APi Scopes

This commit is contained in:
Paul Schneider 2026-03-16 23:16:12 +00:00
commit be7df3d054
25 changed files with 823 additions and 116 deletions

View file

@ -0,0 +1,153 @@
using Microsoft.AspNetCore.Mvc;
using Microsoft.EntityFrameworkCore;
using Yavsc.Models;
using IdentityServer8.EntityFramework.Entities;
namespace Yavsc.Org.Controllers
{
public class ApiScopeController : Controller
{
private readonly ApplicationDbContext _context;
public ApiScopeController(ApplicationDbContext context)
{
_context = context;
}
// GET: ApiScope
public async Task<IActionResult> Index()
{
return View(await _context.ApiScopes.ToListAsync());
}
// GET: ApiScope/Details/5
public async Task<IActionResult> Details(int? id)
{
if (id == null)
{
return NotFound();
}
var apiScope = await _context.ApiScopes
.FirstOrDefaultAsync(m => m.Id == id);
if (apiScope == null)
{
return NotFound();
}
return View(apiScope);
}
// GET: ApiScope/Create
public IActionResult Create()
{
return View();
}
// POST: ApiScope/Create
// To protect from overposting attacks, enable the specific properties you want to bind to.
// For more details, see http://go.microsoft.com/fwlink/?LinkId=317598.
[HttpPost]
[ValidateAntiForgeryToken]
public async Task<IActionResult> Create(ApiScope apiScope)
{
if (ModelState.IsValid)
{
_context.Add(apiScope);
await _context.SaveChangesAsync();
return RedirectToAction(nameof(Index));
}
return View(apiScope);
}
// GET: ApiScope/Edit/5
public async Task<IActionResult> Edit(int? id)
{
if (id == null)
{
return NotFound();
}
var apiScope = await _context.ApiScopes.FindAsync(id);
if (apiScope == null)
{
return NotFound();
}
return View(apiScope);
}
// POST: ApiScope/Edit/5
// To protect from overposting attacks, enable the specific properties you want to bind to.
// For more details, see http://go.microsoft.com/fwlink/?LinkId=317598.
[HttpPost]
[ValidateAntiForgeryToken]
public async Task<IActionResult> Edit(int id,
ApiScope apiScope)
{
if (id != apiScope.Id)
{
return NotFound();
}
if (ModelState.IsValid)
{
try
{
_context.Update(apiScope);
await _context.SaveChangesAsync();
}
catch (DbUpdateConcurrencyException)
{
if (!ApiScopeExists(apiScope.Id))
{
return NotFound();
}
else
{
throw;
}
}
return RedirectToAction(nameof(Index));
}
return View(apiScope);
}
// GET: ApiScope/Delete/5
public async Task<IActionResult> Delete(int? id)
{
if (id == null)
{
return NotFound();
}
var apiScope = await _context.ApiScopes
.FirstOrDefaultAsync(m => m.Id == id);
if (apiScope == null)
{
return NotFound();
}
return View(apiScope);
}
// POST: ApiScope/Delete/5
[HttpPost, ActionName("Delete")]
[ValidateAntiForgeryToken]
public async Task<IActionResult> DeleteConfirmed(int id)
{
var apiScope = await _context.ApiScopes.FindAsync(id);
if (apiScope != null)
{
_context.ApiScopes.Remove(apiScope);
}
await _context.SaveChangesAsync();
return RedirectToAction(nameof(Index));
}
private bool ApiScopeExists(int id)
{
return _context.ApiScopes.Any(e => e.Id == id);
}
}
}

View file

@ -0,0 +1,58 @@
using IdentityServer8.EntityFramework.Entities;
using Microsoft.AspNetCore.Http;
using Microsoft.AspNetCore.Mvc;
using Microsoft.EntityFrameworkCore;
using Yavsc.Models;
using Yavsc.Server.Helpers;
namespace Yavsc.Org.Controllers.Administration
{
[Route("api/[controller]")]
[ApiController]
public class ApiScopesApiController : ControllerBase
{
private ApplicationDbContext dbContext;
public ApiScopesApiController(ApplicationDbContext dbContext)
{
this.dbContext = dbContext;
}
// GET: api/<Administration>
[HttpGet]
public async Task<IEnumerable<ApiScope>> Get(int skip = 0, int take = 25)
{
return await dbContext.ApiScopes.Skip(skip).Take(take).ToArrayAsync();
}
// GET api/<Administration>/5
[HttpGet("{id}")]
public async Task<ApiScope> Get(int id)
{
return await dbContext.ApiScopes.FirstOrDefaultAsync(s => s.Id == id);
}
// POST api/<Administration>
[HttpPost]
public async Task Post([FromBody] ApiScope value)
{
dbContext.ApiScopes.Add(value);
await dbContext.SaveChangesAsync(User.GetUserId());
}
// PUT api/<Administration>/5
[HttpPut("{id}")]
public async Task Put(int id, [FromBody] ApiScope value)
{
dbContext.Update(value);
await dbContext.SaveChangesAsync(User.GetUserId());
}
// DELETE api/<Administration>/5
[HttpDelete("{id}")]
public async Task Delete(int id)
{
var scope = await dbContext.ApiScopes.FirstAsync(s => s.Id == id);
dbContext.Remove(scope);
}
}
}

View file

@ -5,33 +5,36 @@ using Microsoft.AspNetCore.Authorization;
using Microsoft.AspNetCore.Mvc;
using Microsoft.AspNetCore.Mvc.Rendering;
using Microsoft.EntityFrameworkCore;
using Microsoft.Extensions.Options;
using Yavsc.Models;
using Yavsc.Models.Auth;
using Yavsc.Server.Helpers;
namespace Yavsc.Controllers
{
[Authorize("AdministratorOnly")]
public class ClientController : Controller
{
private readonly ApplicationDbContext context;
private readonly ApplicationDbContext dbContext;
private readonly ClientStore clientStore;
private readonly SiteSettings siteSettings;
public ClientController(ApplicationDbContext context,
ClientStore clientStore,
IdentityServer8.Stores.ValidatingClientStore<ClientStore> validatingClientStore
public ClientController(
ApplicationDbContext dbContext,
ClientStore clientStore, IOptions<SiteSettings> siteSettingsOptions
)
{
this.context = context;
this.dbContext = dbContext;
this.clientStore = clientStore;
this.siteSettings = siteSettingsOptions.Value;
}
// GET: Client
public async Task<IActionResult> Index()
{
return View(await context.Clients.Include(c => c.AllowedGrantTypes)
return View(await dbContext.Clients.Include(c => c.AllowedGrantTypes)
.Include(c => c.RedirectUris).ToListAsync());
}
@ -39,7 +42,7 @@ namespace Yavsc.Controllers
public async Task<IActionResult> Details(int id)
{
Client client = await context.Clients.Include(
Client client = await dbContext.Clients.Include(
c => c.ClientSecrets
).Include(c => c.AllowedGrantTypes)
.Include(c => c.RedirectUris)
@ -59,8 +62,6 @@ namespace Yavsc.Controllers
// GET: Client/Create
public IActionResult Create()
{
Secret s;
SetAppTypesInputValues();
return View();
}
@ -68,6 +69,7 @@ namespace Yavsc.Controllers
// POST: Client/Create
[HttpPost]
[ValidateAntiForgeryToken]
public async Task<IActionResult> Create(Client client)
{
if (ModelState.IsValid)
@ -79,16 +81,39 @@ namespace Yavsc.Controllers
return BadRequest(ModelState);
}
context.Clients.Add(client);
if (client.ClientSecrets != null)
{
foreach (var secret in client.ClientSecrets)
{
context.ClientSecrets.Add(secret);
}
}
await context.SaveChangesAsync();
dbContext.Clients.Add(client);
await dbContext.SaveChangesAsync(User.GetUserId());
dbContext.ClientRedirectUris.Add(new ClientRedirectUri
{
ClientId = client.Id,
RedirectUri = siteSettings.Audience
});
dbContext.ClientCorsOrigins.Add(new ClientCorsOrigin
{
ClientId = client.Id,
Origin = siteSettings.Audience
});
foreach (String credType in new String[] { "code", "client_credentials", "password" })
{
dbContext.ClientGrantTypes.Add(new ClientGrantType
{
ClientId = client.Id,
GrantType = credType
});
}
foreach (String scope in new String[] { "openid", "profile" })
{
dbContext.ClientScopes.Add(new ClientScope
{
ClientId = client.Id,
Scope = scope
});
}
await dbContext.SaveChangesAsync(User.GetUserId());
return RedirectToAction("Index");
}
@ -112,7 +137,7 @@ namespace Yavsc.Controllers
// GET: Client/Edit/5
public async Task<IActionResult> Edit(int id)
{
Client client = await context.Clients.SingleOrDefaultAsync(m => m.Id == id);
Client client = await dbContext.Clients.SingleOrDefaultAsync(m => m.Id == id);
if (client == null)
{
return NotFound();
@ -133,11 +158,11 @@ namespace Yavsc.Controllers
{
foreach (var secret in client.ClientSecrets)
{
context.Update(secret);
dbContext.Update(secret);
}
}
context.Update(client);
await context.SaveChangesAsync();
dbContext.Update(client);
await dbContext.SaveChangesAsync();
return RedirectToAction("Index");
}
return View(client);
@ -148,7 +173,7 @@ namespace Yavsc.Controllers
public async Task<IActionResult> Delete(int id)
{
Client client = await context.Clients.SingleOrDefaultAsync(m => m.Id == id);
Client client = await dbContext.Clients.SingleOrDefaultAsync(m => m.Id == id);
if (client == null)
{
return NotFound();
@ -162,11 +187,11 @@ namespace Yavsc.Controllers
[ValidateAntiForgeryToken]
public async Task<IActionResult> DeleteConfirmed(int id)
{
Client client = await context.Clients
Client client = await dbContext.Clients
.Include(client => client.ClientSecrets)
.SingleAsync(m => m.Id == id);
context.Clients.Remove(client);
await context.SaveChangesAsync();
dbContext.Clients.Remove(client);
await dbContext.SaveChangesAsync();
return RedirectToAction("Index");
}
}