The Site:Audience setting was conflating two distinct concepts: an OAuth JWT audience (a single resource identifier) and a CORS allow-list (an array of origins). Collapsing them caused several latent bugs: - OAuth/JWT validation expected a single string while CORS WithOrigins accepts an array. - Password-reset callback URLs and OAuth client RedirectUri/Origin were being built from what was meant to be an audience identifier, not a base URL. - Yavsc.Org's main CORS policy was hardcoded to '*', with no way to restrict it without code changes. Changes: - SiteSettings.Audience (string) replaced with CorsAllowedOrigins (IList<string>). - OAuth JWT Authority still reads Site:Authority; Audience now reads Site:ExternalUrl (Org only; Api/Blogs use ValidateAudience=false). - MailSender and AccountController build reset-callback URLs from Site:ExternalUrl. - ClientController uses Site:ExternalUrl for OAuth RedirectUri/Origin defaults on newly created clients. - Yavsc.Api and Yavsc.Blogs now read CORS origins from Site:CorsAllowedOrigins instead of hardcoded URLs. Add shared AddYavscCors / AddYavscJwtBearer extension methods in Yavsc.Server/Helpers/ServiceExtensions.cs to enforce a single configuration contract across all runtime services (Api, Blogs, Org). Fails closed when CorsAllowedOrigins is empty; fails fast at startup when Site:Authority is missing. Remove obsolete ConfigurationHelpers.GetAudience (no remaining callers). Local appsettings-*.json files (which carry deployment-specific values and are gitignored) must be updated to add Site:CorsAllowedOrigins.
128 lines
4.4 KiB
C#
128 lines
4.4 KiB
C#
/*
|
|
Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/
|
|
|
|
Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.
|
|
|
|
Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.
|
|
Source code and license this software can be found
|
|
|
|
The above copyright notice and this permission notice shall be included in all
|
|
copies or substantial portions of the Software.
|
|
*/
|
|
|
|
using Anthropic.SDK;
|
|
using IdentityModel;
|
|
using Microsoft.AspNetCore.Mvc;
|
|
using Microsoft.EntityFrameworkCore;
|
|
using Yavsc;
|
|
using Yavsc.Abstract.Interfaces;
|
|
using Yavsc.Helpers;
|
|
using Yavsc.Interface;
|
|
using Yavsc.Models;
|
|
using Yavsc.Server.Helpers;
|
|
using Yavsc.Services;
|
|
|
|
internal class Program
|
|
{
|
|
private static async Task Main(string[] args)
|
|
{
|
|
Console.Title = "API";
|
|
|
|
var builder = WebApplication.CreateBuilder(args);
|
|
|
|
builder.AddConfiguration("api");
|
|
|
|
var services = builder.Services;
|
|
|
|
// Anthropic client
|
|
builder.Services.AddSingleton<AnthropicClient>(_ =>
|
|
new AnthropicClient(
|
|
new APIAuthentication(
|
|
builder.Configuration["ANTHROPIC_API_KEY"]
|
|
?? throw new InvalidOperationException("ANTHROPIC_API_KEY manquante")
|
|
)
|
|
)
|
|
);
|
|
|
|
// Service de modération
|
|
if (builder.Environment.IsDevelopment())
|
|
builder.Services.AddScoped<IModerationService, MockModerationService>();
|
|
else
|
|
builder.Services.AddScoped<IModerationService, ClaudeModerationService>();
|
|
|
|
|
|
// accepts any access token issued by identity server
|
|
// adds an authorization policy for scope 'scope1'
|
|
|
|
services
|
|
.AddAuthorization(options =>
|
|
{
|
|
options.AddPolicy("ApiScope", policy =>
|
|
{
|
|
policy
|
|
.RequireAuthenticatedUser()
|
|
.RequireClaim(JwtClaimTypes.Scope, new string[] { "com" });
|
|
});
|
|
})
|
|
.AddYavscCors(builder.Configuration)
|
|
.AddControllers();
|
|
|
|
// accepts any access token issued by identity server
|
|
services.AddAuthentication("Bearer")
|
|
.AddYavscJwtBearer(builder.Configuration);
|
|
|
|
services.AddDbContext<ApplicationDbContext>(options =>
|
|
|
|
options.UseNpgsql(builder.Configuration.GetConnectionString("DefaultConnection")));
|
|
|
|
services.AddLocalization(options =>
|
|
{
|
|
options.ResourcesPath = "Resources";
|
|
});
|
|
//
|
|
services.AddTransient<Microsoft.AspNetCore.Identity.IEmailSender<ApplicationUser>, MailSender>();
|
|
services.AddTransient<ITrueEmailSender, MailSender>()
|
|
.AddTransient<Microsoft.AspNetCore.Identity.UI.Services.IEmailSender,
|
|
MailSender>()
|
|
.AddTransient<IBillingService, BillingService>()
|
|
.AddTransient<ICalendarManager, CalendarManager>();
|
|
services.AddTransient<IFileSystemAuthManager, FileSystemAuthManager>();
|
|
builder.Services.AddSession(options =>
|
|
{
|
|
options.IdleTimeout = TimeSpan.FromMinutes(30);
|
|
options.Cookie.HttpOnly = true;
|
|
options.Cookie.IsEssential = false;
|
|
});
|
|
|
|
builder.Services.AddDistributedMemoryCache();
|
|
|
|
builder.Services.Configure<RequestLocalizationOptions>(options =>
|
|
{
|
|
var supportedCultures = new[] { "fr", "en", "pt" };
|
|
options.SetDefaultCulture(supportedCultures[0])
|
|
.AddSupportedCultures(supportedCultures)
|
|
.AddSupportedUICultures(supportedCultures);
|
|
});
|
|
WorkflowHelpers.ConfigureBillingService();
|
|
using (var app = builder.Build())
|
|
{
|
|
if (app.Environment.IsDevelopment())
|
|
app.UseDeveloperExceptionPage();
|
|
|
|
app
|
|
.UseRouting()
|
|
.UseAuthentication()
|
|
.UseAuthorization()
|
|
.UseCors("default")
|
|
;
|
|
app.MapIdentityApi<ApplicationUser>().RequireAuthorization("ApiScope");
|
|
app.MapDefaultControllerRoute();
|
|
app.MapGet("/identity", (HttpContext context) =>
|
|
new JsonResult(context?.User?.Claims.Select(c => new { c.Type, c.Value }))
|
|
);
|
|
|
|
app.UseSession();
|
|
await app.RunAsync();
|
|
}
|
|
}
|
|
}
|