Started improving server shares and general api controller structure
This commit is contained in:
@@ -4,6 +4,7 @@ using MoonCore.Attributes;
|
||||
using MoonlightServers.ApiServer.Database.Entities;
|
||||
using MoonlightServers.ApiServer.Interfaces;
|
||||
using MoonlightServers.ApiServer.Models;
|
||||
using MoonlightServers.Shared.Enums;
|
||||
using MoonlightServers.Shared.Models;
|
||||
|
||||
namespace MoonlightServers.ApiServer.Implementations.ServerAuthFilters;
|
||||
@@ -12,6 +13,8 @@ public class AdminAuthFilter : IServerAuthorizationFilter
|
||||
{
|
||||
private readonly IAuthorizationService AuthorizationService;
|
||||
|
||||
public int Priority => 0;
|
||||
|
||||
public AdminAuthFilter(IAuthorizationService authorizationService)
|
||||
{
|
||||
AuthorizationService = authorizationService;
|
||||
@@ -20,7 +23,8 @@ public class AdminAuthFilter : IServerAuthorizationFilter
|
||||
public async Task<ServerAuthorizationResult?> Process(
|
||||
ClaimsPrincipal user,
|
||||
Server server,
|
||||
Func<ServerSharePermission, bool>? filter = null
|
||||
string permissionId,
|
||||
ServerPermissionLevel requiredLevel
|
||||
)
|
||||
{
|
||||
var authResult = await AuthorizationService.AuthorizeAsync(
|
||||
|
||||
@@ -3,13 +3,21 @@ using MoonCore.Attributes;
|
||||
using MoonlightServers.ApiServer.Database.Entities;
|
||||
using MoonlightServers.ApiServer.Interfaces;
|
||||
using MoonlightServers.ApiServer.Models;
|
||||
using MoonlightServers.Shared.Enums;
|
||||
using MoonlightServers.Shared.Models;
|
||||
|
||||
namespace MoonlightServers.ApiServer.Implementations.ServerAuthFilters;
|
||||
|
||||
public class OwnerAuthFilter : IServerAuthorizationFilter
|
||||
{
|
||||
public Task<ServerAuthorizationResult?> Process(ClaimsPrincipal user, Server server, Func<ServerSharePermission, bool>? filter = null)
|
||||
public int Priority => 0;
|
||||
|
||||
public Task<ServerAuthorizationResult?> Process(
|
||||
ClaimsPrincipal user,
|
||||
Server server,
|
||||
string permissionId,
|
||||
ServerPermissionLevel requiredLevel
|
||||
)
|
||||
{
|
||||
var userIdValue = user.FindFirstValue("userId");
|
||||
|
||||
@@ -17,10 +25,10 @@ public class OwnerAuthFilter : IServerAuthorizationFilter
|
||||
return Task.FromResult<ServerAuthorizationResult?>(null);
|
||||
|
||||
var userId = int.Parse(userIdValue);
|
||||
|
||||
if(server.OwnerId != userId)
|
||||
|
||||
if (server.OwnerId != userId)
|
||||
return Task.FromResult<ServerAuthorizationResult?>(null);
|
||||
|
||||
|
||||
return Task.FromResult<ServerAuthorizationResult?>(
|
||||
ServerAuthorizationResult.Success()
|
||||
);
|
||||
|
||||
@@ -5,6 +5,7 @@ using MoonCore.Extended.Abstractions;
|
||||
using MoonlightServers.ApiServer.Database.Entities;
|
||||
using MoonlightServers.ApiServer.Interfaces;
|
||||
using MoonlightServers.ApiServer.Models;
|
||||
using MoonlightServers.Shared.Enums;
|
||||
using MoonlightServers.Shared.Models;
|
||||
|
||||
namespace MoonlightServers.ApiServer.Implementations.ServerAuthFilters;
|
||||
@@ -18,10 +19,13 @@ public class ShareAuthFilter : IServerAuthorizationFilter
|
||||
ShareRepository = shareRepository;
|
||||
}
|
||||
|
||||
public int Priority => 0;
|
||||
|
||||
public async Task<ServerAuthorizationResult?> Process(
|
||||
ClaimsPrincipal user,
|
||||
Server server,
|
||||
Func<ServerSharePermission, bool>? filter = null
|
||||
string permissionId,
|
||||
ServerPermissionLevel requiredLevel
|
||||
)
|
||||
{
|
||||
var userIdValue = user.FindFirstValue("userId");
|
||||
@@ -30,19 +34,24 @@ public class ShareAuthFilter : IServerAuthorizationFilter
|
||||
return null;
|
||||
|
||||
var userId = int.Parse(userIdValue);
|
||||
|
||||
|
||||
var share = await ShareRepository
|
||||
.Get()
|
||||
.FirstOrDefaultAsync(x => x.Server.Id == server.Id && x.UserId == userId);
|
||||
|
||||
if (share == null)
|
||||
return null;
|
||||
|
||||
if(filter == null)
|
||||
|
||||
if (string.IsNullOrEmpty(permissionId) || requiredLevel == ServerPermissionLevel.None)
|
||||
return ServerAuthorizationResult.Success(share);
|
||||
|
||||
if(share.Content.Permissions.Any(filter))
|
||||
|
||||
if (
|
||||
share.Content.Permissions.TryGetValue(permissionId, out var shareLevel) &&
|
||||
shareLevel >= requiredLevel
|
||||
)
|
||||
{
|
||||
return ServerAuthorizationResult.Success(share);
|
||||
}
|
||||
|
||||
return null;
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user