AuthService.cs 31 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857858859860861862863864865866867868869870871872873874875876877878879880881882883884885886887888889890891892893894895896897898899900901902903904905906907908909910911912913914915916917918919920921922923924925926927928929930931932933934935936937938939940941942943944945946947948949950
  1. using System;
  2. using System.Collections.Generic;
  3. using System.Drawing;
  4. using System.IO;
  5. using System.Net;
  6. using System.Security.Authentication;
  7. using System.Security.Cryptography;
  8. using System.Text;
  9. using System.Collections.Specialized;
  10. using System.Threading;
  11. using FastReport.Cloud.FastReport;
  12. using FastReport.Utils;
  13. using System.Threading.Tasks;
  14. namespace FastReport.Auth
  15. {
  16. /// <summary>
  17. /// Service for working with auth in the Fast Report.
  18. /// </summary>
  19. public class AuthService
  20. {
  21. #region Private Fields
  22. private string code;
  23. private string code_verifier;
  24. private string nonce;
  25. private string scopes;
  26. private string session;
  27. private string state;
  28. private string redirectUri;
  29. private string lastAuthHost;
  30. #endregion Private Fields
  31. #region Public Properties
  32. /// <summary>
  33. /// Instance of default Service.
  34. /// </summary>
  35. public static AuthService Instance { get; } = new AuthService();
  36. /// <summary>
  37. /// Gets or sets indicator to enable or disable personalisation service
  38. /// </summary>
  39. public bool IsEnable { get; set; } = true;
  40. /// <summary>
  41. /// Setting of the service.
  42. /// </summary>
  43. public AppSettings Settings { get; } = new AppSettings();
  44. /// <summary>
  45. /// User of the service.
  46. /// </summary>
  47. public AppUser User { get; } = new AppUser();
  48. #endregion Public Properties
  49. #region Public Methods
  50. /// <summary>
  51. /// If FastReport.config contains information about custom server and api-key to it,
  52. /// this method will reset inner instance with that data. Otherwise default server
  53. /// will be set.
  54. /// </summary>
  55. /// <summary>
  56. /// The method creates an sign in link.
  57. /// </summary>
  58. /// <returns></returns>
  59. public string GenerateSignInUri(string redirectURI)
  60. {
  61. try
  62. {
  63. this.nonce = NewRandomString(10);
  64. this.state = NewRandomString(64);
  65. this.code_verifier = NewRandomString(128);
  66. string codeChallenge = Sha256Url(code_verifier);
  67. StringBuilder sb = new StringBuilder(1024);
  68. sb.Append(Settings.Host + Settings.AuthorizationEndpoint).Append('?')
  69. .Append("response_type=").Append(Uri.EscapeDataString(Settings.ResponseType))
  70. .Append('&')
  71. .Append("client_id=").Append(Uri.EscapeDataString(Settings.ClientId))
  72. .Append('&')
  73. .Append("nonce=").Append(Uri.EscapeDataString(this.nonce))
  74. .Append('&')
  75. .Append("redirect_uri=").Append(Uri.EscapeDataString(redirectURI))
  76. .Append('&')
  77. .Append("scope=").Append(Uri.EscapeDataString(Settings.Scopes))
  78. //.Append('&')
  79. //.Append("response_mode=").Append(Uri.EscapeDataString(Settings.ResponseMode))
  80. .Append('&')
  81. .Append("code_challenge_method=").Append(Uri.EscapeDataString(Settings.CodeChallengeMethod))
  82. .Append('&')
  83. .Append("code_challenge=").Append(Uri.EscapeDataString(codeChallenge))
  84. .Append('&')
  85. .Append("state=").Append(Uri.EscapeDataString(this.state));
  86. ;
  87. return sb.ToString();
  88. }
  89. catch (Exception e)
  90. {
  91. throw new AuthenticationException("Error generating sign in uri, maybe one of the path parameters is null.", e);
  92. }
  93. }
  94. /// <summary>
  95. /// The method creates an sign out link.
  96. /// </summary>
  97. /// <returns></returns>
  98. public string GenerateSignOutUri(string redirectURI)
  99. {
  100. try
  101. {
  102. StringBuilder sb = new StringBuilder(1024);
  103. sb.Append(GetAuthHost() + Settings.EndSessionEndpoint).Append('?')
  104. .Append("id_token_hint=")
  105. .Append(Uri.EscapeDataString(User.IdToken))
  106. .Append("&post_logout_redirect_uri=")
  107. .Append(Uri.EscapeDataString(redirectURI));
  108. return sb.ToString();
  109. }
  110. catch (Exception e)
  111. {
  112. throw new AuthenticationException("Error generating sign out uri, maybe one of the path parameters is null.", e);
  113. }
  114. }
  115. /// <summary>
  116. /// Returns true, if user has offline_access scope and refresh_token is not null
  117. /// </summary>
  118. public bool CanRefresh
  119. {
  120. get
  121. {
  122. return !String.IsNullOrEmpty(User.RefreshToken) && (User.Scopes == null || User.Scopes != null && Contains(User.Scopes, "offline_access"));
  123. }
  124. }
  125. /// <summary>
  126. /// If possible, the method updates the user credentials.
  127. /// </summary>
  128. /// <returns>True if success</returns>
  129. public bool Refresh()
  130. {
  131. try
  132. {
  133. if (CanRefresh)
  134. {
  135. var request = HttpWebRequest.Create(new Uri(GetAuthHost() + Settings.TokenEndpoint));
  136. request.Method = "POST";
  137. request.ContentType = "application/x-www-form-urlencoded";
  138. using (Stream requestStream = request.GetRequestStream())
  139. {
  140. byte[] bytes = Encoding.UTF8.GetBytes(GenerateTokenRequestBodyByRefresh());
  141. requestStream.Write(bytes, 0, bytes.Length);
  142. }
  143. using (var response = request.GetResponse())
  144. {
  145. using (Stream responseStream = response.GetResponseStream())
  146. {
  147. using (TextReader tr = new StreamReader(responseStream, Encoding.UTF8))
  148. {
  149. var result = tr.ReadToEnd();
  150. SaveTokens(result);
  151. ValidateTokens();
  152. ParseTokens();
  153. }
  154. }
  155. }
  156. return true;
  157. }
  158. }
  159. catch (Exception ex)
  160. {
  161. User.RefreshToken = null;
  162. }
  163. return false;
  164. }
  165. /// <summary>
  166. /// The method resets auth, without sign out process.
  167. /// </summary>
  168. public void Reset()
  169. {
  170. User.Reset();
  171. }
  172. /// <summary>
  173. /// The method shows sign in form and auth the user.
  174. /// </summary>
  175. public async Task SignIn(CancellationToken token = default)
  176. {
  177. NameValueCollection queryString;
  178. using (var authServer = new TCPServerListener())
  179. {
  180. redirectUri = authServer.RedirectURL;
  181. redirectUri = redirectUri.Remove(redirectUri.Length - 1);
  182. var uri = GenerateSignInUri(redirectUri + Settings.RedirectSignInUri);
  183. authServer.Open();
  184. ProcessHelper.StartProcess(uri);
  185. var context = await authServer.WaitConnectAsync(token).ConfigureAwait(false);
  186. if (context is null)
  187. {
  188. return;
  189. }
  190. var response = context.Response;
  191. var request = context.Request;
  192. response.Redirect(Settings.Host + Settings.RedirectSignInUri);
  193. response.OutputStream.Close();
  194. lastAuthHost = Settings.Host;
  195. queryString = request.QueryString;
  196. }
  197. SignInCalback(queryString);
  198. }
  199. /// <summary>
  200. /// The method shows sign out form and resets the user credentials.
  201. /// </summary>
  202. public async Task SignOut(CancellationToken token = default)
  203. {
  204. using (var authServer = new TCPServerListener())
  205. {
  206. redirectUri = authServer.RedirectURL;
  207. redirectUri = redirectUri.Remove(redirectUri.Length - 1);
  208. string uri = GenerateSignOutUri(redirectUri + Settings.RedirectSignOutUri);
  209. authServer.Open();
  210. ProcessHelper.StartProcess(uri);
  211. var context = await authServer.WaitConnectAsync(token).ConfigureAwait(false);
  212. if (context is null)
  213. {
  214. return;
  215. }
  216. var response = context.Response;
  217. response.Redirect(GetAuthHost() + Settings.RedirectSignInUri);
  218. response.OutputStream.Close();
  219. }
  220. User.Reset();
  221. }
  222. #endregion Public Methods
  223. #region Internal Methods
  224. internal static string NewRandomString(int v)
  225. {
  226. const string chars = "abcdefghijklmnopqrstuvwxyz1234567890";
  227. Random r = new Random();
  228. StringBuilder sb = new StringBuilder(v);
  229. for (int i = 0; i < v; i++)
  230. {
  231. sb.Append(chars[r.Next(chars.Length)]);
  232. }
  233. return sb.ToString();
  234. }
  235. #endregion Internal Methods
  236. #region Private Methods
  237. private string GetAuthHost()
  238. {
  239. return string.IsNullOrEmpty(lastAuthHost) ? Settings.Host : lastAuthHost;
  240. }
  241. private void SignInCalback(NameValueCollection queryString)
  242. {
  243. // Checks for errors.
  244. if (HasError(queryString))
  245. return;
  246. Process(queryString);
  247. SignInPart2SecondRequest();
  248. }
  249. private bool HasError(NameValueCollection query)
  250. {
  251. var error = query.Get("error");
  252. if (error != null)
  253. {
  254. if (error == "access_denied")
  255. return true;
  256. else
  257. throw new AuthenticationException(error);
  258. //output(String.Format("OAuth authorization error: {0}.", error));
  259. }
  260. return false;
  261. }
  262. private static string Base64UrlToBase64(string base64url)
  263. {
  264. string base64 = base64url.Replace('-', '+').Replace('_', '/');
  265. if (base64.Length % 4 != 0)
  266. {
  267. base64 += new string('=', 4 - base64.Length % 4);
  268. }
  269. return base64;
  270. }
  271. private static string ConvertToString(object v, string defaultValue)
  272. {
  273. if (v != null)
  274. return v.ToString();
  275. return defaultValue;
  276. }
  277. private static string Sha256Url(string input)
  278. {
  279. if (String.IsNullOrEmpty(input))
  280. return string.Empty;
  281. using (var sha = SHA256.Create())
  282. {
  283. var bytes = Encoding.UTF8.GetBytes(input);
  284. var hash = sha.ComputeHash(bytes);
  285. return Convert.ToBase64String(hash).Replace('+', '-').Replace('/', '_').Replace("=", "");
  286. }
  287. }
  288. private static bool Contains(IEnumerable<string> scopes, string value)
  289. {
  290. foreach (string scope in scopes)
  291. {
  292. if (scope == value)
  293. return true;
  294. }
  295. return false;
  296. }
  297. private byte[] Download(string url)
  298. {
  299. using (MemoryStream memoryStream = new MemoryStream())
  300. {
  301. #if MONO
  302. ServicePointManager.Expect100Continue = true;
  303. ServicePointManager.SecurityProtocol = SecurityProtocolType.Tls12;
  304. #endif
  305. try
  306. {
  307. // send second request
  308. var request = HttpWebRequest.Create(new Uri(url));
  309. request.Method = "GET";
  310. using (var response = request.GetResponse())
  311. {
  312. using (Stream responseStream = response.GetResponseStream())
  313. {
  314. responseStream.CopyTo(memoryStream);
  315. }
  316. }
  317. }
  318. catch
  319. {
  320. }
  321. return memoryStream.ToArray();
  322. }
  323. }
  324. private string GenerateTokenRequestBodyByCode(string redirectUri)
  325. {
  326. try
  327. {
  328. StringBuilder sb = new StringBuilder(1024);
  329. sb
  330. .Append("grant_type=authorization_code")
  331. //.Append(Uri.EscapeDataString(Settings.GrandType))
  332. .Append("&client_id=").Append(Uri.EscapeDataString(Settings.ClientId))
  333. .Append("&scope=").Append(Uri.EscapeDataString(this.scopes))
  334. .Append("&redirect_uri=").Append(Uri.EscapeDataString(redirectUri))
  335. .Append("&code=").Append(Uri.EscapeDataString(this.code))
  336. .Append("&code_verifier=").Append(Uri.EscapeDataString(this.code_verifier))
  337. .Append("&client_secret=").Append(Uri.EscapeDataString(Settings.ClientSecret));
  338. return sb.ToString();
  339. }
  340. catch (Exception e)
  341. {
  342. throw new AuthenticationException("Error generating token request body, maybe one of the path parameters is null.", e);
  343. }
  344. }
  345. private string GenerateTokenRequestBodyByRefresh()
  346. {
  347. try
  348. {
  349. StringBuilder sb = new StringBuilder(1024);
  350. sb
  351. .Append("grant_type=refresh_token")
  352. //.Append(Uri.EscapeDataString(Settings.GrandType))
  353. .Append("&client_id=").Append(Uri.EscapeDataString(Settings.ClientId))
  354. .Append("&refresh_token=").Append(Uri.EscapeDataString(User.RefreshToken))
  355. .Append("&client_secret=").Append(Uri.EscapeDataString(Settings.ClientSecret));
  356. ;
  357. if (User.Scopes != null && User.Scopes.Length > 0)
  358. {
  359. sb.Append("&scope=").Append(Uri.EscapeDataString(String.Join(" ", User.Scopes)));
  360. }
  361. return sb.ToString();
  362. }
  363. catch (Exception e)
  364. {
  365. throw new AuthenticationException("Error generating token request body, maybe one of the path parameters is null.", e);
  366. }
  367. }
  368. private string Gravatar(string email)
  369. {
  370. MD5 md5Hasher = MD5.Create();
  371. byte[] data = md5Hasher.ComputeHash(Encoding.Default.GetBytes(email));
  372. StringBuilder sBuilder = new StringBuilder("https://www.gravatar.com/avatar/");
  373. for (int i = 0; i < data.Length; i++)
  374. {
  375. sBuilder.Append(data[i].ToString("x2"));
  376. }
  377. sBuilder.Append("?s=150");
  378. return sBuilder.ToString();
  379. }
  380. /// <summary>
  381. /// Do not make this method public, use refresh token for save-load. <br/>
  382. /// You need only refresh token (<see cref="AppUser.RefreshToken"/>) to get a new token set.<br/>
  383. /// This method is used to save time for starting a designer.
  384. /// </summary>
  385. internal void ParseTokens(bool isProgramStart = false)
  386. {
  387. try
  388. {
  389. if (!String.IsNullOrEmpty(User.IdToken))
  390. {
  391. string[] token = User.IdToken.Split('.');
  392. string payload = token[1];
  393. JsonBase json
  394. = JsonBase.FromString(
  395. Encoding.UTF8.GetString(
  396. Convert.FromBase64String(
  397. Base64UrlToBase64(payload)
  398. )
  399. )
  400. );
  401. User.Subject = ConvertToString(json["sub"], "");
  402. User.Email = ConvertToString(json["email"], "");
  403. User.Username = ConvertToString(json["preferred_username"], User.Email);
  404. User.FullName = ConvertToString(json["name"], "");
  405. if ((ConvertToString(json["nonce"], nonce) != nonce) && !isProgramStart)
  406. {
  407. throw new AuthenticationException("Nonce check error, token is not valid.");
  408. }
  409. try
  410. {
  411. var url = Gravatar(User.Email);
  412. var ms = Download(url);
  413. User.Avatar = ImageHelper.Load(ms);
  414. }
  415. catch (Exception e)
  416. {
  417. User.Avatar = null;
  418. }
  419. }
  420. }
  421. catch (AuthenticationException e)
  422. {
  423. User.IdToken = "";
  424. throw e;
  425. }
  426. catch (Exception e)
  427. {
  428. User.IdToken = "";
  429. throw new AuthenticationException("Identity token parse error!", e);
  430. }
  431. try
  432. {
  433. if (!String.IsNullOrEmpty(User.Token))
  434. {
  435. string[] token = User.Token.Split('.');
  436. string payload = token[1];
  437. JsonBase json
  438. = JsonBase.FromString(
  439. Encoding.UTF8.GetString(
  440. Convert.FromBase64String(
  441. Base64UrlToBase64(payload)
  442. )
  443. )
  444. );
  445. double nbf = Convert.ToDouble(json["nbf"]);
  446. double exp = Convert.ToDouble(json["exp"]);
  447. double time = exp - nbf;
  448. User.ExpiresIn = new DateTime(1970, 1, 1, 0, 0, 0, 0).AddSeconds(exp).ToLocalTime();
  449. User.ExpiresInternal = new DateTime(1970, 1, 1, 0, 0, 0, 0).AddSeconds(nbf + time * 0.95).ToLocalTime();
  450. JsonBase scopes = json["scope"] as JsonBase;
  451. if (scopes != null && scopes.IsArray)
  452. {
  453. List<string> allowedScopes = new List<string>();
  454. for (int i = 0; i < scopes.Count; i++)
  455. {
  456. allowedScopes.Add(scopes[i].ToString());
  457. }
  458. User.Scopes = allowedScopes.ToArray();
  459. }
  460. }
  461. }
  462. catch (AuthenticationException e)
  463. {
  464. User.Token = "";
  465. throw e;
  466. }
  467. catch (Exception e)
  468. {
  469. User.Token = "";
  470. throw new AuthenticationException("Access token parse error!", e);
  471. }
  472. }
  473. private void Process(NameValueCollection query)
  474. {
  475. foreach (var key in query.AllKeys)
  476. {
  477. var value = query[key];
  478. switch (key.ToLower())
  479. {
  480. case "code":
  481. this.code = value;
  482. break;
  483. case "scope":
  484. scopes = value;
  485. break;
  486. case "state":
  487. if (value != this.state)
  488. throw new Exception("State is not valid");
  489. break;
  490. case "session_state":
  491. this.session = value;
  492. break;
  493. }
  494. }
  495. }
  496. private void SaveTokens(string result)
  497. {
  498. JsonBase json = JsonBase.FromString(result);
  499. if (json.ContainsKey("expires_in"))
  500. {
  501. var expiresIn = Convert.ToSingle(json["expires_in"]);
  502. User.ExpiresIn = DateTime.Now.AddSeconds(expiresIn);
  503. User.ExpiresInternal = DateTime.Now.AddSeconds(expiresIn * 0.95);
  504. }
  505. else
  506. {
  507. // if no expires_in value, then default token lifetime
  508. User.ExpiresIn = DateTime.Now.AddMinutes(5);
  509. User.ExpiresInternal = User.ExpiresIn;
  510. }
  511. if (!json.ContainsKey("id_token"))
  512. {
  513. throw new AuthenticationException("No id token provided in server response.");
  514. }
  515. if (!json.ContainsKey("access_token"))
  516. {
  517. throw new AuthenticationException("No access token provided in server response.");
  518. }
  519. if (!json.ContainsKey("token_type"))
  520. {
  521. throw new AuthenticationException("No token type provided in server response.");
  522. }
  523. User.IdToken = json.ReadString("id_token");
  524. User.Token = json.ReadString("access_token");
  525. User.TokenType = json.ReadString("token_type");
  526. User.RefreshToken = json.ReadString("refresh_token");
  527. }
  528. private void SignInPart2SecondRequest()
  529. {
  530. var request = HttpWebRequest.Create(new Uri(Settings.Host + Settings.TokenEndpoint));
  531. request.Method = "POST";
  532. request.ContentType = "application/x-www-form-urlencoded";
  533. using (Stream requestStream = request.GetRequestStream())
  534. {
  535. string requestBody = GenerateTokenRequestBodyByCode(redirectUri + Settings.RedirectSignInUri);
  536. byte[] bytes = Encoding.UTF8.GetBytes(requestBody);
  537. requestStream.Write(bytes, 0, bytes.Length);
  538. }
  539. using (var response = request.GetResponse())
  540. {
  541. using (Stream responseStream = response.GetResponseStream())
  542. {
  543. using (TextReader tr = new StreamReader(responseStream, Encoding.UTF8))
  544. {
  545. var result = tr.ReadToEnd();
  546. SaveTokens(result);
  547. ValidateTokens();
  548. ParseTokens();
  549. }
  550. }
  551. }
  552. }
  553. private void ValidateTokens()
  554. {
  555. // External library for validation signature on tokens
  556. User.IsValid = false;
  557. }
  558. #endregion Private Methods
  559. #region Public Classes
  560. /// <summary>
  561. /// Class for store appsettings, by default appsettings is hardcoded.
  562. /// </summary>
  563. public class AppSettings
  564. {
  565. public AppSettings()
  566. {
  567. Host = Res.Get("Forms,AccountWindow,AuthServer");
  568. }
  569. private string host;
  570. #region Public Properties
  571. /// <summary>
  572. /// Authorization Endpoint from the OAuth2 specification.
  573. /// </summary>
  574. public string AuthorizationEndpoint { get; set; } = "/connect/authorize";
  575. /// <summary>
  576. /// Host for callback requests.
  577. /// </summary>
  578. public string CallbackHost { get; set; } = "https://id.fast-report.com";
  579. /// <summary>
  580. /// Client identifier or client name from the OAuth2 specification.
  581. /// </summary>
  582. public string ClientId { get; set; } = "FastReport.Net.Designer";
  583. /// <summary>
  584. /// Client secret or client name from the OAuth2 specification.
  585. /// </summary>
  586. public string ClientSecret { get; set; } = "91d18a32-1630-66d5-7f43-05d6e2caf02f";
  587. /// <summary>
  588. /// Code challenge method from the OAuth2 specification.
  589. /// </summary>
  590. public string CodeChallengeMethod { get; set; } = "S256";
  591. /// <summary>
  592. /// EndSession Endpoint from the OAuth2 specification.
  593. /// </summary>
  594. public string EndSessionEndpoint { get; set; } = "/connect/endsession";
  595. /// <summary>
  596. /// Host for sign in requests
  597. /// </summary>
  598. public string Host
  599. {
  600. get => HttpMessages.Idn.GetAscii(host);
  601. set => host = value;
  602. }
  603. /// <summary>
  604. /// JSON Web Key Set Endpoint from the OAuth2 specification.
  605. /// </summary>
  606. public string JwksEndpoint { get; set; } = "/.well-known/openid-configuration/jwks";
  607. /// <summary>
  608. /// Error result
  609. /// </summary>
  610. public string RedirectError { get; set; } = "/home/error";
  611. /// <summary>
  612. /// Redirent sign in link for this application.
  613. /// </summary>
  614. public string RedirectSignInUri { get; set; } = "/native/sign-in";
  615. /// <summary>
  616. /// Redirent sign out link for this application.
  617. /// </summary>
  618. public string RedirectSignOutUri { get; set; } = "/native/sign-out";
  619. /// <summary>
  620. /// Success result
  621. /// </summary>
  622. public string RedirectSuccess { get; set; } = "/home/success";
  623. /// <summary>
  624. /// Type of the reponse from the OAuth2 specification.
  625. /// </summary>
  626. public string ResponseType { get; set; } = "code";
  627. /// <summary>
  628. /// Scopes for the request from the OAuth2 specification, splited by space.
  629. /// </summary>
  630. public string Scopes { get; set; } = "openid email profile offline_access fr.cloud.role";
  631. /// <summary>
  632. /// Token Endpoint from the OAuth2 specification.
  633. /// </summary>
  634. public string TokenEndpoint { get; set; } = "/connect/token";
  635. #endregion Public Properties
  636. }
  637. public class AppUser
  638. {
  639. #region Private Fields
  640. private Image avatar;
  641. private Image defaultAvatar;
  642. #endregion Private Fields
  643. #region Public Properties
  644. /// <summary>
  645. /// Avatar of the user, by default is 150x150 picture.
  646. /// </summary>
  647. public Image Avatar
  648. {
  649. get { return avatar; }
  650. set
  651. {
  652. if (avatar != null)
  653. avatar.Dispose();
  654. avatar = value;
  655. }
  656. }
  657. /// <summary>
  658. /// Returns the display avatar of the user, cannot return null
  659. /// </summary>
  660. /// <returns></returns>
  661. public Image DisplayAvatar
  662. {
  663. get
  664. {
  665. if (avatar != null)
  666. return avatar;
  667. if (defaultAvatar == null)
  668. defaultAvatar = ResourceLoader.GetBitmap("defaultAvatar.jpg");
  669. return defaultAvatar;
  670. }
  671. }
  672. /// <summary>
  673. /// Returns the display email of the user, cannot return null
  674. /// </summary>
  675. /// <returns></returns>
  676. public string DisplayEmail
  677. {
  678. get
  679. {
  680. if (Email == null)
  681. return "";
  682. return Email;
  683. }
  684. }
  685. /// <summary>
  686. /// Returns the display name of the user, cannot return null
  687. /// </summary>
  688. /// <returns></returns>
  689. public string DisplayName
  690. {
  691. get
  692. {
  693. if (String.IsNullOrEmpty(FullName))
  694. {
  695. if (String.IsNullOrEmpty(Username))
  696. {
  697. if (String.IsNullOrEmpty(Subject))
  698. {
  699. return "";
  700. }
  701. return Subject;
  702. }
  703. return Username;
  704. }
  705. return FullName;
  706. }
  707. }
  708. /// <summary>
  709. /// Email of the user.
  710. /// </summary>
  711. public string Email { get; set; }
  712. /// <summary>
  713. /// Local time when the token will go out.
  714. /// </summary>
  715. public DateTime ExpiresIn { get; set; }
  716. /// <summary>
  717. /// Full name of the user.
  718. /// </summary>
  719. public string FullName { get; set; }
  720. /// <summary>
  721. /// Returns true if user is authenticated.
  722. /// </summary>
  723. public bool IsAuthenticated
  724. {
  725. get
  726. {
  727. return !String.IsNullOrEmpty(IdToken) && !String.IsNullOrEmpty(Token);
  728. }
  729. }
  730. internal bool IsAuthentificatedAndActive
  731. {
  732. get
  733. {
  734. return IsAuthenticated && !IsExpired ||
  735. !string.IsNullOrEmpty(ApiKey);
  736. }
  737. }
  738. /// <summary>
  739. /// Returns true if token is expired and is need to referesh
  740. /// </summary>
  741. public bool IsExpired
  742. {
  743. get
  744. {
  745. return ExpiresInternal < DateTime.Now;
  746. }
  747. }
  748. /// <summary>
  749. /// Indicates that token is check by external method, see <see cref="CustomValidator"/> for details.
  750. /// </summary>
  751. public bool IsValid { get; set; }
  752. /// <summary>
  753. /// List of allowed scopes.
  754. /// </summary>
  755. public string[] Scopes { get; set; }
  756. /// <summary>
  757. /// Identifier of the user.
  758. /// </summary>
  759. public string Subject { get; set; }
  760. /// <summary>
  761. /// Type of token for resource request header, e.g. Bearer.
  762. /// </summary>
  763. public string TokenType { get; set; }
  764. /// <summary>
  765. /// Preferred username of the user.
  766. /// </summary>
  767. public string Username { get; set; }
  768. /// <summary>
  769. /// User's api key.
  770. /// </summary>
  771. public string ApiKey { get; set; }
  772. #endregion Public Properties
  773. #region Internal Properties
  774. /// <summary>
  775. /// Local time when the token needs to be updated.
  776. /// </summary>
  777. internal DateTime ExpiresInternal { get; set; }
  778. internal string IdToken { get; set; }
  779. internal string RefreshToken { get; set; }
  780. internal string Token { get; set; }
  781. #endregion Internal Properties
  782. #region Public Methods
  783. /// <summary>
  784. /// Reset the values
  785. /// </summary>
  786. public void Reset()
  787. {
  788. Avatar = null;
  789. Email = null;
  790. ExpiresIn = DateTime.MinValue;
  791. FullName = null;
  792. IdToken = null;
  793. IsValid = false;
  794. RefreshToken = null;
  795. Scopes = null;
  796. Subject = null;
  797. Token = null;
  798. TokenType = null;
  799. Username = null;
  800. }
  801. #endregion Public Methods
  802. }
  803. #endregion Public Classes
  804. }
  805. }