Fixed a horrible password exposure (the exposed password is now changed and password is moved to configution file which has different values on the production server from source)

This commit is contained in:
Hamid Reza Mohammadi 2020-08-29 19:50:55 +04:30
parent 6cc34968b5
commit b83dfe3274
5 changed files with 54 additions and 60 deletions

View File

@ -3710,11 +3710,6 @@
<param name="format"></param>
<returns></returns>
</member>
<member name="P:RMuseum.Services.Implementation.MailKitEmailSender.SmptConfig">
<summary>
SmptConfig
</summary>
</member>
<member name="T:RMuseum.Services.Implementation.PictureFileService">
<summary>
manipulating picture files

View File

@ -1,33 +0,0 @@
using RSecurityBackend.Models.Mail;
using RSecurityBackend.Services.Implementation;
using System;
using System.Collections.Generic;
using System.Linq;
using System.Threading.Tasks;
namespace RMuseum.Services.Implementation
{
public class MailKitEmailSender : MailKitEmailSenderBase
{
/// <summary>
/// SmptConfig
/// </summary>
public override SmptConfig SmptConfig
{
get
{
return
new SmptConfig()
{
port = 25,
server = "ganjgah.ir",
smtpUsername = "noreply@ganjgah.ir",
smtpPassword = "sahY%6&$OnD67i0978",
from = "noreply@ganjgah.ir",
useSsl = false
};
}
}
}
}

View File

@ -25,5 +25,14 @@
"Secret": "k4Fy7pDsc0LgXQ8PCCfZtwmju5Ed8asc",
"DefaultTokenExpirationInSeconds": "2502000"
},
"SmptConfig": {
"Server": "smtp.gmail.com",
"Port": "465",
"UseSsl": "true",
"Username": "test@gmail.com",
"Password": "password",
"From": "test@gmail.com"
},
"AllowedHosts": "*"
}

View File

@ -2571,27 +2571,33 @@
<param name="context"></param>
<param name="configuration"></param>
</member>
<member name="T:RSecurityBackend.Services.Implementation.MailKitEmailSenderBase">
<member name="T:RSecurityBackend.Services.Implementation.MailKitEmailSender">
<summary>
mail sender using MailKit
</summary>
</member>
<member name="M:RSecurityBackend.Services.Implementation.MailKitEmailSenderBase.#ctor">
<member name="M:RSecurityBackend.Services.Implementation.MailKitEmailSender.#ctor(Microsoft.Extensions.Configuration.IConfiguration)">
<summary>
constructor
</summary>
<param name="configuration"></param>
</member>
<member name="P:RSecurityBackend.Services.Implementation.MailKitEmailSenderBase.Options">
<member name="P:RSecurityBackend.Services.Implementation.MailKitEmailSender.Configuration">
<summary>
Configuration
</summary>
</member>
<member name="P:RSecurityBackend.Services.Implementation.MailKitEmailSender.Options">
<summary>
options
</summary>
</member>
<member name="P:RSecurityBackend.Services.Implementation.MailKitEmailSenderBase.SmptConfig">
<member name="P:RSecurityBackend.Services.Implementation.MailKitEmailSender.SmptConfig">
<summary>
SmptConfig
</summary>
</member>
<member name="M:RSecurityBackend.Services.Implementation.MailKitEmailSenderBase.SendEmailAsync(System.String,System.String,System.String)">
<member name="M:RSecurityBackend.Services.Implementation.MailKitEmailSender.SendEmailAsync(System.String,System.String,System.String)">
<summary>
send email
</summary>
@ -2600,7 +2606,7 @@
<param name="message"></param>
<returns></returns>
</member>
<member name="M:RSecurityBackend.Services.Implementation.MailKitEmailSenderBase.Execute(RSecurityBackend.Models.Mail.SmptConfig,System.String,System.String,System.String)">
<member name="M:RSecurityBackend.Services.Implementation.MailKitEmailSender.Execute(RSecurityBackend.Models.Mail.SmptConfig,System.String,System.String,System.String)">
<summary>
</summary>

View File

@ -1,6 +1,6 @@
using MailKit.Net.Smtp;
using Microsoft.AspNetCore.Identity.UI.Services;
using Microsoft.Extensions.Options;
using Microsoft.Extensions.Configuration;
using MimeKit;
using RSecurityBackend.Models.Mail;
using System.Threading.Tasks;
@ -10,39 +10,56 @@ namespace RSecurityBackend.Services.Implementation
/// <summary>
/// mail sender using MailKit
/// </summary>
public class MailKitEmailSenderBase : IEmailSender
public class MailKitEmailSender : IEmailSender
{
/// <summary>
/// constructor
/// </summary>
public MailKitEmailSenderBase()
/// <param name="configuration"></param>
public MailKitEmailSender(IConfiguration configuration)
{
Configuration = configuration;
Options = SmptConfig;
}
/// <summary>
/// Configuration
/// </summary>
protected IConfiguration Configuration { get; }
/// <summary>
/// options
/// </summary>
public SmptConfig Options { get; } //set only via Secret Manager
private SmptConfig _SmptConfig = null;
/// <summary>
/// SmptConfig
/// </summary>
public virtual SmptConfig SmptConfig
public SmptConfig SmptConfig
{
get
{
return
if (_SmptConfig == null)
{
_SmptConfig =
new SmptConfig()
{
port = 465,
server = "smtp.gmail.com",
smtpUsername = "nonexistingganjoor@gmail.com",
smtpPassword = "APasswordHere",
from = "nonexistingganjoor@gmail.com",
useSsl = true
server = $"{Configuration.GetSection("SmptConfig")["Server"]}",
port = int.Parse($"{Configuration.GetSection("SmptConfig")["Port"]}"),
useSsl = bool.Parse($"{Configuration.GetSection("SmptConfig")["UseSsl"]}"),
smtpUsername = $"{ Configuration.GetSection("SmptConfig")["Username"] }",
smtpPassword = $"{Configuration.GetSection("SmptConfig")["Password"]}",
from = $"{ Configuration.GetSection("SmptConfig")["From"] }"
};
}
return _SmptConfig;
}
}
/// <summary>