yavsc/src/Yavsc.Org/Controllers/Administration/ClientController.cs

297 lines
10 KiB
C#
Raw Normal View History

2025-08-24 16:07:53 +01:00
using IdentityServer8.EntityFramework.DbContexts;
using IdentityServer8.EntityFramework.Entities;
2026-03-09 02:07:09 +00:00
using IdentityServer8.EntityFramework.Stores;
2025-08-24 16:07:53 +01:00
using Microsoft.AspNetCore.Authorization;
2023-03-19 17:57:55 +00:00
using Microsoft.AspNetCore.Mvc;
using Microsoft.AspNetCore.Mvc.Rendering;
using Microsoft.EntityFrameworkCore;
2026-03-16 23:16:12 +00:00
using Microsoft.Extensions.Options;
2018-05-04 13:56:22 +02:00
using Yavsc.Models;
using Yavsc.Models.Auth;
2026-03-16 23:16:12 +00:00
using Yavsc.Server.Helpers;
2018-05-04 13:56:22 +02:00
namespace Yavsc.Controllers
{
2025-08-24 16:07:53 +01:00
[Authorize("AdministratorOnly")]
2018-05-04 13:56:22 +02:00
public class ClientController : Controller
{
2026-03-16 23:16:12 +00:00
private readonly ApplicationDbContext dbContext;
2026-03-09 02:07:09 +00:00
private readonly ClientStore clientStore;
2026-03-16 23:16:12 +00:00
private readonly SiteSettings siteSettings;
2018-05-04 13:56:22 +02:00
2026-03-16 23:16:12 +00:00
public ClientController(
ApplicationDbContext dbContext,
ClientStore clientStore, IOptions<SiteSettings> siteSettingsOptions
2026-03-09 02:07:09 +00:00
)
2018-05-04 13:56:22 +02:00
{
2026-03-16 23:16:12 +00:00
this.dbContext = dbContext;
2026-03-09 02:07:09 +00:00
this.clientStore = clientStore;
2026-03-16 23:16:12 +00:00
this.siteSettings = siteSettingsOptions.Value;
2018-05-04 13:56:22 +02:00
}
// GET: Client
public async Task<IActionResult> Index()
{
2026-03-16 23:16:12 +00:00
return View(await dbContext.Clients.Include(c => c.AllowedGrantTypes)
2026-03-09 02:07:09 +00:00
.Include(c => c.RedirectUris).ToListAsync());
2018-05-04 13:56:22 +02:00
}
// GET: Client/Details/5
2026-03-09 02:07:09 +00:00
public async Task<IActionResult> Details(int id)
2018-05-04 13:56:22 +02:00
{
2026-03-16 23:16:12 +00:00
Client client = await dbContext.Clients.Include(
2025-08-24 16:07:53 +01:00
c => c.ClientSecrets
2026-03-09 02:07:09 +00:00
).Include(c => c.AllowedGrantTypes)
.Include(c => c.RedirectUris)
.Include(c=>c.ClientSecrets)
.Include(c=>c.AllowedCorsOrigins)
.Include(c=>c.AllowedScopes)
.Include(c=>c.IdentityProviderRestrictions)
.Include(c=>c.PostLogoutRedirectUris)
.SingleAsync(m => m.Id == id);
2018-05-04 13:56:22 +02:00
if (client == null)
{
2023-03-19 17:57:55 +00:00
return NotFound();
2018-05-04 13:56:22 +02:00
}
return View(client);
}
// GET: Client/Create
public IActionResult Create()
{
SetAppTypesInputValues();
return View();
}
// POST: Client/Create
[HttpPost]
[ValidateAntiForgeryToken]
2026-03-16 23:16:12 +00:00
2018-05-04 13:56:22 +02:00
public async Task<IActionResult> Create(Client client)
{
if (ModelState.IsValid)
{
2026-03-09 02:07:09 +00:00
var model = await clientStore.FindClientByIdAsync(client.ClientId);
if (model != null)
{
ModelState.AddModelError("ClientId", "existent");
return BadRequest(ModelState);
}
2026-03-16 23:16:12 +00:00
dbContext.Clients.Add(client);
await dbContext.SaveChangesAsync(User.GetUserId());
dbContext.ClientRedirectUris.Add(new ClientRedirectUri
2026-03-09 02:07:09 +00:00
{
2026-03-16 23:16:12 +00:00
ClientId = client.Id,
RedirectUri = siteSettings.Audience
});
dbContext.ClientCorsOrigins.Add(new ClientCorsOrigin
{
ClientId = client.Id,
Origin = siteSettings.Audience
});
foreach (String credType in new String[] { "code", "client_credentials", "password" })
{
dbContext.ClientGrantTypes.Add(new ClientGrantType
2026-03-09 02:07:09 +00:00
{
2026-03-16 23:16:12 +00:00
ClientId = client.Id,
GrantType = credType
});
2026-03-09 02:07:09 +00:00
}
2026-03-16 23:16:12 +00:00
foreach (String scope in new String[] { "openid", "profile" })
{
dbContext.ClientScopes.Add(new ClientScope
{
ClientId = client.Id,
Scope = scope
});
}
await dbContext.SaveChangesAsync(User.GetUserId());
2026-03-09 02:07:09 +00:00
2018-05-04 13:56:22 +02:00
return RedirectToAction("Index");
}
SetAppTypesInputValues();
return View(client);
}
2026-03-09 02:07:09 +00:00
2018-05-04 13:56:22 +02:00
private void SetAppTypesInputValues()
{
2025-08-24 16:07:53 +01:00
IEnumerable<SelectListItem> types = new SelectListItem[] {
2018-05-04 13:56:22 +02:00
new SelectListItem {
Text = ApplicationTypes.JavaScript.ToString(),
Value = ((int) ApplicationTypes.JavaScript).ToString() },
new SelectListItem {
Text = ApplicationTypes.NativeConfidential.ToString(),
2025-08-24 16:07:53 +01:00
Value = ((int) ApplicationTypes.NativeConfidential).ToString()
2018-05-04 13:56:22 +02:00
}
};
2026-06-04 12:13:37 +01:00
ViewBag.AccessTokenType = types;
2018-05-04 13:56:22 +02:00
}
// GET: Client/Edit/5
2026-03-09 02:07:09 +00:00
public async Task<IActionResult> Edit(int id)
2018-05-04 13:56:22 +02:00
{
2026-03-16 23:16:12 +00:00
Client client = await dbContext.Clients.SingleOrDefaultAsync(m => m.Id == id);
2018-05-04 13:56:22 +02:00
if (client == null)
{
2023-03-19 17:57:55 +00:00
return NotFound();
2018-05-04 13:56:22 +02:00
}
SetAppTypesInputValues();
return View(client);
}
// POST: Client/Edit/5
[HttpPost]
[ValidateAntiForgeryToken]
public async Task<IActionResult> Edit(Client client)
{
if (ModelState.IsValid)
{
2026-03-09 02:07:09 +00:00
if (client.ClientSecrets != null)
{
foreach (var secret in client.ClientSecrets)
{
2026-03-16 23:16:12 +00:00
dbContext.Update(secret);
2026-03-09 02:07:09 +00:00
}
}
2026-03-16 23:16:12 +00:00
dbContext.Update(client);
await dbContext.SaveChangesAsync();
2018-05-04 13:56:22 +02:00
return RedirectToAction("Index");
}
return View(client);
}
// GET: Client/Delete/5
[ActionName("Delete")]
2026-03-09 02:07:09 +00:00
public async Task<IActionResult> Delete(int id)
2018-05-04 13:56:22 +02:00
{
2026-03-16 23:16:12 +00:00
Client client = await dbContext.Clients.SingleOrDefaultAsync(m => m.Id == id);
2018-05-04 13:56:22 +02:00
if (client == null)
{
2023-03-19 17:57:55 +00:00
return NotFound();
2018-05-04 13:56:22 +02:00
}
return View(client);
}
// POST: Client/Delete/5
[HttpPost, ActionName("Delete")]
[ValidateAntiForgeryToken]
2026-03-09 02:07:09 +00:00
public async Task<IActionResult> DeleteConfirmed(int id)
2018-05-04 13:56:22 +02:00
{
2026-03-16 23:16:12 +00:00
Client client = await dbContext.Clients
2026-03-09 02:07:09 +00:00
.Include(client => client.ClientSecrets)
.SingleAsync(m => m.Id == id);
2026-03-16 23:16:12 +00:00
dbContext.Clients.Remove(client);
await dbContext.SaveChangesAsync();
2018-05-04 13:56:22 +02:00
return RedirectToAction("Index");
}
2026-06-19 01:36:08 +01:00
// GET: Client/RegenerateSecret/5
[ActionName("RegenerateSecret")]
public async Task<IActionResult> RegenerateSecretGet(int id)
{
Client client = await dbContext.Clients
.Include(c => c.ClientSecrets)
.SingleOrDefaultAsync(m => m.Id == id);
if (client == null)
{
return NotFound();
}
return View("RegenerateSecret", client);
}
// POST: Client/RegenerateSecret/5
[HttpPost, ActionName("RegenerateSecret")]
[ValidateAntiForgeryToken]
public async Task<IActionResult> RegenerateSecretConfirmed(int id)
{
Client client = await dbContext.Clients
.Include(c => c.ClientSecrets)
.SingleOrDefaultAsync(m => m.Id == id);
if (client == null)
{
return NotFound();
}
// Generate a fresh secret in clear text. We display it to the admin
// once, then IdentityServer will hash it on SaveChanges.
var newSecret = GenerateRawClientSecret();
var now = DateTime.UtcNow;
var expiration = now.AddDays(90);
// Replace: drop existing secrets and add the freshly generated one.
if (client.ClientSecrets != null && client.ClientSecrets.Count > 0)
{
dbContext.ClientSecrets.RemoveRange(client.ClientSecrets);
}
client.ClientSecrets = new List<ClientSecret>
{
new ClientSecret
{
ClientId = client.Id,
Client = client,
Type = "SharedSecret",
Value = newSecret,
Description = $"Regenerated on {now:yyyy-MM-dd HH:mm:ss} UTC",
Created = now,
Expiration = expiration
}
};
dbContext.Update(client);
await dbContext.SaveChangesAsync(User.GetUserId());
// Flash the secret through TempData so the next request can render
// it exactly once, then it is gone forever (IdentityServer stores
// it hashed).
TempData["NewClientSecret"] = newSecret;
TempData["NewClientSecretExpiresAt"] = expiration.ToString("u");
TempData["NewClientSecretClientName"] = client.ClientName ?? client.ClientId;
return RedirectToAction("ShowSecret", new { id = client.Id });
}
// GET: Client/ShowSecret/5
public IActionResult ShowSecret(int id)
{
var secret = TempData["NewClientSecret"] as string;
if (string.IsNullOrEmpty(secret))
{
// The one-shot window is closed. Refuse to render anything
// sensitive and bounce back to the details page.
return RedirectToAction("Details", new { id });
}
// TempData.Keep would persist to the next request; we deliberately
// do NOT keep it so the value cannot be replayed.
ViewBag.NewClientSecret = secret;
ViewBag.NewClientSecretExpiresAt = TempData["NewClientSecretExpiresAt"] as string;
ViewBag.NewClientSecretClientName = TempData["NewClientSecretClientName"] as string;
ViewBag.ClientId = id;
return View();
}
private static string GenerateRawClientSecret()
{
// 32 bytes => 43 url-safe base64 chars without padding. Enough entropy
// for a client secret; readable enough to copy/paste once.
var bytes = new byte[32];
System.Security.Cryptography.RandomNumberGenerator.Fill(bytes);
return Convert.ToBase64String(bytes)
.TrimEnd('=')
.Replace('+', '-')
.Replace('/', '_');
}
2018-05-04 13:56:22 +02:00
}
}