using Microsoft.AspNetCore.Authorization; using Microsoft.IdentityModel.Tokens; using System; using System.Collections.Generic; namespace EntrustSettle.AuthHelper { /// /// 必要参数类,类似一个订单信息 /// 继承 IAuthorizationRequirement,用于设计自定义权限处理器PermissionHandler /// 因为AuthorizationHandler 中的泛型参数 TRequirement 必须继承 IAuthorizationRequirement /// public class PermissionRequirement : IAuthorizationRequirement { /// /// 用户权限集合,一个订单包含了很多详情, /// 同理,一个网站的认证发行中,也有很多权限详情(这里是Role和URL的关系) /// public List Permissions { get; set; } /// /// 无权限action /// public string DeniedAction { get; set; } /// /// 认证授权类型 /// public string ClaimType { internal get; set; } /// /// 请求路径 /// public string LoginPath { get; set; } = "/Api/Login"; /// /// 发行人 /// public string Issuer { get; set; } /// /// 订阅人 /// public string Audience { get; set; } /// /// 过期时间 /// public TimeSpan Expiration { get; set; } /// /// 签名验证 /// public SigningCredentials SigningCredentials { get; set; } /// /// 构造 /// /// 拒约请求的url /// 权限集合 /// 声明类型 /// 发行人 /// 订阅人 /// 签名验证实体 /// 过期时间 public PermissionRequirement(string deniedAction, List permissions, string claimType, string issuer, string audience, SigningCredentials signingCredentials, TimeSpan expiration) { ClaimType = claimType; DeniedAction = deniedAction; Permissions = permissions; Issuer = issuer; Audience = audience; Expiration = expiration; SigningCredentials = signingCredentials; } } }