Compare commits

..

8 Commits

Author SHA1 Message Date
khwezi c27aba1954 Merge pull request 'Forcing login https proto on redirect' (#77) from payments into master
Reviewed-on: #77
2026-06-05 06:40:33 +02:00
Khwezi Mngoma e646d16053 Forcing login https proto on redirect
continuous-integration/drone/pr Build is passing
2026-06-05 06:39:47 +02:00
khwezi 1c946dab26 Merge pull request 'Refactored security components' (#76) from payments into master
Reviewed-on: #76
2026-06-05 05:44:47 +02:00
Khwezi Mngoma 20c3ad9569 Refactored security components
continuous-integration/drone/pr Build is passing
2026-06-05 05:43:56 +02:00
khwezi 9977cf27b9 Merge pull request 'Added a redirect packet attachment to UI signout process' (#75) from payments into master
Reviewed-on: #75
2026-06-04 16:03:06 +02:00
Khwezi Mngoma cf7eed0603 Added a redirect packet attachment to UI signout process
continuous-integration/drone/pr Build is passing
2026-06-04 16:02:29 +02:00
khwezi 8e9ac1e1ad Merge pull request 'Added signout functionality for user authentik link' (#74) from payments into master
Reviewed-on: #74
2026-06-04 14:40:00 +02:00
Khwezi Mngoma fa79bd8021 Added signout functionality for user authentik link
continuous-integration/drone/pr Build is passing
2026-06-04 14:39:14 +02:00
3 changed files with 68 additions and 2 deletions
@@ -4,7 +4,11 @@ public sealed class AuthentikSettings
{ {
public string? Authority { get; set; } public string? Authority { get; set; }
public string? IntrospectionUrl { get; set; } public string? IntrospectionEndpoint { get; set; }
public string? MetadataEndpoint { get; set; }
public string? RevokationEndpoint { get; set; }
public string? ClientId { get; set; } public string? ClientId { get; set; }
+62 -1
View File
@@ -27,9 +27,11 @@ public static class Api
.AddOpenIdConnect(OpenIdConnectDefaults.AuthenticationScheme, options => .AddOpenIdConnect(OpenIdConnectDefaults.AuthenticationScheme, options =>
{ {
options.Authority = authOptions.Authority; options.Authority = authOptions.Authority;
options.MetadataAddress = authOptions.MetadataEndpoint;
options.ClientId = authOptions.ClientId; options.ClientId = authOptions.ClientId;
options.ClientSecret = authOptions.ClientSecret; options.ClientSecret = authOptions.ClientSecret;
options.SignedOutCallbackPath = "/signout-callback-oidc";
options.ResponseType = "code"; options.ResponseType = "code";
options.SaveTokens = true; options.SaveTokens = true;
@@ -39,6 +41,24 @@ public static class Api
options.Scope.Add("openid"); options.Scope.Add("openid");
options.Scope.Add("profile"); options.Scope.Add("profile");
options.Scope.Add("email"); options.Scope.Add("email");
options.Events = new OpenIdConnectEvents
{
OnRedirectToIdentityProvider = context =>
{
if (!string.IsNullOrEmpty(context.ProtocolMessage.RedirectUri) && context.ProtocolMessage.RedirectUri.StartsWith("http://", StringComparison.OrdinalIgnoreCase))
{
var uriBuilder = new UriBuilder(context.ProtocolMessage.RedirectUri)
{
Scheme = "https"
};
context.ProtocolMessage.RedirectUri = uriBuilder.Uri.ToString();
}
return Task.CompletedTask;
},
};
}); });
return services; return services;
@@ -57,7 +77,7 @@ public static class Api
.AddOAuth2Introspection(OAuth2IntrospectionDefaults.AuthenticationScheme, options => .AddOAuth2Introspection(OAuth2IntrospectionDefaults.AuthenticationScheme, options =>
{ {
options.Authority = authOptions.Authority; options.Authority = authOptions.Authority;
options.IntrospectionEndpoint = authOptions.IntrospectionUrl; options.IntrospectionEndpoint = authOptions.IntrospectionEndpoint;
options.ClientId = authOptions.ClientId; options.ClientId = authOptions.ClientId;
options.ClientSecret = authOptions.ClientSecret; options.ClientSecret = authOptions.ClientSecret;
@@ -79,6 +99,47 @@ public static class Api
return services; return services;
} }
public static WebApplication AddSecurityEndpoints(this WebApplication app)
{
app.MapGet("/login", async (HttpContext context, string redirectUri = "/") =>
{
await context.ChallengeAsync(OpenIdConnectDefaults.AuthenticationScheme, new AuthenticationProperties
{
RedirectUri = redirectUri,
});
});
app.MapGet("/logout", async (HttpContext context, IHttpClientFactory httpClientFactory, IOptions<AuthentikSettings> settings) =>
{
var authOptions = settings.Value;
var accessToken = await context.GetTokenAsync("access_token");
if (!string.IsNullOrEmpty(accessToken))
{
try
{
var client = httpClientFactory.CreateClient();
var requestContent = new FormUrlEncodedContent(new Dictionary<string, string>(StringComparer.Ordinal)
{
{ "token", accessToken },
{ "client_id", authOptions.ClientId! },
{ "client_secret", authOptions.ClientSecret! },
});
await client.PostAsync(authOptions.RevokationEndpoint, requestContent, context.RequestAborted);
}
catch { }
}
await context.SignOutAsync(CookieAuthenticationDefaults.AuthenticationScheme);
return Results.Redirect($"{authOptions.Authority}end-session/");
});
return app;
}
public static IServiceCollection AddApiServices(this IServiceCollection services, IConfiguration configuration) public static IServiceCollection AddApiServices(this IServiceCollection services, IConfiguration configuration)
{ {
services.AddHttpClient(); services.AddHttpClient();
@@ -38,6 +38,7 @@
<PackageReference Include="Microsoft.AspNetCore.Authentication.Certificate" Version="10.0.8" /> <PackageReference Include="Microsoft.AspNetCore.Authentication.Certificate" Version="10.0.8" />
<PackageReference Include="Microsoft.AspNetCore.Authentication.JwtBearer" Version="10.0.8" /> <PackageReference Include="Microsoft.AspNetCore.Authentication.JwtBearer" Version="10.0.8" />
<Using Include="Microsoft.AspNetCore.Authentication"/>
<Using Include="Microsoft.AspNetCore.Authentication.OpenIdConnect"/> <Using Include="Microsoft.AspNetCore.Authentication.OpenIdConnect"/>
<Using Include="Microsoft.AspNetCore.Authentication.Cookies"/> <Using Include="Microsoft.AspNetCore.Authentication.Cookies"/>
<Using Include="IdentityModel.AspNetCore.OAuth2Introspection"/> <Using Include="IdentityModel.AspNetCore.OAuth2Introspection"/>