| | | 1 | | using System.Security.Claims; |
| | | 2 | | using ProjectTemplate.Infrastructure.Data; |
| | | 3 | | using ProjectTemplate.Web.Authentication.Claims; |
| | | 4 | | |
| | | 5 | | namespace ProjectTemplate.Web.Accessors; |
| | | 6 | | |
| | | 7 | | /// <summary> |
| | | 8 | | /// An implementation of <see cref="ICurrentActorAccessor"/> that retrieves the current actor information from the HTTP |
| | | 9 | | /// </summary> |
| | | 10 | | /// <param name="httpContextAccessor"></param> |
| | 20 | 11 | | public sealed class HttpContextCurrentActorAccessor( |
| | 20 | 12 | | IHttpContextAccessor httpContextAccessor) |
| | | 13 | | : ICurrentActorAccessor |
| | | 14 | | { |
| | | 15 | | private const string _subjectClaimType = "sub"; |
| | | 16 | | private const string _unknownActor = "Unknown"; |
| | | 17 | | |
| | | 18 | | /// <summary> |
| | | 19 | | /// Accesses the current actor information from the HTTP context. It first attempts to retrieve the authenticated |
| | | 20 | | /// normalized application subject claim, then the provider subject claim, then falls back to the authenticated name |
| | | 21 | | /// IP address. If none are available, it returns "Unknown". |
| | | 22 | | /// </summary> |
| | | 23 | | public string CurrentActor |
| | | 24 | | { |
| | | 25 | | get |
| | | 26 | | { |
| | 10 | 27 | | HttpContext? httpContext = httpContextAccessor.HttpContext; |
| | | 28 | | |
| | 10 | 29 | | string? authenticatedActor = GetAuthenticatedActor(httpContext?.User); |
| | | 30 | | |
| | 10 | 31 | | if (!string.IsNullOrWhiteSpace(authenticatedActor)) |
| | | 32 | | { |
| | 6 | 33 | | return authenticatedActor; |
| | | 34 | | } |
| | | 35 | | |
| | 4 | 36 | | string? remoteIpAddress = httpContext?.Connection.RemoteIpAddress?.ToString(); |
| | | 37 | | |
| | 4 | 38 | | return !string.IsNullOrWhiteSpace(remoteIpAddress) |
| | 4 | 39 | | ? $"Remote IP: {remoteIpAddress}" |
| | 4 | 40 | | : _unknownActor; |
| | | 41 | | } |
| | | 42 | | } |
| | | 43 | | |
| | | 44 | | private static string? GetAuthenticatedActor(ClaimsPrincipal? user) |
| | | 45 | | { |
| | 10 | 46 | | if (user?.Identity?.IsAuthenticated != true) |
| | | 47 | | { |
| | 3 | 48 | | return null; |
| | | 49 | | } |
| | | 50 | | |
| | | 51 | | // Prefer the normalized application claim: when claims transformation removes the original claims, |
| | | 52 | | // the provider "sub" and name identifier claims are no longer present. |
| | 7 | 53 | | string? subject = GetClaimValue(user, ApplicationClaimTypes.Subject) |
| | 7 | 54 | | ?? GetClaimValue(user, _subjectClaimType); |
| | | 55 | | |
| | 7 | 56 | | if (!string.IsNullOrWhiteSpace(subject)) |
| | | 57 | | { |
| | 4 | 58 | | return $"Subject: {subject}"; |
| | | 59 | | } |
| | | 60 | | |
| | 3 | 61 | | string? nameIdentifier = GetClaimValue(user, ClaimTypes.NameIdentifier); |
| | | 62 | | |
| | 3 | 63 | | return !string.IsNullOrWhiteSpace(nameIdentifier) |
| | 3 | 64 | | ? $"Name Identifier: {nameIdentifier}" |
| | 3 | 65 | | : null; |
| | | 66 | | } |
| | | 67 | | |
| | | 68 | | private static string? GetClaimValue(ClaimsPrincipal user, string claimType) |
| | | 69 | | { |
| | 15 | 70 | | string? value = user.FindFirst(claimType)?.Value?.Trim(); |
| | | 71 | | |
| | 15 | 72 | | return string.IsNullOrWhiteSpace(value) ? null : value; |
| | | 73 | | } |
| | | 74 | | } |