
||||||
|
using System.Collections.Generic;
|
||||||
|
using System.Reflection;
|
||||||
|
using Microsoft.OpenApi.Any;
|
||||||
|
|
||||||
|
namespace SimApi.SwaggerFilters;
|
||||||
|
|
||||||
|
public class GlobalDynamicObjectSchemaFilter : ISchemaFilter
|
||||||
|
{
|
||||||
|
public void Apply(OpenApiSchema schema, SchemaFilterContext context)
|
||||||
|
{
|
||||||
|
if (!IsDynamicObjectType(context.Type)) return;
|
||||||
|
schema.AdditionalPropertiesAllowed = true;
|
||||||
|
schema.AdditionalProperties = new OpenApiSchema
|
||||||
|
{
|
||||||
|
Type = "object", // 表示 value 可以是任意类型(兼容所有类型)
|
||||||
|
Nullable = true
|
||||||
|
};
|
||||||
|
|
||||||
|
// 2. 覆盖默认示例,使用包含多种类型的示例
|
||||||
|
schema.Example = CreateMultiTypeExample();
|
||||||
|
}
|
||||||
|
|
||||||
|
// 判断是否为需要处理的“动态对象”类型
|
||||||
|
private bool IsDynamicObjectType(Type? type)
|
||||||
|
{
|
||||||
|
if (type == null) return false;
|
||||||
|
if (typeof(IDictionary).IsAssignableFrom(type) ||
|
||||||
|
(type.IsGenericType && type.GetGenericTypeDefinition() == typeof(Dictionary<,>)))
|
||||||
|
{
|
||||||
|
return true;
|
||||||
|
}
|
||||||
|
if (type == typeof(object))
|
||||||
|
{
|
||||||
|
return true;
|
||||||
|
}
|
||||||
|
return type.Name.Contains("AnonymousType") && type.Namespace == null;
|
||||||
|
}
|
||||||
|
|
||||||
|
// 创建包含多种类型的示例(覆盖默认的 string 示例)
|
||||||
|
private OpenApiObject CreateMultiTypeExample()
|
||||||
|
{
|
||||||
|
return new OpenApiObject
|
||||||
|
{
|
||||||
|
["stringProp"] = new OpenApiString("example string"), // 字符串
|
||||||
|
["numberProp"] = new OpenApiInteger(123), // 数字
|
||||||
|
["boolProp"] = new OpenApiBoolean(true), // 布尔值
|
||||||
|
["objectProp"] = new OpenApiObject // 嵌套对象
|
||||||
|
{
|
||||||
|
["nestedKey"] = new OpenApiString("nested value")
|
||||||
|
},
|
||||||
|
["arrayProp"] = new OpenApiArray // 数组
|
||||||
|
{
|
||||||
|
new OpenApiInteger(1),
|
||||||
|
new OpenApiString("two")
|
||||||
|
}
|
||||||
|
};
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -1,4 +1,3 @@
|
|||||||
using System;
|
|
||||||
using System.Collections.Generic;
|
using System.Collections.Generic;
|
||||||
using System.Linq;
|
using System.Linq;
|
||||||
using System.Reflection;
|
using System.Reflection;
|
||||||
@@ -6,7 +5,7 @@ using Microsoft.OpenApi.Models;
|
|||||||
using Swashbuckle.AspNetCore.SwaggerGen;
|
using Swashbuckle.AspNetCore.SwaggerGen;
|
||||||
using SimApi.Attributes;
|
using SimApi.Attributes;
|
||||||
|
|
||||||
namespace SimApi.Helpers
|
namespace SimApi.SwaggerFilters
|
||||||
{
|
{
|
||||||
public class SimApiAuthOperationFilter : IOperationFilter
|
public class SimApiAuthOperationFilter : IOperationFilter
|
||||||
{
|
{
|
||||||
+2
-2
@@ -9,9 +9,9 @@ using Microsoft.AspNetCore.Mvc;
|
|||||||
using SimApi.Attributes;
|
using SimApi.Attributes;
|
||||||
using SimApi.Communications;
|
using SimApi.Communications;
|
||||||
|
|
||||||
namespace SimApi.Helpers;
|
namespace SimApi.SwaggerFilters;
|
||||||
|
|
||||||
public class SimApiResponseSchemaFilter : IOperationFilter
|
public class SimApiResponseOperationFilter : IOperationFilter
|
||||||
{
|
{
|
||||||
public void Apply(OpenApiOperation operation, OperationFilterContext context)
|
public void Apply(OpenApiOperation operation, OperationFilterContext context)
|
||||||
{
|
{
|
||||||
@@ -0,0 +1,97 @@
|
|||||||
|
using System;
|
||||||
|
using System.Collections.Generic;
|
||||||
|
using System.Linq;
|
||||||
|
using System.Reflection;
|
||||||
|
using Microsoft.Extensions.DependencyInjection;
|
||||||
|
using Microsoft.OpenApi.Models;
|
||||||
|
using SimApi.Attributes;
|
||||||
|
using SimApi.ModelBinders;
|
||||||
|
using Swashbuckle.AspNetCore.SwaggerGen;
|
||||||
|
|
||||||
|
namespace SimApi.SwaggerFilters;
|
||||||
|
|
||||||
|
public class SimApiSignOperationFilter(IServiceProvider serviceProvider) : IOperationFilter
|
||||||
|
{
|
||||||
|
public void Apply(OpenApiOperation operation, OperationFilterContext context)
|
||||||
|
{
|
||||||
|
// 1. 检查当前方法或类是否标注了 SimApiSignAttribute 及其子类
|
||||||
|
var signAttribute = context.MethodInfo.GetCustomAttribute<SimApiSignAttribute>(inherit: true)
|
||||||
|
?? context.MethodInfo.DeclaringType?.GetCustomAttribute<SimApiSignAttribute>(inherit: true);
|
||||||
|
|
||||||
|
if (signAttribute == null)
|
||||||
|
{
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
|
var keyProviderType = signAttribute.KeyProvider;
|
||||||
|
if (!typeof(SimApiSignProviderBase).IsAssignableFrom(keyProviderType))
|
||||||
|
{
|
||||||
|
throw new InvalidOperationException($"KeyProvider 必须继承自 {nameof(SimApiSignProviderBase)}");
|
||||||
|
}
|
||||||
|
|
||||||
|
SimApiSignProviderBase? keyProvider;
|
||||||
|
try
|
||||||
|
{
|
||||||
|
keyProvider =
|
||||||
|
serviceProvider.CreateScope().ServiceProvider.GetService(keyProviderType) as SimApiSignProviderBase;
|
||||||
|
}
|
||||||
|
catch (Exception ex)
|
||||||
|
{
|
||||||
|
throw new InvalidOperationException($"无法从 DI 容器获取 {keyProviderType.Name} 实例:{ex.Message}");
|
||||||
|
}
|
||||||
|
|
||||||
|
if (keyProvider == null)
|
||||||
|
{
|
||||||
|
throw new InvalidOperationException($"{keyProviderType.Name} 未在 DI 容器中注册");
|
||||||
|
}
|
||||||
|
|
||||||
|
var signStr = keyProvider.SignFields.Aggregate(string.Empty, (current, field) => current + $"{field}=xxx&");
|
||||||
|
if (!string.IsNullOrEmpty(keyProvider.AppIdName))
|
||||||
|
{
|
||||||
|
signStr += $"{keyProvider.AppIdName}=xxx&";
|
||||||
|
}
|
||||||
|
|
||||||
|
signStr += $"{keyProvider.TimestampName}=xxx&{keyProvider.NonceName}=xxx&签名密钥";
|
||||||
|
|
||||||
|
var signParameters = new List<(string Name, string Description, bool Required)>
|
||||||
|
{
|
||||||
|
(keyProvider.TimestampName, "时间戳(秒级)", true),
|
||||||
|
(keyProvider.NonceName, "随机字符串", true),
|
||||||
|
(keyProvider.SignName, $"MD5签名结果,签名MD5字符串: {signStr}", true)
|
||||||
|
};
|
||||||
|
if (keyProvider.AppIdName != null)
|
||||||
|
{
|
||||||
|
signParameters.Add((keyProvider.AppIdName, "应用标识", true));
|
||||||
|
}
|
||||||
|
|
||||||
|
signParameters.AddRange(keyProvider.SignFields.Where(x => x != keyProvider.AppIdName)
|
||||||
|
.Select(f => (f, string.Empty, true)));
|
||||||
|
|
||||||
|
foreach (var (name, description, required) in signParameters)
|
||||||
|
{
|
||||||
|
if (operation.Parameters?.Any(p => p.Name == name) == true)
|
||||||
|
{
|
||||||
|
var tmp = operation.Parameters?.FirstOrDefault(p => p.Name == name);
|
||||||
|
if (tmp != null)
|
||||||
|
{
|
||||||
|
tmp.Required = required;
|
||||||
|
tmp.Description = description;
|
||||||
|
}
|
||||||
|
continue;
|
||||||
|
}
|
||||||
|
|
||||||
|
operation.Parameters ??= new List<OpenApiParameter>();
|
||||||
|
operation.Parameters.Add(new OpenApiParameter
|
||||||
|
{
|
||||||
|
Name = name,
|
||||||
|
In = ParameterLocation.Query, // 指定为 Query 参数
|
||||||
|
Description = description,
|
||||||
|
Required = required,
|
||||||
|
Schema = new OpenApiSchema
|
||||||
|
{
|
||||||
|
Type = "string" // 签名相关参数通常为字符串类型
|
||||||
|
}
|
||||||
|
});
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
Reference in New Issue
Block a user