| | | 1 | | using System.Text; |
| | | 2 | | using Syki.Back.Auth.Claims; |
| | | 3 | | using System.Security.Claims; |
| | | 4 | | using Microsoft.IdentityModel.Tokens; |
| | | 5 | | using System.IdentityModel.Tokens.Jwt; |
| | | 6 | | using Syki.Back.Features.Identity.SignIn; |
| | | 7 | | |
| | | 8 | | namespace Syki.Back.Features.Cross.SignIn; |
| | | 9 | | |
| | 344 | 10 | | public class SignInService( |
| | 344 | 11 | | SykiDbContext ctx, |
| | 344 | 12 | | AuthSettings settings, |
| | 344 | 13 | | IHttpContextAccessor httpCtx) : ISykiService |
| | | 14 | | { |
| | | 15 | | public async Task<SignInOut> SignIn(string email) |
| | | 16 | | { |
| | 252 | 17 | | var user = await ctx.Users.Where(u => u.Email == email).Select(x => new { x.Id, x.InstitutionId }).FirstAsync(); |
| | 252 | 18 | | var role = await ctx.GetUserRole(user.Id, user.InstitutionId); |
| | 252 | 19 | | var permissions = role.Permissions.Serialize(); |
| | | 20 | | |
| | 252 | 21 | | var claims = new List<Claim> |
| | 252 | 22 | | { |
| | 252 | 23 | | new(SykiClaims.UserId, user.Id.ToString()), |
| | 252 | 24 | | new(SykiClaims.UserPermissions, permissions), |
| | 252 | 25 | | new(SykiClaims.Jti, Guid.NewGuid().ToString()), |
| | 252 | 26 | | new(SykiClaims.InstitutionId, user.InstitutionId.ToString()), |
| | 252 | 27 | | }; |
| | | 28 | | |
| | 252 | 29 | | var identityClaims = new ClaimsIdentity(); |
| | 252 | 30 | | identityClaims.AddClaims(claims); |
| | | 31 | | |
| | 252 | 32 | | var key = Encoding.ASCII.GetBytes(settings.SecurityKey); |
| | 252 | 33 | | var expirationTime = settings.ExpirationTimeInMinutes; |
| | 252 | 34 | | var signingCredentials = new SigningCredentials( |
| | 252 | 35 | | new SymmetricSecurityKey(key), |
| | 252 | 36 | | SecurityAlgorithms.HmacSha256Signature |
| | 252 | 37 | | ); |
| | | 38 | | |
| | 252 | 39 | | var tokenDescriptor = new SecurityTokenDescriptor |
| | 252 | 40 | | { |
| | 252 | 41 | | Issuer = settings.Issuer, |
| | 252 | 42 | | Subject = identityClaims, |
| | 252 | 43 | | Audience = settings.Audience, |
| | 252 | 44 | | SigningCredentials = signingCredentials, |
| | 252 | 45 | | Expires = DateTime.UtcNow.AddMinutes(expirationTime), |
| | 252 | 46 | | }; |
| | | 47 | | |
| | 252 | 48 | | var tokenHandler = new JwtSecurityTokenHandler(); |
| | 252 | 49 | | var securityToken = tokenHandler.CreateToken(tokenDescriptor); |
| | | 50 | | |
| | 252 | 51 | | httpCtx.HttpContext.Response.AppendJWTCookie(tokenHandler.WriteToken(securityToken), settings); |
| | | 52 | | |
| | 252 | 53 | | return new SignInOut |
| | 252 | 54 | | { |
| | 252 | 55 | | UserId = user.Id, |
| | 252 | 56 | | InstitutionId = user.InstitutionId, |
| | 252 | 57 | | }; |
| | 252 | 58 | | } |
| | | 59 | | } |