| | | 1 | | using System.Security.Claims; |
| | | 2 | | using Microsoft.AspNetCore.Authentication; |
| | | 3 | | using Microsoft.Extensions.Options; |
| | | 4 | | using ProjectTemplate.Web.Authentication.Options; |
| | | 5 | | |
| | | 6 | | namespace ProjectTemplate.Web.Authentication.Claims; |
| | | 7 | | |
| | | 8 | | /// <summary> |
| | | 9 | | /// Normalizes provider-specific claims into application-owned claim names. |
| | | 10 | | /// </summary> |
| | | 11 | | /// <param name="authenticationOptionsAccessor">The application authentication options accessor.</param> |
| | 96 | 12 | | public sealed class ApplicationClaimsTransformation( |
| | 96 | 13 | | IOptions<ApplicationAuthenticationOptions> authenticationOptionsAccessor) : IClaimsTransformation |
| | | 14 | | { |
| | 96 | 15 | | private readonly IOptions<ApplicationAuthenticationOptions> _authenticationOptionsAccessor = |
| | 96 | 16 | | authenticationOptionsAccessor ?? throw new ArgumentNullException(nameof(authenticationOptionsAccessor)); |
| | | 17 | | |
| | | 18 | | /// <inheritdoc /> |
| | | 19 | | public Task<ClaimsPrincipal> TransformAsync(ClaimsPrincipal principal) |
| | | 20 | | { |
| | 19 | 21 | | ArgumentNullException.ThrowIfNull(principal); |
| | | 22 | | |
| | 19 | 23 | | ApplicationClaimsTransformationOptions options = |
| | 19 | 24 | | _authenticationOptionsAccessor.Value.ClaimsTransformation; |
| | | 25 | | |
| | 19 | 26 | | if (!options.Enabled) |
| | | 27 | | { |
| | 1 | 28 | | return Task.FromResult(principal); |
| | | 29 | | } |
| | | 30 | | |
| | | 31 | | // Transformation may run more than once per request, and the incoming principal can be shared with other |
| | | 32 | | // components, so normalize copies instead of editing the caller's principal in place. |
| | 18 | 33 | | var transformed = new ClaimsPrincipal(); |
| | | 34 | | |
| | 72 | 35 | | foreach (ClaimsIdentity source in principal.Identities) |
| | | 36 | | { |
| | 18 | 37 | | ClaimsIdentity identity = source.Clone(); |
| | 18 | 38 | | ApplicationClaimMappingOptions mappings = ResolveMappings(options, identity.AuthenticationType); |
| | | 39 | | |
| | 18 | 40 | | NormalizeClaim(identity, ApplicationClaimTypes.Subject, mappings.Subject, options.RemoveOriginalClaims); |
| | 18 | 41 | | NormalizeClaim(identity, ApplicationClaimTypes.Name, mappings.Name, options.RemoveOriginalClaims); |
| | 18 | 42 | | NormalizeClaim(identity, ApplicationClaimTypes.Email, mappings.Email, options.RemoveOriginalClaims); |
| | 18 | 43 | | NormalizeClaim(identity, ApplicationClaimTypes.Role, mappings.Role, options.RemoveOriginalClaims); |
| | 18 | 44 | | NormalizeClaim(identity, ApplicationClaimTypes.Group, mappings.Group, options.RemoveOriginalClaims); |
| | 18 | 45 | | NormalizeClaim(identity, ApplicationClaimTypes.Permission, mappings.Permission, options.RemoveOriginalClaims |
| | | 46 | | |
| | 18 | 47 | | transformed.AddIdentity(WithNormalizedNameAndRoleClaimTypes(identity)); |
| | | 48 | | } |
| | | 49 | | |
| | 18 | 50 | | return Task.FromResult(transformed); |
| | | 51 | | } |
| | | 52 | | |
| | | 53 | | // Points Identity.Name, User.IsInRole, and [Authorize(Roles = "...")] at application:name and |
| | | 54 | | // application:role, so they keep working once RemoveOriginalClaims strips the provider claims. The original |
| | | 55 | | // claim type is kept only when the identity still carries it and has no normalized equivalent (for example, |
| | | 56 | | // when the provider's type is not in the configured mappings). |
| | | 57 | | private static ClaimsIdentity WithNormalizedNameAndRoleClaimTypes(ClaimsIdentity identity) |
| | | 58 | | { |
| | 18 | 59 | | string nameClaimType = ResolveClaimType(identity, ApplicationClaimTypes.Name, identity.NameClaimType); |
| | 18 | 60 | | string roleClaimType = ResolveClaimType(identity, ApplicationClaimTypes.Role, identity.RoleClaimType); |
| | | 61 | | |
| | 18 | 62 | | return string.Equals(nameClaimType, identity.NameClaimType, StringComparison.Ordinal) |
| | 18 | 63 | | && string.Equals(roleClaimType, identity.RoleClaimType, StringComparison.Ordinal) |
| | 18 | 64 | | ? identity |
| | 18 | 65 | | : new ClaimsIdentity(identity.Claims, identity.AuthenticationType, nameClaimType, roleClaimType) |
| | 18 | 66 | | { |
| | 18 | 67 | | Actor = identity.Actor, |
| | 18 | 68 | | BootstrapContext = identity.BootstrapContext, |
| | 18 | 69 | | Label = identity.Label |
| | 18 | 70 | | }; |
| | | 71 | | } |
| | | 72 | | |
| | | 73 | | private static string ResolveClaimType(ClaimsIdentity identity, string normalizedClaimType, string currentClaimType) |
| | | 74 | | { |
| | 36 | 75 | | bool hasNormalized = identity.HasClaim(claim => |
| | 36 | 76 | | string.Equals(claim.Type, normalizedClaimType, StringComparison.OrdinalIgnoreCase)); |
| | 36 | 77 | | bool hasCurrent = identity.HasClaim(claim => |
| | 36 | 78 | | string.Equals(claim.Type, currentClaimType, StringComparison.OrdinalIgnoreCase)); |
| | | 79 | | |
| | 36 | 80 | | return hasNormalized || !hasCurrent ? normalizedClaimType : currentClaimType; |
| | | 81 | | } |
| | | 82 | | |
| | | 83 | | private static ApplicationClaimMappingOptions ResolveMappings( |
| | | 84 | | ApplicationClaimsTransformationOptions options, |
| | | 85 | | string? authenticationType) |
| | | 86 | | { |
| | 18 | 87 | | return !string.IsNullOrWhiteSpace(authenticationType) |
| | 18 | 88 | | && options.ProviderMappings.TryGetValue(authenticationType, out ApplicationClaimMappingOptions? providerMapp |
| | 18 | 89 | | ? providerMappings |
| | 18 | 90 | | : options.DefaultMappings; |
| | | 91 | | } |
| | | 92 | | |
| | | 93 | | private static void NormalizeClaim( |
| | | 94 | | ClaimsIdentity identity, |
| | | 95 | | string normalizedClaimType, |
| | | 96 | | IEnumerable<string> sourceClaimTypes, |
| | | 97 | | bool removeOriginalClaims) |
| | | 98 | | { |
| | 108 | 99 | | var sourceTypes = sourceClaimTypes |
| | 108 | 100 | | .Where(claimType => !string.IsNullOrWhiteSpace(claimType)) |
| | 108 | 101 | | .ToHashSet(StringComparer.OrdinalIgnoreCase); |
| | | 102 | | |
| | 108 | 103 | | if (sourceTypes.Count == 0) |
| | | 104 | | { |
| | 0 | 105 | | return; |
| | | 106 | | } |
| | | 107 | | |
| | 108 | 108 | | var sourceClaims = identity.Claims |
| | 108 | 109 | | .Where(claim => sourceTypes.Contains(claim.Type)) |
| | 108 | 110 | | .ToList(); |
| | | 111 | | |
| | 108 | 112 | | if (sourceClaims.Count == 0) |
| | | 113 | | { |
| | 64 | 114 | | return; |
| | | 115 | | } |
| | | 116 | | |
| | 176 | 117 | | foreach (Claim sourceClaim in sourceClaims) |
| | | 118 | | { |
| | 44 | 119 | | if (!HasClaim(identity, normalizedClaimType, sourceClaim.Value)) |
| | | 120 | | { |
| | 43 | 121 | | identity.AddClaim(new Claim( |
| | 43 | 122 | | normalizedClaimType, |
| | 43 | 123 | | sourceClaim.Value, |
| | 43 | 124 | | sourceClaim.ValueType, |
| | 43 | 125 | | sourceClaim.Issuer, |
| | 43 | 126 | | sourceClaim.OriginalIssuer)); |
| | | 127 | | } |
| | | 128 | | } |
| | | 129 | | |
| | 44 | 130 | | if (!removeOriginalClaims) |
| | | 131 | | { |
| | 39 | 132 | | return; |
| | | 133 | | } |
| | | 134 | | |
| | 20 | 135 | | foreach (Claim sourceClaim in sourceClaims) |
| | | 136 | | { |
| | 5 | 137 | | if (!string.Equals(sourceClaim.Type, normalizedClaimType, StringComparison.OrdinalIgnoreCase)) |
| | | 138 | | { |
| | 5 | 139 | | identity.RemoveClaim(sourceClaim); |
| | | 140 | | } |
| | | 141 | | } |
| | 5 | 142 | | } |
| | | 143 | | |
| | | 144 | | private static bool HasClaim( |
| | | 145 | | ClaimsIdentity identity, |
| | | 146 | | string claimType, |
| | | 147 | | string claimValue) |
| | | 148 | | { |
| | 44 | 149 | | return identity.Claims.Any(claim => |
| | 44 | 150 | | string.Equals(claim.Type, claimType, StringComparison.OrdinalIgnoreCase) |
| | 44 | 151 | | && string.Equals(claim.Value, claimValue, StringComparison.Ordinal)); |
| | | 152 | | } |
| | | 153 | | } |