using Application.Domain.Entities; using Infrastructure.Data; using Infrastructure.Email; using Infrastructure.Extensions; using Infrastructure.Sms; using Infrastructure.Web; using Microsoft.AspNetCore.Authentication; using Microsoft.AspNetCore.Authentication.Cookies; using Microsoft.AspNetCore.Hosting; using Microsoft.EntityFrameworkCore; using Microsoft.Extensions.Configuration; using Microsoft.Extensions.DependencyInjection; using System; using System.Collections.Generic; using System.Linq; using System.Threading.Tasks; namespace ManagementCenter { public class Startup : BaseStartup { public Startup(IConfiguration configuration, IWebHostEnvironment env) : base(configuration, env) { } public override void ConfigureServices(IServiceCollection services) { services.AddTransient(); services.AddTransient(); services.AddSignalR(o => o.EnableDetailedErrors = true); services.AddTransient(); base.ConfigureServices(services); } public override Task ValidatePrincipal(CookieValidatePrincipalContext arg) { return Task.Run(() => { var userRepo = arg.HttpContext.RequestServices.GetService>(); var userName = arg.Principal.Identity.Name; var userPermissions = userRepo.ReadOnlyTable().Where(o => o.UserName == userName) .SelectMany(o => o.UserRoles) .Select(o => o.Role) .SelectMany(o => o.RolePermissions) .Select(o => o.Permission.Number) .ToList(); var currentPermissions = arg.Principal.Claims.Where(o => o.Type == "Role").Select(o => o.Value).ToList(); if (!currentPermissions.SequenceEqual(userPermissions)) { arg.HttpContext.SignOutAsync(); arg.HttpContext.SignIn(userName, userPermissions, arg.Properties.IsPersistent); } }); } public override void OnModelCreating(ModelBuilder modelBuilder) { modelBuilder.Entity().HasOne(o => o.Parent).WithMany(o => o.Children).HasForeignKey(o => o.ParentId); modelBuilder.Entity().HasOne(o => o.Category).WithMany(o => o.Permissions).HasForeignKey(o => o.CategoryId); modelBuilder.Entity().HasOne(o => o.User).WithMany(o => o.UserRoles).HasForeignKey(o => o.UserId); modelBuilder.Entity().HasOne(o => o.Role).WithMany(o => o.UserRoles).HasForeignKey(o => o.RoleId); modelBuilder.Entity().HasOne(o => o.Role).WithMany(o => o.RolePermissions).HasForeignKey(o => o.RoleId); modelBuilder.Entity().HasOne(o => o.Permission).WithMany(o => o.RolePermissions).HasForeignKey(o => o.PermissionId); modelBuilder.Entity().HasIndex(o => o.UserName).IsUnique(); modelBuilder.Entity().HasIndex(o => o.Name).IsUnique(); modelBuilder.Entity().HasIndex(o => o.Number).IsUnique(); modelBuilder.Entity().HasIndex(o => o.Number).IsUnique(); modelBuilder.Entity().HasIndex(o => new { o.UserId, o.RoleId }).IsUnique(); modelBuilder.Entity().HasIndex(o => new { o.RoleId, o.PermissionId }).IsUnique(); } public override void Seed(DbContext dbContext, IServiceProvider serviceProvider, IConfiguration configuration) { dbContext.Set().Add(new PermissionCategory { Name = "配置", Number = "EFConfigurationValue", Permissions = new List { new Permission { Name = "查看配置", Number = "Read-EFConfigurationValue" }, new Permission { Name = "添加配置", Number = "Add-EFConfigurationValue" }, new Permission { Name = "修改配置", Number = "Edit-EFConfigurationValue" }, new Permission { Name = "删除配置", Number = "Delete-EFConfigurationValue" } } }); foreach (var item in dbContext.Model.GetEntityTypes()) { var type = item.ClrType; var name = type.GetDisplayName(); var number = type.Name; var category = new PermissionCategory { Name = name, Number = type.Name }; category.Permissions.Add(new Permission { Name = $"查看{name}", Number = $"Read-{number}" }); category.Permissions.Add(new Permission { Name = $"添加{name}", Number = $"Add-{number}" }); category.Permissions.Add(new Permission { Name = $"修改{name}", Number = $"Edit-{number}" }); category.Permissions.Add(new Permission { Name = $"删除{name}", Number = $"Delete-{number}" }); dbContext.Set().Add(category); } dbContext.SaveChanges(); var saRole = new Role { Name = "超级管理员", IsReadOnly = true }; var adminRole = new Role { Name = "管理员", IsReadOnly = true }; foreach (var item in dbContext.Set()) { saRole.RolePermissions.Add(new RolePermission { Permission = item, IsReadOnly = true }); if (!item.Name.Contains("删除")) { adminRole.RolePermissions.Add(new RolePermission { Permission = item, IsReadOnly = true }); } } dbContext.Set().Add(new User { UserName = "super", UserRoles = new List { new UserRole { Role = saRole } } }); var user1Id = dbContext.Set().Add(new User { UserName = "admin", UserRoles = new List { new UserRole { Role = adminRole } } }).Entity.Id; dbContext.SaveChanges(); } } }