using Microsoft.AspNetCore.Identity; using Microsoft.EntityFrameworkCore; using RSecurityBackend.DbContext; using RSecurityBackend.Models.Auth.Db; using RSecurityBackend.Models.Auth.Memory; using RSecurityBackend.Models.Generic; using System; using System.Collections.Generic; using System.Linq; using System.Threading.Tasks; namespace RSecurityBackend.Services.Implementation { /// /// User Roles Service Implementation /// public class RoleServiceBase : IUserRoleService { /// /// returns all user roles /// /// public async Task> GetAllRoles() { try { RAppRole[] rolesInfo = await _roleManager.Roles.Include(r => r.Permissions).ToArrayAsync(); return new RServiceResult(rolesInfo); } catch (Exception exp) { return new RServiceResult(null, exp.ToString()); } } /// /// returns user role information /// /// /// public async Task> GetRoleInformation(string roleName) { try { RAppRole dbUserRoleInfo = await _roleManager.FindByNameAsync(roleName); return new RServiceResult(dbUserRoleInfo); } catch (Exception exp) { return new RServiceResult(null, exp.ToString()); } } /// /// modify existing user role /// /// /// /// public async Task> ModifyRole(string roleName, RAppRole updateRoleInfo) { try { RAppRole existingInfo = await _roleManager.FindByNameAsync(roleName); if (existingInfo == null) { return new RServiceResult(false, "role not found"); } if (existingInfo.Name != updateRoleInfo.Name) { RAppRole anotherWithSameName = await _roleManager.Roles.Where(g => g.Name == updateRoleInfo.Name && g.Id != existingInfo.Id).SingleOrDefaultAsync(); if (anotherWithSameName != null) { return new RServiceResult(false, "duplicated role name"); } existingInfo.Name = updateRoleInfo.Name; } existingInfo.Description = updateRoleInfo.Description; await _roleManager.UpdateAsync(existingInfo); return new RServiceResult(true); } catch (Exception exp) { return new RServiceResult(false, exp.ToString()); } } /// /// delete user role /// /// /// true if succeeds public async Task> DeleteRole(string roleName) { try { RAppRole existingInfo = await _roleManager.FindByNameAsync(roleName); if (existingInfo != null) { await _roleManager.DeleteAsync(existingInfo); return new RServiceResult(true); } return new RServiceResult(false, "role not found."); } catch (Exception exp) { return new RServiceResult(false, exp.ToString()); } } /// /// adds a new user role /// /// new role info /// update user role info (id) public async Task> AddRole(RAppRole newRoleInfo) { try { RAppRole existingRole = await _roleManager.Roles.Where(g => g.Name == newRoleInfo.Name).SingleOrDefaultAsync(); if(existingRole != null) { return new RServiceResult(null, "Role name is in use"); } await _roleManager.CreateAsync(newRoleInfo); return new RServiceResult(newRoleInfo); } catch (Exception exp) { return new RServiceResult(null, exp.ToString()); } } /// /// Has role specified permission /// /// /// /// /// public async Task> HasPermission(string roleName, string securableItemShortName, string operationShortName) { try { RAppRole roleByName = await _roleManager.FindByNameAsync(roleName); if (roleByName == null) { return new RServiceResult(false, "role not found"); } RAppRole role = await _roleManager.Roles.Include(g => g.Permissions) .Where(g => g.Id == roleByName.Id) .SingleOrDefaultAsync(); return new RServiceResult( role.Permissions.Where(p => p.SecurableItemShortName == securableItemShortName && p.OperationShortName == operationShortName) .SingleOrDefault() != null ); } catch(Exception exp) { return new RServiceResult(false, exp.ToString()); } } /// /// gets list of SecurableItem, should be reimplemented in end user applications /// /// public virtual SecurableItem[] GetSecurableItems() { return SecurableItem.Items; } /// /// Lists role permissions /// /// /// public async Task> GetRoleSecurableItemsStatus(string roleName) { try { RAppRole roleByName = await _roleManager.FindByNameAsync(roleName); if (roleByName == null) { return new RServiceResult(null, "role not found"); } RAppRole role = await _roleManager.Roles.Include(g => g.Permissions).Where(g => g.Id == roleByName.Id).SingleOrDefaultAsync(); List securableItems = new List(); foreach(SecurableItem templateItem in GetSecurableItems()) { SecurableItem item = new SecurableItem() { ShortName = templateItem.ShortName, Description = templateItem.Description }; List operations = new List(); foreach(SecurableItemOperation operation in templateItem.Operations) { operations.Add( new SecurableItemOperation() { ShortName = operation.ShortName, Description = operation.Description, Prerequisites = operation.Prerequisites, Status = role.Permissions.Where(p => p.SecurableItemShortName == templateItem.ShortName && p.OperationShortName == operation.ShortName).SingleOrDefault() != null } ); } item.Operations = operations.ToArray(); securableItems.Add(item); } return new RServiceResult(securableItems.ToArray()); } catch (Exception exp) { return new RServiceResult(null, exp.ToString()); } } /// /// Saves role permissions /// /// /// /// public async Task> SetRoleSecurableItemsStatus(string roleName, SecurableItem[] securableItems) { try { RAppRole roleByName = await _roleManager.FindByNameAsync(roleName); if (roleByName == null) { return new RServiceResult(false, "role not found"); } RAppRole role = await _roleManager.Roles.Include(g => g.Permissions).Where(g => g.Id == roleByName.Id).SingleOrDefaultAsync(); role.Permissions.Clear(); await _roleManager.UpdateAsync(role); List newPermissionSet = new List(); foreach(SecurableItem securableItem in securableItems) { foreach (SecurableItemOperation operation in securableItem.Operations) { if(operation.Status) { newPermissionSet.Add(new RPermission() { SecurableItemShortName = securableItem.ShortName, OperationShortName = operation.ShortName }); } } } role.Permissions = newPermissionSet; await _roleManager.UpdateAsync(role); return new RServiceResult(true); } catch (Exception exp) { return new RServiceResult(false, exp.ToString()); } } /// /// Identity Role Manager /// protected RoleManager _roleManager = null; /// /// constructor /// /// public RoleServiceBase( RoleManager roleManager ) { _roleManager = roleManager; } } }