diff options
Diffstat (limited to 'code')
32 files changed, 418 insertions, 386 deletions
diff --git a/code/api/src/Data/Enums/StringsLang.cs b/code/api/src/Data/Enums/StringsLang.cs new file mode 100644 index 0000000..e4e2066 --- /dev/null +++ b/code/api/src/Data/Enums/StringsLang.cs @@ -0,0 +1,7 @@ +namespace IOL.GreatOffice.Api.Data.Enums; + +public enum StringsLang +{ + ENGLISH_GB = 0, + NORWEGIAN_NB = 1 +}
\ No newline at end of file diff --git a/code/api/src/Data/Enums/TodoVisibility.cs b/code/api/src/Data/Enums/TodoVisibility.cs index 6ebef9b..8581ba9 100644 --- a/code/api/src/Data/Enums/TodoVisibility.cs +++ b/code/api/src/Data/Enums/TodoVisibility.cs @@ -1,4 +1,6 @@ +namespace IOL.GreatOffice.Api.Data.Enums; + public enum TodoVisibility { PRIVATE = 0, diff --git a/code/api/src/Data/Models/KnownProblemModel.cs b/code/api/src/Data/Models/KnownProblemModel.cs new file mode 100644 index 0000000..445d338 --- /dev/null +++ b/code/api/src/Data/Models/KnownProblemModel.cs @@ -0,0 +1,16 @@ +namespace IOL.GreatOffice.Api.Data.Models; + +public class KnownProblemModel +{ + public KnownProblemModel(string title = default, string subtitle = default, Dictionary<string, string> errors = default) { + Title = title; + Subtitle = subtitle; + Errors = errors; + } + + public string Title { get; set; } + public string Subtitle { get; set; } + public Dictionary<string, string> Errors { get; set; } + public string TraceId { get; set; } + public string RequestId { get; set; } +}
\ No newline at end of file diff --git a/code/api/src/Data/Results/ErrorResult.cs b/code/api/src/Data/Results/ErrorResult.cs deleted file mode 100644 index fd2fd6a..0000000 --- a/code/api/src/Data/Results/ErrorResult.cs +++ /dev/null @@ -1,12 +0,0 @@ -namespace IOL.GreatOffice.Api.Data.Results; - -public class ErrorResult -{ - public ErrorResult(string title = default, string text = default) { - Title = title; - Text = text; - } - - public string Title { get; set; } - public string Text { get; set; } -} diff --git a/code/api/src/Endpoints/EndpointBase.cs b/code/api/src/Endpoints/EndpointBase.cs new file mode 100644 index 0000000..c088976 --- /dev/null +++ b/code/api/src/Endpoints/EndpointBase.cs @@ -0,0 +1,27 @@ +using System.Diagnostics; + +namespace IOL.GreatOffice.Api.Endpoints; + +[ApiController] +public class EndpointBase : ControllerBase +{ + /// <summary> + /// User data for the currently logged on user. + /// </summary> + protected LoggedInUserModel LoggedInUser => new() { + Username = User.FindFirstValue(AppClaims.NAME), + Id = User.FindFirstValue(AppClaims.USER_ID).AsGuid(), + }; + + public ObjectResult KnownProblem(string title = default, string subtitle = default, Dictionary<string, string> errors = default) { + return new ObjectResult(new KnownProblemModel { + Title = title, + Subtitle = subtitle, + Errors = errors, + TraceId = Activity.Current?.Id, + RequestId = HttpContext.TraceIdentifier + }) { + StatusCode = (int) HttpStatusCode.BadRequest + }; + } +}
\ No newline at end of file diff --git a/code/api/src/Endpoints/Internal/Account/CreateAccountRoute.cs b/code/api/src/Endpoints/Internal/Account/CreateAccountRoute.cs index 954fbf5..0f4a383 100644 --- a/code/api/src/Endpoints/Internal/Account/CreateAccountRoute.cs +++ b/code/api/src/Endpoints/Internal/Account/CreateAccountRoute.cs @@ -22,16 +22,16 @@ public class CreateAccountRoute : RouteBaseAsync.WithRequest<CreateAccountPayloa [HttpPost("~/_/account/create")] public override async Task<ActionResult> HandleAsync(CreateAccountPayload request, CancellationToken cancellationToken = default) { if (request.Username.IsValidEmailAddress() == false) { - return BadRequest(new ErrorResult("Invalid form", request.Username + " does not look like a valid email")); + return BadRequest(new KnownProblemModel("Invalid form", request.Username + " does not look like a valid email")); } if (request.Password.Length < 6) { - return BadRequest(new ErrorResult("Invalid form", "The password requires 6 or more characters.")); + return BadRequest(new KnownProblemModel("Invalid form", "The password requires 6 or more characters.")); } var username = request.Username.Trim(); if (_context.Users.Any(c => c.Username == username)) { - return BadRequest(new ErrorResult("Username is not available", "There is already a user registered with email: " + username)); + return BadRequest(new KnownProblemModel("Username is not available", "There is already a user registered with email: " + username)); } var user = new User(username); diff --git a/code/api/src/Endpoints/Internal/Account/LoginRoute.cs b/code/api/src/Endpoints/Internal/Account/LoginRoute.cs index 5b41c61..e4ef54c 100644 --- a/code/api/src/Endpoints/Internal/Account/LoginRoute.cs +++ b/code/api/src/Endpoints/Internal/Account/LoginRoute.cs @@ -28,7 +28,7 @@ public class LoginRoute : RouteBaseAsync var user = _context.Users.SingleOrDefault(u => u.Username == request.Username); if (user == default || !user.VerifyPassword(request.Password)) { - return BadRequest(new ErrorResult("Invalid username or password")); + return BadRequest(new KnownProblemModel("Invalid username or password")); } await _userService.LogInUser(HttpContext, user, request.Persist); diff --git a/code/api/src/Endpoints/Internal/Account/UpdateAccountRoute.cs b/code/api/src/Endpoints/Internal/Account/UpdateAccountRoute.cs index a997dcb..31ff10b 100644 --- a/code/api/src/Endpoints/Internal/Account/UpdateAccountRoute.cs +++ b/code/api/src/Endpoints/Internal/Account/UpdateAccountRoute.cs @@ -24,11 +24,11 @@ public class UpdateAccountRoute : RouteBaseAsync.WithRequest<UpdatePayload>.With } if (request.Password.IsNullOrWhiteSpace() && request.Username.IsNullOrWhiteSpace()) { - return BadRequest(new ErrorResult("Invalid request", "No data was submitted")); + return BadRequest(new KnownProblemModel("Invalid request", "No data was submitted")); } if (request.Password.HasValue() && request.Password.Length < 6) { - return BadRequest(new ErrorResult("Invalid request", + return BadRequest(new KnownProblemModel("Invalid request", "The new password must contain at least 6 characters")); } @@ -37,7 +37,7 @@ public class UpdateAccountRoute : RouteBaseAsync.WithRequest<UpdatePayload>.With } if (request.Username.HasValue() && !request.Username.IsValidEmailAddress()) { - return BadRequest(new ErrorResult("Invalid request", + return BadRequest(new KnownProblemModel("Invalid request", "The new username does not look like a valid email address")); } diff --git a/code/api/src/Data/Dtos/UserArchiveDto.cs b/code/api/src/Endpoints/Internal/Account/UserArchiveDto.cs index 42e0600..5d259ab 100644 --- a/code/api/src/Data/Dtos/UserArchiveDto.cs +++ b/code/api/src/Endpoints/Internal/Account/UserArchiveDto.cs @@ -1,5 +1,5 @@ -namespace IOL.GreatOffice.Api.Data.Dtos; +namespace IOL.GreatOffice.Api.Endpoints.Internal.Account; /// <summary> /// Represents a user archive as it is provided to users. diff --git a/code/api/src/Endpoints/Internal/BaseRoute.cs b/code/api/src/Endpoints/Internal/BaseRoute.cs deleted file mode 100644 index 3e2c6af..0000000 --- a/code/api/src/Endpoints/Internal/BaseRoute.cs +++ /dev/null @@ -1,16 +0,0 @@ -namespace IOL.GreatOffice.Api.Endpoints.Internal; - -[Authorize] -[ApiController] -[ApiExplorerSettings(IgnoreApi = true)] -[ApiVersionNeutral] -public class BaseRoute : ControllerBase -{ - /// <summary> - /// User data for the currently logged on user. - /// </summary> - protected LoggedInUserModel LoggedInUser => new() { - Username = User.FindFirstValue(AppClaims.NAME), - Id = User.FindFirstValue(AppClaims.USER_ID).AsGuid(), - }; -} diff --git a/code/api/src/Endpoints/Internal/INT_EndpointBase.cs b/code/api/src/Endpoints/Internal/INT_EndpointBase.cs new file mode 100644 index 0000000..699a976 --- /dev/null +++ b/code/api/src/Endpoints/Internal/INT_EndpointBase.cs @@ -0,0 +1,9 @@ +namespace IOL.GreatOffice.Api.Endpoints.Internal; + +[Authorize] +[ApiExplorerSettings(IgnoreApi = true)] +[ApiVersionNeutral] +public class INT_EndpointBase : EndpointBase +{ + +} diff --git a/code/api/src/Endpoints/Internal/PasswordResetRequests/Create/RequestModel.cs b/code/api/src/Endpoints/Internal/PasswordResetRequests/Create/RequestModel.cs new file mode 100644 index 0000000..236c650 --- /dev/null +++ b/code/api/src/Endpoints/Internal/PasswordResetRequests/Create/RequestModel.cs @@ -0,0 +1,6 @@ +namespace IOL.GreatOffice.Api.Endpoints.Internal.PasswordResetRequests.Create; + +public class RequestModel +{ + public string Username { get; set; } +}
\ No newline at end of file diff --git a/code/api/src/Endpoints/Internal/PasswordResetRequests/Create/Route.cs b/code/api/src/Endpoints/Internal/PasswordResetRequests/Create/Route.cs new file mode 100644 index 0000000..f837fc0 --- /dev/null +++ b/code/api/src/Endpoints/Internal/PasswordResetRequests/Create/Route.cs @@ -0,0 +1,57 @@ +namespace IOL.GreatOffice.Api.Endpoints.Internal.PasswordResetRequests.Create; + +public class Route : RouteBaseAsync.WithRequest<RequestModel>.WithActionResult +{ + private readonly ILogger<Route> _logger; + private readonly PasswordResetService _passwordResetService; + private readonly AppDbContext _context; + + public Route(ILogger<Route> logger, PasswordResetService passwordResetService, AppDbContext context) { + _logger = logger; + _passwordResetService = passwordResetService; + _context = context; + } + + /// <summary> + /// Create a new password reset request. + /// </summary> + /// <param name="request"></param> + /// <param name="cancellationToken"></param> + /// <returns></returns> + [AllowAnonymous] + [HttpPost("~/_/password-reset-request/create")] + public override async Task<ActionResult> HandleAsync(RequestModel request, CancellationToken cancellationToken = default) { + if (!request.Username.IsValidEmailAddress()) { + _logger.LogInformation("Username is invalid, not doing request for password change"); + return KnownProblem("Invalid email address", request.Username + " looks like an invalid email address"); + } + + Request.Headers.TryGetValue(AppHeaders.BROWSER_TIME_ZONE, out var timeZoneHeader); + var tz = TimeZoneInfo.FindSystemTimeZoneById(timeZoneHeader.ToString().HasValue() ? timeZoneHeader.ToString() : "UTC"); + var offset = tz.BaseUtcOffset.Hours; + + // this is fine as long as the client is not connecting from Australia: Lord Howe Island + // according to https://en.wikipedia.org/wiki/Daylight_saving_time_by_country + if (tz.IsDaylightSavingTime(AppDateTime.UtcNow)) { + offset++; + } + + _logger.LogInformation("Request time zone (" + tz.Id + ") offset is: " + offset + " hours"); + var requestDateTime = TimeZoneInfo.ConvertTimeFromUtc(AppDateTime.UtcNow, tz); + _logger.LogInformation("Creating forgot password request with date time: " + requestDateTime.ToString("u")); + + try { + var user = _context.Users.SingleOrDefault(c => c.Username.Equals(request.Username)); + if (user != default) { + await _passwordResetService.AddRequestAsync(user, tz, cancellationToken); + return Ok(); + } + + _logger.LogInformation("User was not found, not doing request for password change"); + return Ok(); + } catch (Exception e) { + _logger.LogError(e, "_/password-reset-request/create threw an exception"); + return Ok(); + } + } +}
\ No newline at end of file diff --git a/code/api/src/Endpoints/Internal/PasswordResetRequests/CreateResetRequestRoute.cs b/code/api/src/Endpoints/Internal/PasswordResetRequests/CreateResetRequestRoute.cs deleted file mode 100644 index 8fbc9a0..0000000 --- a/code/api/src/Endpoints/Internal/PasswordResetRequests/CreateResetRequestRoute.cs +++ /dev/null @@ -1,59 +0,0 @@ -namespace IOL.GreatOffice.Api.Endpoints.Internal.PasswordResetRequests; - -/// <inheritdoc /> -public class CreateResetRequestRoute : RouteBaseAsync.WithRequest<string>.WithActionResult -{ - private readonly ILogger<CreateResetRequestRoute> _logger; - private readonly PasswordResetService _passwordResetService; - private readonly AppDbContext _context; - - /// <inheritdoc /> - public CreateResetRequestRoute(ILogger<CreateResetRequestRoute> logger, PasswordResetService passwordResetService, AppDbContext context) { - _logger = logger; - _passwordResetService = passwordResetService; - _context = context; - } - - /// <summary> - /// Create a new password reset request. - /// </summary> - /// <param name="username"></param> - /// <param name="cancellationToken"></param> - /// <returns></returns> - [AllowAnonymous] - [HttpGet("~/_/forgot-password-requests/create")] - public override async Task<ActionResult> HandleAsync(string username, CancellationToken cancellationToken = default) { - if (!username.IsValidEmailAddress()) { - _logger.LogInformation("Username is invalid, not doing request for password change"); - return BadRequest(new ErrorResult("Invalid email address", username + " looks like an invalid email address")); - } - - Request.Headers.TryGetValue(AppHeaders.BROWSER_TIME_ZONE, out var timeZoneHeader); - var tz = TimeZoneInfo.FindSystemTimeZoneById(timeZoneHeader.ToString().HasValue() ? timeZoneHeader.ToString() : "UTC"); - var offset = tz.BaseUtcOffset.Hours; - - // this is fine as long as the client is not connecting from Australia: Lord Howe Island - // according to https://en.wikipedia.org/wiki/Daylight_saving_time_by_country - if (tz.IsDaylightSavingTime(AppDateTime.UtcNow)) { - offset++; - } - - _logger.LogInformation("Request time zone (" + tz.Id + ") offset is: " + offset + " hours"); - var requestDateTime = TimeZoneInfo.ConvertTimeFromUtc(AppDateTime.UtcNow, tz); - _logger.LogInformation("Creating forgot password request with date time: " + requestDateTime.ToString("u")); - - try { - var user = _context.Users.SingleOrDefault(c => c.Username.Equals(username)); - if (user != default) { - await _passwordResetService.AddRequestAsync(user, tz, cancellationToken); - return Ok(); - } - - _logger.LogInformation("User was not found, not doing request for password change"); - return Ok(); - } catch (Exception e) { - _logger.LogError(e, "ForgotAction failed badly"); - return Ok(); - } - } -} diff --git a/code/api/src/Endpoints/Internal/PasswordResetRequests/FulfillResetRequestRoute.cs b/code/api/src/Endpoints/Internal/PasswordResetRequests/FulfillResetRequestRoute.cs index 96f344a..a0ad4d0 100644 --- a/code/api/src/Endpoints/Internal/PasswordResetRequests/FulfillResetRequestRoute.cs +++ b/code/api/src/Endpoints/Internal/PasswordResetRequests/FulfillResetRequestRoute.cs @@ -18,7 +18,7 @@ public class FulfillResetRequestRoute : RouteBaseAsync.WithRequest<FulfillResetR /// <param name="cancellationToken"></param> /// <returns></returns> [AllowAnonymous] - [HttpPost("~/_/forgot-password-requests/fulfill")] + [HttpPost("~/_/password-reset-request/fulfill")] public override async Task<ActionResult> HandleAsync(FulfillResetRequestPayload request, CancellationToken cancellationToken = default) { try { var fulfilled = await _passwordResetService.FullFillRequestAsync(request.Id, request.NewPassword, cancellationToken); diff --git a/code/api/src/Endpoints/Internal/PasswordResetRequests/IsResetRequestValidRoute.cs b/code/api/src/Endpoints/Internal/PasswordResetRequests/IsResetRequestValidRoute.cs index c4dcd22..917c4f0 100644 --- a/code/api/src/Endpoints/Internal/PasswordResetRequests/IsResetRequestValidRoute.cs +++ b/code/api/src/Endpoints/Internal/PasswordResetRequests/IsResetRequestValidRoute.cs @@ -17,7 +17,7 @@ public class IsResetRequestValidRoute : RouteBaseAsync.WithRequest<Guid>.WithAct /// <param name="cancellationToken"></param> /// <returns></returns> [AllowAnonymous] - [HttpGet("~/_/forgot-password-requests/is-valid")] + [HttpGet("~/_/password-reset-request/is-valid")] public override async Task<ActionResult> HandleAsync(Guid id, CancellationToken cancellationToken = default) { var request = await _passwordResetService.GetRequestAsync(id, cancellationToken); if (request == default) { diff --git a/code/api/src/Endpoints/Internal/RouteBaseAsync.cs b/code/api/src/Endpoints/Internal/RouteBaseAsync.cs index 1bb0af0..a87facf 100644 --- a/code/api/src/Endpoints/Internal/RouteBaseAsync.cs +++ b/code/api/src/Endpoints/Internal/RouteBaseAsync.cs @@ -7,7 +7,7 @@ public static class RouteBaseAsync { public static class WithRequest<TRequest> { - public abstract class WithResult<TResponse> : BaseRoute + public abstract class WithResult<TResponse> : INT_EndpointBase { public abstract Task<TResponse> HandleAsync( TRequest request, @@ -15,7 +15,7 @@ public static class RouteBaseAsync ); } - public abstract class WithoutResult : BaseRoute + public abstract class WithoutResult : INT_EndpointBase { public abstract Task HandleAsync( TRequest request, @@ -23,7 +23,7 @@ public static class RouteBaseAsync ); } - public abstract class WithActionResult<TResponse> : BaseRoute + public abstract class WithActionResult<TResponse> : INT_EndpointBase { public abstract Task<ActionResult<TResponse>> HandleAsync( TRequest request, @@ -31,7 +31,7 @@ public static class RouteBaseAsync ); } - public abstract class WithActionResult : BaseRoute + public abstract class WithActionResult : INT_EndpointBase { public abstract Task<ActionResult> HandleAsync( TRequest request, @@ -42,28 +42,28 @@ public static class RouteBaseAsync public static class WithoutRequest { - public abstract class WithResult<TResponse> : BaseRoute + public abstract class WithResult<TResponse> : INT_EndpointBase { public abstract Task<TResponse> HandleAsync( CancellationToken cancellationToken = default ); } - public abstract class WithoutResult : BaseRoute + public abstract class WithoutResult : INT_EndpointBase { public abstract Task HandleAsync( CancellationToken cancellationToken = default ); } - public abstract class WithActionResult<TResponse> : BaseRoute + public abstract class WithActionResult<TResponse> : INT_EndpointBase { public abstract Task<ActionResult<TResponse>> HandleAsync( CancellationToken cancellationToken = default ); } - public abstract class WithActionResult : BaseRoute + public abstract class WithActionResult : INT_EndpointBase { public abstract Task<ActionResult> HandleAsync( CancellationToken cancellationToken = default diff --git a/code/api/src/Endpoints/Internal/RouteBaseSync.cs b/code/api/src/Endpoints/Internal/RouteBaseSync.cs index 173999d..9d9bd5a 100644 --- a/code/api/src/Endpoints/Internal/RouteBaseSync.cs +++ b/code/api/src/Endpoints/Internal/RouteBaseSync.cs @@ -7,22 +7,22 @@ public static class RouteBaseSync { public static class WithRequest<TRequest> { - public abstract class WithResult<TResponse> : BaseRoute + public abstract class WithResult<TResponse> : INT_EndpointBase { public abstract TResponse Handle(TRequest request); } - public abstract class WithoutResult : BaseRoute + public abstract class WithoutResult : INT_EndpointBase { public abstract void Handle(TRequest request); } - public abstract class WithActionResult<TResponse> : BaseRoute + public abstract class WithActionResult<TResponse> : INT_EndpointBase { public abstract ActionResult<TResponse> Handle(TRequest request); } - public abstract class WithActionResult : BaseRoute + public abstract class WithActionResult : INT_EndpointBase { public abstract ActionResult Handle(TRequest request); } @@ -30,22 +30,22 @@ public static class RouteBaseSync public static class WithoutRequest { - public abstract class WithResult<TResponse> : BaseRoute + public abstract class WithResult<TResponse> : INT_EndpointBase { public abstract TResponse Handle(); } - public abstract class WithoutResult : BaseRoute + public abstract class WithoutResult : INT_EndpointBase { public abstract void Handle(); } - public abstract class WithActionResult<TResponse> : BaseRoute + public abstract class WithActionResult<TResponse> : INT_EndpointBase { public abstract ActionResult<TResponse> Handle(); } - public abstract class WithActionResult : BaseRoute + public abstract class WithActionResult : INT_EndpointBase { public abstract ActionResult Handle(); } diff --git a/code/api/src/Endpoints/V1/ApiTokens/CreateTokenRoute.cs b/code/api/src/Endpoints/V1/ApiTokens/CreateTokenRoute.cs index 2086619..60b00ff 100644 --- a/code/api/src/Endpoints/V1/ApiTokens/CreateTokenRoute.cs +++ b/code/api/src/Endpoints/V1/ApiTokens/CreateTokenRoute.cs @@ -23,13 +23,13 @@ public class CreateTokenRoute : RouteBaseSync.WithRequest<ApiAccessToken.ApiAcce [ApiVersion(ApiSpecV1.VERSION_STRING)] [HttpPost("~/v{version:apiVersion}/api-tokens/create")] [ProducesResponseType(200, Type = typeof(string))] - [ProducesResponseType(404, Type = typeof(ErrorResult))] + [ProducesResponseType(404, Type = typeof(KnownProblemModel))] public override ActionResult Handle(ApiAccessToken.ApiAccessTokenDto request) { var user = _context.Users.SingleOrDefault(c => c.Id == LoggedInUser.Id); if (user == default) { - return NotFound(new ErrorResult("User does not exist")); + return NotFound(new KnownProblemModel("User does not exist")); } var token_entropy = _configuration.APP_AES_KEY; diff --git a/code/api/src/Endpoints/V1/BaseRoute.cs b/code/api/src/Endpoints/V1/BaseRoute.cs deleted file mode 100644 index e7d72ac..0000000 --- a/code/api/src/Endpoints/V1/BaseRoute.cs +++ /dev/null @@ -1,39 +0,0 @@ -using System.Net.Http.Headers; - -namespace IOL.GreatOffice.Api.Endpoints.V1; - -/// <inheritdoc /> -[ApiVersion(ApiSpecV1.VERSION_STRING)] -[Authorize(AuthenticationSchemes = AuthSchemes)] -[ApiController] -public class BaseRoute : ControllerBase -{ - private const string AuthSchemes = CookieAuthenticationDefaults.AuthenticationScheme + "," + AppConstants.BASIC_AUTH_SCHEME; - - /// <summary> - /// User data for the currently logged on user. - /// </summary> - protected LoggedInUserModel LoggedInUser => new() { - Username = User.FindFirstValue(AppClaims.NAME), - Id = User.FindFirstValue(AppClaims.USER_ID).AsGuid(), - }; - - protected bool IsApiCall() { - if (!Request.Headers.ContainsKey("Authorization")) return false; - try { - var authHeader = AuthenticationHeaderValue.Parse(Request.Headers["Authorization"]); - if (authHeader.Parameter == null) return false; - } catch { - return false; - } - - return true; - } - - protected bool HasApiPermission(string permission_key) { - var permission_claim = User.Claims.SingleOrDefault(c => c.Type == permission_key); - return permission_claim is { - Value: "True" - }; - } -} diff --git a/code/api/src/Endpoints/V1/Entries/CreateEntryRoute.cs b/code/api/src/Endpoints/V1/Entries/CreateEntryRoute.cs index 362e430..854ff59 100644 --- a/code/api/src/Endpoints/V1/Entries/CreateEntryRoute.cs +++ b/code/api/src/Endpoints/V1/Entries/CreateEntryRoute.cs @@ -16,27 +16,28 @@ public class CreateEntryRoute : RouteBaseSync.WithRequest<TimeEntry.TimeEntryDto [ApiVersion(ApiSpecV1.VERSION_STRING)] [BasicAuthentication(AppConstants.TOKEN_ALLOW_CREATE)] [ProducesResponseType(200)] - [ProducesResponseType(400, Type = typeof(ErrorResult))] - [ProducesResponseType(404, Type = typeof(ErrorResult))] + [ProducesResponseType(400, Type = typeof(KnownProblemModel))] + [ProducesResponseType(404, Type = typeof(KnownProblemModel))] [HttpPost("~/v{version:apiVersion}/entries/create")] public override ActionResult<TimeEntry.TimeEntryDto> Handle(TimeEntry.TimeEntryDto timeEntryTimeEntryDto) { if (timeEntryTimeEntryDto.Stop == default) { - return BadRequest(new ErrorResult("Invalid form", "A stop date is required")); + return BadRequest(new KnownProblemModel("Invalid form", "A stop date is required")); } if (timeEntryTimeEntryDto.Start == default) { - return BadRequest(new ErrorResult("Invalid form", "A start date is required")); + return BadRequest(new KnownProblemModel("Invalid form", "A start date is required")); } if (timeEntryTimeEntryDto.Category == default) { - return BadRequest(new ErrorResult("Invalid form", "A category is required")); + return BadRequest(new KnownProblemModel("Invalid form", "A category is required")); } var category = _context.TimeCategories .Where(c => c.UserId == LoggedInUser.Id) .SingleOrDefault(c => c.Id == timeEntryTimeEntryDto.Category.Id); + if (category == default) { - return NotFound(new ErrorResult("Not found", $"Could not find category {timeEntryTimeEntryDto.Category.Name}")); + return NotFound(new KnownProblemModel("Not found", $"Could not find category {timeEntryTimeEntryDto.Category.Name}")); } var entry = new TimeEntry(LoggedInUser.Id) { @@ -52,7 +53,7 @@ public class CreateEntryRoute : RouteBaseSync.WithRequest<TimeEntry.TimeEntryDto .Where(c => timeEntryTimeEntryDto.Labels.Select(p => p.Id).Contains(c.Id)) .ToList(); if (labels.Count != timeEntryTimeEntryDto.Labels.Count) { - return NotFound(new ErrorResult("Not found", "Could not find all of the specified labels")); + return NotFound(new KnownProblemModel("Not found", "Could not find all of the specified labels")); } entry.Labels = labels; diff --git a/code/api/src/Endpoints/V1/Entries/EntryQueryRoute.cs b/code/api/src/Endpoints/V1/Entries/EntryQueryRoute.cs index d431ac5..ec6003c 100644 --- a/code/api/src/Endpoints/V1/Entries/EntryQueryRoute.cs +++ b/code/api/src/Endpoints/V1/Entries/EntryQueryRoute.cs @@ -20,7 +20,7 @@ public class EntryQueryRoute : RouteBaseSync.WithRequest<EntryQueryPayload>.With [BasicAuthentication(AppConstants.TOKEN_ALLOW_READ)] [HttpPost("~/v{version:apiVersion}/entries/query")] [ProducesResponseType(204)] - [ProducesResponseType(400, Type = typeof(ErrorResult))] + [ProducesResponseType(400, Type = typeof(KnownProblemModel))] [ProducesResponseType(200, Type = typeof(EntryQueryResponse))] public override ActionResult<EntryQueryResponse> Handle(EntryQueryPayload entryQuery) { var result = new TimeQueryDto(); @@ -142,19 +142,19 @@ public class EntryQueryRoute : RouteBaseSync.WithRequest<EntryQueryPayload>.With break; case TimeEntryQueryDuration.DATE_RANGE: if (entryQuery.DateRange.From == default) { - return BadRequest(new ErrorResult("Invalid query", "From date cannot be empty")); + return BadRequest(new KnownProblemModel("Invalid query", "From date cannot be empty")); } var fromDate = DateTime.SpecifyKind(entryQuery.DateRange.From, DateTimeKind.Utc); if (entryQuery.DateRange.To == default) { - return BadRequest(new ErrorResult("Invalid query", "To date cannot be empty")); + return BadRequest(new KnownProblemModel("Invalid query", "To date cannot be empty")); } var toDate = DateTime.SpecifyKind(entryQuery.DateRange.To, DateTimeKind.Utc); if (DateTime.Compare(fromDate, toDate) > 0) { - return BadRequest(new ErrorResult("Invalid query", "To date cannot be less than From date")); + return BadRequest(new KnownProblemModel("Invalid query", "To date cannot be less than From date")); } var baseDateRangeEntries = baseQuery diff --git a/code/api/src/Data/Dtos/TimeQueryDto.cs b/code/api/src/Endpoints/V1/Entries/TimeQueryDto.cs index f734cb1..6c199d8 100644 --- a/code/api/src/Data/Dtos/TimeQueryDto.cs +++ b/code/api/src/Endpoints/V1/Entries/TimeQueryDto.cs @@ -1,5 +1,5 @@ -namespace IOL.GreatOffice.Api.Data.Dtos; +namespace IOL.GreatOffice.Api.Endpoints.V1.Entries; public class TimeQueryDto { diff --git a/code/api/src/Endpoints/V1/Entries/UpdateEntryRoute.cs b/code/api/src/Endpoints/V1/Entries/UpdateEntryRoute.cs index ac233e0..09e3b9c 100644 --- a/code/api/src/Endpoints/V1/Entries/UpdateEntryRoute.cs +++ b/code/api/src/Endpoints/V1/Entries/UpdateEntryRoute.cs @@ -16,7 +16,7 @@ public class UpdateEntryRoute : RouteBaseSync.WithRequest<TimeEntry.TimeEntryDto [ApiVersion(ApiSpecV1.VERSION_STRING)] [BasicAuthentication(AppConstants.TOKEN_ALLOW_UPDATE)] [HttpPost("~/v{version:apiVersion}/entries/update")] - [ProducesResponseType(404, Type = typeof(ErrorResult))] + [ProducesResponseType(404, Type = typeof(KnownProblemModel))] [ProducesResponseType(200, Type = typeof(TimeEntry.TimeEntryDto))] public override ActionResult<TimeEntry.TimeEntryDto> Handle(TimeEntry.TimeEntryDto timeEntryTimeEntryDto) { var entry = _context.TimeEntries @@ -32,7 +32,7 @@ public class UpdateEntryRoute : RouteBaseSync.WithRequest<TimeEntry.TimeEntryDto .Where(c => c.UserId == LoggedInUser.Id) .SingleOrDefault(c => c.Id == timeEntryTimeEntryDto.Category.Id); if (category == default) { - return NotFound(new ErrorResult("Not found", $"Could not find category {timeEntryTimeEntryDto.Category.Name}")); + return NotFound(new KnownProblemModel("Not found", $"Could not find category {timeEntryTimeEntryDto.Category.Name}")); } entry.Start = timeEntryTimeEntryDto.Start.ToUniversalTime(); diff --git a/code/api/src/Endpoints/V1/RouteBaseAsync.cs b/code/api/src/Endpoints/V1/RouteBaseAsync.cs index 1d179f7..a75e9da 100644 --- a/code/api/src/Endpoints/V1/RouteBaseAsync.cs +++ b/code/api/src/Endpoints/V1/RouteBaseAsync.cs @@ -7,7 +7,7 @@ public static class RouteBaseAsync { public static class WithRequest<TRequest> { - public abstract class WithResult<TResponse> : BaseRoute + public abstract class WithResult<TResponse> : V1_EndpointBase { public abstract Task<TResponse> HandleAsync( TRequest request, @@ -15,7 +15,7 @@ public static class RouteBaseAsync ); } - public abstract class WithoutResult : BaseRoute + public abstract class WithoutResult : V1_EndpointBase { public abstract Task HandleAsync( TRequest request, @@ -23,7 +23,7 @@ public static class RouteBaseAsync ); } - public abstract class WithActionResult<TResponse> : BaseRoute + public abstract class WithActionResult<TResponse> : V1_EndpointBase { public abstract Task<ActionResult<TResponse>> HandleAsync( TRequest request, @@ -31,7 +31,7 @@ public static class RouteBaseAsync ); } - public abstract class WithActionResult : BaseRoute + public abstract class WithActionResult : V1_EndpointBase { public abstract Task<ActionResult> HandleAsync( TRequest request, @@ -42,28 +42,28 @@ public static class RouteBaseAsync public static class WithoutRequest { - public abstract class WithResult<TResponse> : BaseRoute + public abstract class WithResult<TResponse> : V1_EndpointBase { public abstract Task<TResponse> HandleAsync( CancellationToken cancellationToken = default ); } - public abstract class WithoutResult : BaseRoute + public abstract class WithoutResult : V1_EndpointBase { public abstract Task HandleAsync( CancellationToken cancellationToken = default ); } - public abstract class WithActionResult<TResponse> : BaseRoute + public abstract class WithActionResult<TResponse> : V1_EndpointBase { public abstract Task<ActionResult<TResponse>> HandleAsync( CancellationToken cancellationToken = default ); } - public abstract class WithActionResult : BaseRoute + public abstract class WithActionResult : V1_EndpointBase { public abstract Task<ActionResult> HandleAsync( CancellationToken cancellationToken = default diff --git a/code/api/src/Endpoints/V1/RouteBaseSync.cs b/code/api/src/Endpoints/V1/RouteBaseSync.cs index cb27c14..6a86074 100644 --- a/code/api/src/Endpoints/V1/RouteBaseSync.cs +++ b/code/api/src/Endpoints/V1/RouteBaseSync.cs @@ -7,22 +7,22 @@ public static class RouteBaseSync { public static class WithRequest<TRequest> { - public abstract class WithResult<TResponse> : BaseRoute + public abstract class WithResult<TResponse> : V1_EndpointBase { public abstract TResponse Handle(TRequest request); } - public abstract class WithoutResult : BaseRoute + public abstract class WithoutResult : V1_EndpointBase { public abstract void Handle(TRequest request); } - public abstract class WithActionResult<TResponse> : BaseRoute + public abstract class WithActionResult<TResponse> : V1_EndpointBase { public abstract ActionResult<TResponse> Handle(TRequest request); } - public abstract class WithActionResult : BaseRoute + public abstract class WithActionResult : V1_EndpointBase { public abstract ActionResult Handle(TRequest request); } @@ -30,22 +30,22 @@ public static class RouteBaseSync public static class WithoutRequest { - public abstract class WithResult<TResponse> : BaseRoute + public abstract class WithResult<TResponse> : V1_EndpointBase { public abstract TResponse Handle(); } - public abstract class WithoutResult : BaseRoute + public abstract class WithoutResult : V1_EndpointBase { public abstract void Handle(); } - public abstract class WithActionResult<TResponse> : BaseRoute + public abstract class WithActionResult<TResponse> : V1_EndpointBase { public abstract ActionResult<TResponse> Handle(); } - public abstract class WithActionResult : BaseRoute + public abstract class WithActionResult : V1_EndpointBase { public abstract ActionResult Handle(); } diff --git a/code/api/src/Endpoints/V1/V1_EndpointBase.cs b/code/api/src/Endpoints/V1/V1_EndpointBase.cs new file mode 100644 index 0000000..08ce4ab --- /dev/null +++ b/code/api/src/Endpoints/V1/V1_EndpointBase.cs @@ -0,0 +1,29 @@ +using System.Net.Http.Headers; + +namespace IOL.GreatOffice.Api.Endpoints.V1; + +[ApiVersion(ApiSpecV1.VERSION_STRING)] +[Authorize(AuthenticationSchemes = AuthSchemes)] +public class V1_EndpointBase : EndpointBase +{ + private const string AuthSchemes = CookieAuthenticationDefaults.AuthenticationScheme + "," + AppConstants.BASIC_AUTH_SCHEME; + + protected bool IsApiCall() { + if (!Request.Headers.ContainsKey("Authorization")) return false; + try { + var authHeader = AuthenticationHeaderValue.Parse(Request.Headers["Authorization"]); + if (authHeader.Parameter == null) return false; + } catch { + return false; + } + + return true; + } + + protected bool HasApiPermission(string permission_key) { + var permission_claim = User.Claims.SingleOrDefault(c => c.Type == permission_key); + return permission_claim is { + Value: "True" + }; + } +}
\ No newline at end of file diff --git a/code/api/src/IOL.GreatOffice.Api.csproj b/code/api/src/IOL.GreatOffice.Api.csproj index 1ffa04b..bb8c122 100644 --- a/code/api/src/IOL.GreatOffice.Api.csproj +++ b/code/api/src/IOL.GreatOffice.Api.csproj @@ -13,6 +13,7 @@ <PackageReference Include="Duende.IdentityServer" Version="6.1.2" /> <PackageReference Include="Duende.IdentityServer.EntityFramework.Storage" Version="6.1.2" /> <PackageReference Include="EFCore.NamingConventions" Version="6.0.0" /> + <PackageReference Include="FastEndpoints" Version="5.2.1" /> <PackageReference Include="IOL.Helpers" Version="3.1.0" /> <PackageReference Include="Microsoft.AspNetCore.DataProtection.EntityFrameworkCore" Version="6.0.7" /> <PackageReference Include="Microsoft.AspNetCore.Mvc.Versioning" Version="5.0.0" /> @@ -24,7 +25,6 @@ <PackageReference Include="Npgsql.EntityFrameworkCore.PostgreSQL" Version="6.0.6" /> <PackageReference Include="Quartz.Extensions.Hosting" Version="3.4.0" /> <PackageReference Include="Serilog.AspNetCore" Version="6.0.1" /> - <PackageReference Include="Serilog.Expressions" Version="3.4.0" /> <PackageReference Include="Serilog.Sinks.Seq" Version="5.1.1" /> <PackageReference Include="Swashbuckle.AspNetCore" Version="6.4.0" /> <PackageReference Include="Swashbuckle.AspNetCore.Annotations" Version="6.4.0" /> @@ -50,4 +50,8 @@ </Content> </ItemGroup> + <ItemGroup> + <Folder Include="Resources" /> + </ItemGroup> + </Project> diff --git a/code/api/src/Program.cs b/code/api/src/Program.cs index 9a6bc3f..aa7cae3 100644 --- a/code/api/src/Program.cs +++ b/code/api/src/Program.cs @@ -13,10 +13,8 @@ global using System.Text.Json; global using System.Text.Json.Serialization; global using IOL.GreatOffice.Api.Data.Database; global using IOL.GreatOffice.Api.Data.Exceptions; -global using IOL.GreatOffice.Api.Data.Dtos; global using IOL.GreatOffice.Api.Data.Enums; global using IOL.GreatOffice.Api.Data.Models; -global using IOL.GreatOffice.Api.Data.Results; global using IOL.Helpers; global using Microsoft.OpenApi.Models; global using Microsoft.AspNetCore.Authentication.Cookies; @@ -48,189 +46,194 @@ namespace IOL.GreatOffice.Api; public static class Program { - public static WebApplicationBuilder CreateAppBuilder(string[] args) { - var builder = WebApplication.CreateBuilder(args); - builder.Services.AddLogging(); - builder.Services.AddHttpClient(); - builder.Services.AddMemoryCache(); - builder.Services.AddScoped<MailService>(); - builder.Services.AddScoped<PasswordResetService>(); - builder.Services.AddScoped<UserService>(); - builder.Services.AddTransient<VaultService>(); - var vaultService = builder.Services.BuildServiceProvider().GetRequiredService<VaultService>(); - var configuration = vaultService.GetCurrentAppConfiguration(); - var logger = new LoggerConfiguration() - .Enrich.FromLogContext() - .ReadFrom.Configuration(builder.Configuration) - .WriteTo.Console(); + public static WebApplicationBuilder CreateAppBuilder(string[] args) { + var builder = WebApplication.CreateBuilder(args); + builder.Services.AddLogging(); + builder.Services.AddHttpClient(); + builder.Services.AddMemoryCache(); + builder.Services.AddScoped<MailService>(); + builder.Services.AddScoped<PasswordResetService>(); + builder.Services.AddScoped<UserService>(); + builder.Services.AddTransient<VaultService>(); + var vaultService = builder.Services.BuildServiceProvider().GetRequiredService<VaultService>(); + var configuration = vaultService.GetCurrentAppConfiguration(); + var logger = new LoggerConfiguration() + .Enrich.FromLogContext() + .ReadFrom.Configuration(builder.Configuration) + .WriteTo.Console(); - if (!builder.Environment.IsDevelopment() && configuration.SEQ_API_KEY.HasValue() && configuration.SEQ_API_URL.HasValue()) { - logger.WriteTo.Seq(configuration.SEQ_API_URL, apiKey: configuration.SEQ_API_KEY); - } + if (!builder.Environment.IsDevelopment() && configuration.SEQ_API_KEY.HasValue() && configuration.SEQ_API_URL.HasValue()) { + logger.WriteTo.Seq(configuration.SEQ_API_URL, apiKey: configuration.SEQ_API_KEY); + } - Log.Logger = logger.CreateLogger(); - Log.Information("Starting web host, " - + JsonSerializer.Serialize(configuration.GetPublicVersion(), - new JsonSerializerOptions() { - WriteIndented = true - })); - builder.Host.UseSerilog(Log.Logger); - builder.WebHost.ConfigureKestrel(kestrel => { - kestrel.AddServerHeader = false; - }); + Log.Logger = logger.CreateLogger(); + Log.Information("Starting web host, " + + JsonSerializer.Serialize(configuration.GetPublicVersion(), + new JsonSerializerOptions() { + WriteIndented = true + })); + builder.Host.UseSerilog(Log.Logger); + builder.WebHost.ConfigureKestrel(kestrel => { kestrel.AddServerHeader = false; }); - if (builder.Environment.IsDevelopment()) { - builder.Services.AddCors(); - } + if (builder.Environment.IsDevelopment()) { + builder.Services.AddCors(); + } - if (builder.Environment.IsProduction()) { - builder.Services.Configure<ForwardedHeadersOptions>(options => { - options.ForwardedHeaders = ForwardedHeaders.XForwardedProto; - }); - } - - builder.Services - .AddDataProtection() - .ProtectKeysWithCertificate(configuration.CERT1()) - .PersistKeysToDbContext<AppDbContext>(); + if (builder.Environment.IsProduction()) { + builder.Services.Configure<ForwardedHeadersOptions>(options => { options.ForwardedHeaders = ForwardedHeaders.XForwardedProto; }); + } - builder.Services.Configure(JsonSettings.Default); - builder.Services.AddQuartz(options => { - options.UsePersistentStore(o => { - o.UsePostgres(builder.Configuration.GetQuartzDatabaseConnectionString(vaultService.GetCurrentAppConfiguration)); - o.UseSerializer<QuartzJsonSerializer>(); - }); - options.UseMicrosoftDependencyInjectionJobFactory(); - options.RegisterJobs(); - }); - - builder.Services.AddQuartzHostedService(options => { - options.WaitForJobsToComplete = true; - }); + builder.Services.AddLocalization(options => { + options.ResourcesPath = "Resources"; + }); + builder.Services.AddRequestLocalization(options => { + var supportedCultures = new[] {"en-gb", "no-nb"}; + options.SetDefaultCulture(supportedCultures[0]) + .AddSupportedCultures(supportedCultures) + .AddSupportedUICultures(supportedCultures); + options.ApplyCurrentCultureToResponseHeaders = true; + }); - builder.Services.AddAuthentication(options => { - options.DefaultScheme = CookieAuthenticationDefaults.AuthenticationScheme; - options.DefaultChallengeScheme = CookieAuthenticationDefaults.AuthenticationScheme; - }) - .AddCookie(options => { - options.Cookie.Name = "go_session"; - options.Cookie.HttpOnly = true; - options.Cookie.IsEssential = true; - options.SlidingExpiration = true; - options.Events.OnRedirectToAccessDenied = - options.Events.OnRedirectToLogin = c => { - c.Response.StatusCode = StatusCodes.Status401Unauthorized; - return Task.FromResult<object>(null); - }; - }) - .AddScheme<AuthenticationSchemeOptions, BasicAuthenticationHandler>(AppConstants.BASIC_AUTH_SCHEME, default); + builder.Services + .AddDataProtection() + .ProtectKeysWithCertificate(configuration.CERT1()) + .PersistKeysToDbContext<AppDbContext>(); - builder.Services.AddDbContext<AppDbContext>(options => { - options.UseNpgsql(builder.Configuration.GetAppDatabaseConnectionString(vaultService.GetCurrentAppConfiguration), - npgsqlDbContextOptionsBuilder => { - npgsqlDbContextOptionsBuilder.UseQuerySplittingBehavior(QuerySplittingBehavior.SplitQuery); - npgsqlDbContextOptionsBuilder.EnableRetryOnFailure(5, TimeSpan.FromSeconds(10), default); - }) - .UseSnakeCaseNamingConvention(); - if (builder.Environment.IsDevelopment()) { - options.EnableSensitiveDataLogging(); - } - }); + builder.Services.Configure(JsonSettings.Default); + builder.Services.AddQuartz(options => { + options.UsePersistentStore(o => { + o.UsePostgres(builder.Configuration.GetQuartzDatabaseConnectionString(vaultService.GetCurrentAppConfiguration)); + o.UseSerializer<QuartzJsonSerializer>(); + }); + options.UseMicrosoftDependencyInjectionJobFactory(); + options.RegisterJobs(); + }); - builder.Services.AddApiVersioning(options => { - options.ApiVersionReader = new UrlSegmentApiVersionReader(); - options.ReportApiVersions = true; - options.AssumeDefaultVersionWhenUnspecified = false; - }); - builder.Services.AddVersionedApiExplorer(options => { - options.SubstituteApiVersionInUrl = true; - }); - builder.Services.AddSwaggerGen(options => { - options.IncludeXmlComments(Path.Combine(AppContext.BaseDirectory, Assembly.GetExecutingAssembly().GetName().Name + ".xml")); - options.UseApiEndpoints(); - options.OperationFilter<SwaggerDefaultValues>(); - options.SwaggerDoc(ApiSpecV1.Document.VersionName, ApiSpecV1.Document.OpenApiInfo); - options.AddSecurityDefinition("Basic", - new OpenApiSecurityScheme { - Name = "Authorization", - Type = SecuritySchemeType.ApiKey, - Scheme = "Basic", - BearerFormat = "Basic", - In = ParameterLocation.Header, - Description = - "Enter your token in the text input below.\r\n\r\nExample: \"Basic 12345abcdef\"", - }); + builder.Services.AddQuartzHostedService(options => { options.WaitForJobsToComplete = true; }); - options.AddSecurityRequirement(new OpenApiSecurityRequirement { - { - new OpenApiSecurityScheme { - Reference = new OpenApiReference { - Type = ReferenceType.SecurityScheme, - Id = "Basic" - } - }, - Array.Empty<string>() - } - }); - }); + builder.Services.AddAuthentication(options => { + options.DefaultScheme = CookieAuthenticationDefaults.AuthenticationScheme; + options.DefaultChallengeScheme = CookieAuthenticationDefaults.AuthenticationScheme; + }) + .AddCookie(options => { + options.Cookie.Name = "go_session"; + options.Cookie.HttpOnly = true; + options.Cookie.IsEssential = true; + options.SlidingExpiration = true; + options.Events.OnRedirectToAccessDenied = + options.Events.OnRedirectToLogin = c => { + c.Response.StatusCode = StatusCodes.Status401Unauthorized; + return Task.FromResult<object>(null); + }; + }) + .AddScheme<AuthenticationSchemeOptions, BasicAuthenticationHandler>(AppConstants.BASIC_AUTH_SCHEME, default); - builder.Services - .AddControllers() - .AddJsonOptions(JsonSettings.Default); + builder.Services.AddDbContext<AppDbContext>(options => { + options.UseNpgsql(builder.Configuration.GetAppDatabaseConnectionString(vaultService.GetCurrentAppConfiguration), + npgsqlDbContextOptionsBuilder => { + npgsqlDbContextOptionsBuilder.UseQuerySplittingBehavior(QuerySplittingBehavior.SplitQuery); + npgsqlDbContextOptionsBuilder.EnableRetryOnFailure(5, TimeSpan.FromSeconds(10), default); + }) + .UseSnakeCaseNamingConvention(); + if (builder.Environment.IsDevelopment()) { + options.EnableSensitiveDataLogging(); + } + }); - return builder; - } + builder.Services.AddApiVersioning(options => { + options.ApiVersionReader = new UrlSegmentApiVersionReader(); + options.ReportApiVersions = true; + options.AssumeDefaultVersionWhenUnspecified = false; + }); + builder.Services.AddVersionedApiExplorer(options => { options.SubstituteApiVersionInUrl = true; }); + builder.Services.AddSwaggerGen(options => { + options.IncludeXmlComments(Path.Combine(AppContext.BaseDirectory, Assembly.GetExecutingAssembly().GetName().Name + ".xml")); + options.UseApiEndpoints(); + options.OperationFilter<SwaggerDefaultValues>(); + options.SwaggerDoc(ApiSpecV1.Document.VersionName, ApiSpecV1.Document.OpenApiInfo); + options.AddSecurityDefinition("Basic", + new OpenApiSecurityScheme { + Name = "Authorization", + Type = SecuritySchemeType.ApiKey, + Scheme = "Basic", + BearerFormat = "Basic", + In = ParameterLocation.Header, + Description = + "Enter your token in the text input below.\r\n\r\nExample: \"Basic 12345abcdef\"", + }); - public static WebApplication CreateWebApplication(WebApplicationBuilder builder) { - var app = builder.Build(); + options.AddSecurityRequirement(new OpenApiSecurityRequirement { + { + new OpenApiSecurityScheme { + Reference = new OpenApiReference { + Type = ReferenceType.SecurityScheme, + Id = "Basic" + } + }, + Array.Empty<string>() + } + }); + }); - if (app.Environment.IsDevelopment()) { - app.UseDeveloperExceptionPage(); - app.UseCors(cors => { - cors.AllowAnyMethod(); - cors.AllowAnyHeader(); - cors.SetIsOriginAllowed((origin) => true); - cors.AllowCredentials(); - }); - } + builder.Services + .AddControllers() + .AddDataAnnotationsLocalization() + .AddJsonOptions(JsonSettings.Default); - if (app.Environment.IsProduction()) { - app.UseForwardedHeaders(); - } + return builder; + } - app.UseDefaultFiles() - .UseStaticFiles() - .UseRouting() - .UseSerilogRequestLogging() - .UseStatusCodePages() - .UseAuthentication() - .UseAuthorization() - .UseSwagger() - .UseSwaggerUI(options => { - options.SwaggerEndpoint(ApiSpecV1.Document.SwaggerPath, ApiSpecV1.Document.VersionName); - options.DocumentTitle = AppConstants.API_NAME; - }) - .UseEndpoints(endpoints => { - endpoints.MapControllers(); - }); - return app; - } + public static WebApplication CreateWebApplication(WebApplicationBuilder builder) { + var app = builder.Build(); - public static int Main(string[] args) { - try { - CreateWebApplication(CreateAppBuilder(args)).Run(); - return 0; - } catch (Exception ex) { - // This is subject to change in future .net versions, see https://github.com/dotnet/runtime/issues/60600. - if (ex.GetType().Name.Equals("StopTheHostException", StringComparison.Ordinal)) { - throw; - } + if (app.Environment.IsDevelopment()) { + app.UseDeveloperExceptionPage(); + app.UseCors(cors => { + cors.AllowAnyMethod(); + cors.AllowAnyHeader(); + cors.SetIsOriginAllowed(_ => true); + cors.AllowCredentials(); + }); + } - Log.Fatal(ex, "Unhandled exception"); - return 1; - } finally { - Log.Information("Shut down complete, flusing logs..."); - Log.CloseAndFlush(); - } - } -} + if (app.Environment.IsProduction()) { + app.UseForwardedHeaders(); + } + + + app.UseDefaultFiles() + .UseStaticFiles() + .UseRequestLocalization() + .UseRouting() + .UseSerilogRequestLogging() + .UseStatusCodePages() + .UseAuthentication() + .UseAuthorization() + .UseSwagger() + .UseSwaggerUI(options => { + options.SwaggerEndpoint(ApiSpecV1.Document.SwaggerPath, ApiSpecV1.Document.VersionName); + options.DocumentTitle = AppConstants.API_NAME; + }) + .UseEndpoints(endpoints => { endpoints.MapControllers(); }); + return app; + } + + public static int Main(string[] args) { + try { + CreateWebApplication(CreateAppBuilder(args)).Run(); + return 0; + } catch (Exception ex) { + // This is subject to change in future .net versions, see https://github.com/dotnet/runtime/issues/60600. + if (ex.GetType().Name.Equals("StopTheHostException", StringComparison.Ordinal)) { + throw; + } + + Log.Fatal(ex, "Unhandled exception"); + return 1; + } + finally { + Log.Information("Shut down complete, flusing logs..."); + Log.CloseAndFlush(); + } + } +}
\ No newline at end of file diff --git a/code/api/src/Services/VaultService.cs b/code/api/src/Services/VaultService.cs index 732911a..2f8d46e 100644 --- a/code/api/src/Services/VaultService.cs +++ b/code/api/src/Services/VaultService.cs @@ -31,7 +31,7 @@ public class VaultService cacheEntry => { cacheEntry.AbsoluteExpirationRelativeToNow = TimeSpan.FromSeconds(CACHE_TTL); var getSecretResponse = _client.GetFromJsonAsync<GetSecretResponse<T>>("/v1/kv/data/" + path).Result; - + if (getSecretResponse == null) { return default; } diff --git a/code/api/src/Utilities/ConfigurationExtensions.cs b/code/api/src/Utilities/ConfigurationExtensions.cs index 405c702..c95e293 100644 --- a/code/api/src/Utilities/ConfigurationExtensions.cs +++ b/code/api/src/Utilities/ConfigurationExtensions.cs @@ -9,15 +9,15 @@ public static class ConfigurationExtensions var user = configuration.DB_USER; var password = configuration.DB_PASSWORD; - var res = ""; + string result; if (config.GetValue<string>("ASPNETCORE_ENVIRONMENT") == "Development") { - res = $"Server={host};Port={port};Database={database};User Id={user};Password={password};Include Error Detail=true"; + result = $"Server={host};Port={port};Database={database};User Id={user};Password={password};Include Error Detail=true"; } else { - res = $"Server={host};Port={port};Database={database};User Id={user};Password={password}"; + result = $"Server={host};Port={port};Database={database};User Id={user};Password={password}"; } - Log.Debug("Using app database connection string: " + res); - return res; + Log.Debug("Using app database connection string: " + result); + return result; } public static string GetAppDatabaseConnectionString(this IConfiguration config, Func<AppConfiguration> configuration) { @@ -28,15 +28,15 @@ public static class ConfigurationExtensions var user = _configuration.DB_USER; var password = _configuration.DB_PASSWORD; - var res = ""; + string result; if (config.GetValue<string>("ASPNETCORE_ENVIRONMENT") == "Development") { - res = $"Server={host};Port={port};Database={database};User Id={user};Password={password};Include Error Detail=true"; + result = $"Server={host};Port={port};Database={database};User Id={user};Password={password};Include Error Detail=true"; } else { - res = $"Server={host};Port={port};Database={database};User Id={user};Password={password}"; + result = $"Server={host};Port={port};Database={database};User Id={user};Password={password}"; } - Log.Debug("Using app database connection string: " + res); - return res; + Log.Debug("Using app database connection string: " + result); + return result; } public static string GetQuartzDatabaseConnectionString(this IConfiguration config, AppConfiguration configuration) { @@ -46,15 +46,15 @@ public static class ConfigurationExtensions var user = configuration.QUARTZ_DB_USER; var password = configuration.QUARTZ_DB_PASSWORD; - var res = ""; + string result; if (config.GetValue<string>("ASPNETCORE_ENVIRONMENT") == "Development") { - res = $"Server={host};Port={port};Database={database};User Id={user};Password={password};Include Error Detail=true"; + result = $"Server={host};Port={port};Database={database};User Id={user};Password={password};Include Error Detail=true"; } else { - res = $"Server={host};Port={port};Database={database};User Id={user};Password={password}"; + result = $"Server={host};Port={port};Database={database};User Id={user};Password={password}"; } - Log.Debug("Using quartz database connection string: " + res); - return res; + Log.Debug("Using quartz database connection string: " + result); + return result; } public static string GetQuartzDatabaseConnectionString(this IConfiguration config, Func<AppConfiguration> configuration) { @@ -65,24 +65,21 @@ public static class ConfigurationExtensions var user = _configuration.QUARTZ_DB_USER; var password = _configuration.QUARTZ_DB_PASSWORD; - var res = ""; + string result; if (config.GetValue<string>("ASPNETCORE_ENVIRONMENT") == "Development") { - res = $"Server={host};Port={port};Database={database};User Id={user};Password={password};Include Error Detail=true"; + result = $"Server={host};Port={port};Database={database};User Id={user};Password={password};Include Error Detail=true"; } else { - res = $"Server={host};Port={port};Database={database};User Id={user};Password={password}"; + result = $"Server={host};Port={port};Database={database};User Id={user};Password={password}"; } - Log.Debug("Using quartz database connection string: " + res); - return res; + Log.Debug("Using quartz database connection string: " + result); + return result; } public static string GetVersion(this IConfiguration configuration) { var versionFilePath = Path.Combine(AppPaths.AppData.HostPath, "version.txt"); - if (File.Exists(versionFilePath)) { - var versionText = File.ReadAllText(versionFilePath); - return versionText + "-" + configuration.GetValue<string>("ASPNETCORE_ENVIRONMENT"); - } - - return "unknown-" + configuration.GetValue<string>("ASPNETCORE_ENVIRONMENT"); + if (!File.Exists(versionFilePath)) return "unknown-" + configuration.GetValue<string>("ASPNETCORE_ENVIRONMENT"); + var versionText = File.ReadAllText(versionFilePath); + return versionText + "-" + configuration.GetValue<string>("ASPNETCORE_ENVIRONMENT"); } } diff --git a/code/api/src/Utilities/SwaggerGenOptionsExtensions.cs b/code/api/src/Utilities/SwaggerGenOptionsExtensions.cs index a2dcf7a..0a7e07f 100644 --- a/code/api/src/Utilities/SwaggerGenOptionsExtensions.cs +++ b/code/api/src/Utilities/SwaggerGenOptionsExtensions.cs @@ -1,8 +1,8 @@ #nullable enable +using IOL.GreatOffice.Api.Endpoints.V1; using Microsoft.AspNetCore.Mvc.ApiExplorer; using Microsoft.AspNetCore.Mvc.Controllers; using Swashbuckle.AspNetCore.SwaggerGen; -using BaseRoute = IOL.GreatOffice.Api.Endpoints.V1.BaseRoute; namespace IOL.GreatOffice.Api.Utilities; @@ -10,7 +10,7 @@ public static class SwaggerGenOptionsExtensions { /// <summary> /// Updates Swagger document to support ApiEndpoints.<br/><br/> - /// For controllers inherited from <see cref="BaseRoute"/>:<br/> + /// For controllers inherited from <see cref="V1_EndpointBase"/>:<br/> /// - Replaces action Tag with <c>[namespace]</c><br/> /// </summary> public static void UseApiEndpoints(this SwaggerGenOptions options) { @@ -22,7 +22,7 @@ public static class SwaggerGenOptionsExtensions throw new InvalidOperationException($"Unable to determine tag for endpoint: {api.ActionDescriptor.DisplayName}"); } - if (actionDescriptor.ControllerTypeInfo.GetBaseTypesAndThis().Any(t => t == typeof(BaseRoute))) { + if (actionDescriptor.ControllerTypeInfo.GetBaseTypesAndThis().Any(t => t == typeof(V1_EndpointBase))) { return new[] { actionDescriptor.ControllerTypeInfo.Namespace?.Split('.').Last() }; |
