< Summary

Information
Class: ProjectTemplate.Web.Controllers.ExternalController
Assembly: ProjectTemplate.Web
File(s): /home/runner/work/NetCoreApplicationTemplate/NetCoreApplicationTemplate/src/ProjectTemplate.Web/Controllers/ExternalController.cs
Line coverage
94%
Covered lines: 16
Uncovered lines: 1
Coverable lines: 17
Total lines: 64
Line coverage: 94.1%
Branch coverage
75%
Covered branches: 6
Total branches: 8
Branch coverage: 75%
Method coverage

Feature is only available for sponsors

Upgrade to PRO version

Metrics

MethodBranch coverage Crap Score Cyclomatic complexity Line coverage
.ctor(...)100%11100%
Challenge()75%8893.33%

File(s)

/home/runner/work/NetCoreApplicationTemplate/NetCoreApplicationTemplate/src/ProjectTemplate.Web/Controllers/ExternalController.cs

#LineLine coverage
 1using Microsoft.AspNetCore.Authentication;
 2using Microsoft.AspNetCore.Authorization;
 3using Microsoft.AspNetCore.Mvc;
 4using ProjectTemplate.Web.Authentication;
 5
 6namespace ProjectTemplate.Web.Controllers;
 7
 8/// <summary>
 9/// Provides controller actions for initiating external authentication challenges using configured authentication
 10/// schemes.
 11/// </summary>
 12/// <remarks>This controller is intended for use with external authentication providers such as OAuth or OpenID
 13/// Connect. It ensures that only local return URLs are accepted to mitigate open redirect vulnerabilities. The
 14/// controller should be used in scenarios where users need to authenticate via third-party identity
 15/// providers.</remarks>
 16/// <param name="schemeProvider">The authentication scheme provider used to retrieve available external authentication s
 717public sealed class ExternalController(IAuthenticationSchemeProvider schemeProvider) : Controller
 18{
 719    private readonly IAuthenticationSchemeProvider _schemeProvider = schemeProvider;
 20
 21    /// <summary>
 22    /// Initiates an external authentication challenge using the specified provider.
 23    /// </summary>
 24    /// <remarks>This method is typically used to start an OAuth or other external login flow. Only local
 25    /// return URLs are permitted to prevent open redirect vulnerabilities.</remarks>
 26    /// <param name="provider">The name of the external authentication provider to use. Cannot be null, empty, or whites
 27    /// <param name="returnUrl">The URL to redirect the user to after successful authentication. If null or empty, defau
 28    /// root ('/'). Must be a local URL.</param>
 29    /// <returns>An IActionResult that initiates the external authentication challenge or returns a BadRequest result if
 30    /// input is invalid.</returns>
 31    [HttpGet("/External/Challenge")]
 32    [AllowAnonymous]
 33    public async Task<IActionResult> Challenge(string provider, string? returnUrl = null)
 34    {
 735        if (string.IsNullOrWhiteSpace(provider))
 36        {
 037            return BadRequest();
 38        }
 39
 740        string safeReturnUrl = string.IsNullOrWhiteSpace(returnUrl) ? "/" : returnUrl;
 41
 742        if (!Url.IsLocalUrl(safeReturnUrl))
 43        {
 144            return BadRequest();
 45        }
 46
 47        // Only schemes offered on the login page may be challenged. This excludes the cookie session scheme, the
 48        // default authenticate, sign-in, and sign-out schemes, and any scheme registered without a display name.
 649        AuthenticationScheme? scheme = await ExternalAuthenticationProviderSchemes
 650            .FindSelectableSchemeAsync(_schemeProvider, provider);
 51
 652        if (scheme is null)
 53        {
 554            return BadRequest();
 55        }
 56
 157        AuthenticationProperties properties = new()
 158        {
 159            RedirectUri = safeReturnUrl
 160        };
 61
 162        return Challenge(properties, scheme.Name);
 763    }
 64}