using DivanRazor.Models; using Microsoft.AspNetCore.Http; using Microsoft.AspNetCore.Mvc; using Microsoft.AspNetCore.Mvc.RazorPages; using Microsoft.Extensions.Configuration; using Newtonsoft.Json; using RMuseum.Models.Auth.Memory; using RMuseum.Models.Auth.ViewModel; using RSecurityBackend.Models.Auth.Memory; using RSecurityBackend.Models.Auth.ViewModels; using System; using System.Linq; using System.Net.Http; using System.Text; using System.Threading.Tasks; namespace DivanRazor.Pages { public class SignUpModel : PageModel { /// /// HttpClient instance /// private readonly HttpClient _httpClient; /// /// configuration /// private readonly IConfiguration Configuration; public SignUpModel(HttpClient httpClient, IConfiguration configuration) { _httpClient = httpClient; Configuration = configuration; } public bool LoggedIn { get; set; } public string LastError { get; set; } public string CaptchaImageUrl { get; set; } public bool SignupPhase1 { get; set; } public bool SignupVerifyEmailPhase { get; set; } public bool SignupFinalPhase { get; set; } [BindProperty] public UnverifiedSignUpViewModel SignUpViewModel { get; set; } [BindProperty] public string Secret { get; set; } [BindProperty] public VerifiedSignUpViewModelWithRepPass FinalViewModel { get; set; } private void _FillViewData() { ViewData["TrackingScript"] = Configuration["TrackingScript"] != null && string.IsNullOrEmpty(Request.Cookies["Token"]) ? Configuration["TrackingScript"].Replace("loggedon", "") : Configuration["TrackingScript"]; if (SignupPhase1) { ViewData["Title"] = "دیوان » رکنیت » ای میل"; } else if (SignupVerifyEmailPhase) { ViewData["Title"] = "دیوان » رکنیت » موصولہ کوڈ"; } else { ViewData["Title"] = "دیوان » رکنیت » آخری مرحلہ"; } } public async Task OnGetAsync() { if (bool.Parse(Configuration["MaintenanceMode"])) { return StatusCode(503); } if (!string.IsNullOrEmpty(Request.Query["secret"])) return await OnPostPhase2Async(Request.Query["secret"]); LoggedIn = !string.IsNullOrEmpty(Request.Cookies["Name"]); LastError = ""; SignupPhase1 = true; SignupVerifyEmailPhase = false; SignupFinalPhase = false; SignUpViewModel = new UnverifiedSignUpViewModel() { ClientAppName = "دیوان ویب سائٹ", Language = "ur-PK", CallbackUrl = $"{Configuration["SiteUrl"]}/signup" }; var response = await _httpClient.GetAsync($"{APIRoot.Url}/api/users/captchaimage"); if (!response.IsSuccessStatusCode) { LastError = JsonConvert.DeserializeObject(await response.Content.ReadAsStringAsync()); _FillViewData(); return Page(); } SignUpViewModel.CaptchaImageId = JsonConvert.DeserializeObject(await response.Content.ReadAsStringAsync()); CaptchaImageUrl = $"{APIRoot.InternetUrl}/api/rimages/{SignUpViewModel.CaptchaImageId}.jpg"; _FillViewData(); return Page(); } public async Task OnPostPhase1Async(UnverifiedSignUpViewModel signUpViewModel) { LoggedIn = !string.IsNullOrEmpty(Request.Cookies["Name"]); LastError = ""; SignupPhase1 = true; SignupVerifyEmailPhase = false; SignupFinalPhase = false; var response = await _httpClient.PostAsync($"{APIRoot.Url}/api/users/signup", new StringContent(JsonConvert.SerializeObject(SignUpViewModel), Encoding.UTF8, "application/json")); if (!response.IsSuccessStatusCode) { LastError = JsonConvert.DeserializeObject(await response.Content.ReadAsStringAsync()); if(LastError == null) { LastError = "براہِ کرم اپنی ای میل اور حفاظتی تصویر کا عدد درست لکھیں."; } response = await _httpClient.GetAsync($"{APIRoot.Url}/api/users/captchaimage"); if (!response.IsSuccessStatusCode) { LastError = JsonConvert.DeserializeObject(await response.Content.ReadAsStringAsync()); _FillViewData(); return Page(); } ModelState.Clear(); SignUpViewModel = new UnverifiedSignUpViewModel() { ClientAppName = signUpViewModel.ClientAppName, Language = signUpViewModel.Language, CallbackUrl = signUpViewModel.CallbackUrl, Email = signUpViewModel.Email }; SignUpViewModel.CaptchaImageId = JsonConvert.DeserializeObject(await response.Content.ReadAsStringAsync()); CaptchaImageUrl = $"{APIRoot.InternetUrl}/api/rimages/{SignUpViewModel.CaptchaImageId}.jpg"; _FillViewData(); return Page(); } SignupPhase1 = false; SignupVerifyEmailPhase = true; _FillViewData(); return Page(); } public async Task OnPostPhase2Async(string Secret) { LoggedIn = !string.IsNullOrEmpty(Request.Cookies["Name"]); LastError = ""; SignupPhase1 = false; SignupVerifyEmailPhase = true; SignupFinalPhase = false; var response = await _httpClient.GetAsync($"{APIRoot.Url}/api/users/verify?type=0&secret={Secret}"); if (!response.IsSuccessStatusCode) { LastError = JsonConvert.DeserializeObject(await response.Content.ReadAsStringAsync()); _FillViewData(); return Page(); } FinalViewModel = new VerifiedSignUpViewModelWithRepPass() { Secret = Secret, Email = JsonConvert.DeserializeObject(await response.Content.ReadAsStringAsync()), FirstName = "", SurName = "", Password = "", PasswordConfirmation = "" }; SignupVerifyEmailPhase = false; SignupFinalPhase = true; _FillViewData(); return Page(); } public async Task OnPostPhase3Async() { LoggedIn = !string.IsNullOrEmpty(Request.Cookies["Name"]); LastError = ""; SignupPhase1 = false; SignupVerifyEmailPhase = false; SignupFinalPhase = true; if (FinalViewModel.Password != FinalViewModel.PasswordConfirmation) { LastError = "پاس ورڈ اور اس کی تکرار ایک جیسے نہیں."; _FillViewData(); return Page(); } VerifiedSignUpViewModel postViewModel = new VerifiedSignUpViewModel() { Email = FinalViewModel.Email, Secret = FinalViewModel.Secret, FirstName = FinalViewModel.FirstName, SurName = FinalViewModel.SurName, Password = FinalViewModel.Password }; var response = await _httpClient.PostAsync($"{APIRoot.Url}/api/users/finalizesignup", new StringContent(JsonConvert.SerializeObject(postViewModel), Encoding.UTF8, "application/json")); if (!response.IsSuccessStatusCode) { LastError = JsonConvert.DeserializeObject(await response.Content.ReadAsStringAsync()); _FillViewData(); return Page(); } LoginViewModel loginViewModel = new LoginViewModel() { ClientAppName = "دیوان ویب سائٹ", Language = "ur-PK", Username = postViewModel.Email, Password = postViewModel.Password }; var stringContent = new StringContent(JsonConvert.SerializeObject(loginViewModel), Encoding.UTF8, "application/json"); var loginUrl = $"{APIRoot.Url}/api/users/login"; response = await _httpClient.PostAsync(loginUrl, stringContent); if (!response.IsSuccessStatusCode) { LastError = JsonConvert.DeserializeObject(await response.Content.ReadAsStringAsync()); _FillViewData(); return Page(); } LoggedOnUserModelEx loggedOnUser = JsonConvert.DeserializeObject(await response.Content.ReadAsStringAsync()); // Authentication-related cookies are never read by client-side JavaScript // (only server-side C# reads Request.Cookies[...]), so they can safely be // marked HttpOnly to stop them being exfiltrated via document.cookie in the // event of an XSS bug. Secure/SameSite=Lax provide additional defense-in-depth. var cookieOption = new CookieOptions() { Expires = DateTime.Now.AddDays(365), HttpOnly = true, Secure = true, SameSite = SameSiteMode.Lax, }; Response.Cookies.Append("UserId", loggedOnUser.User.Id.ToString(), cookieOption); Response.Cookies.Append("SessionId", loggedOnUser.SessionId.ToString(), cookieOption); Response.Cookies.Append("Token", loggedOnUser.Token, cookieOption); Response.Cookies.Append("Username", loggedOnUser.User.Username, cookieOption); Response.Cookies.Append("Name", $"{loggedOnUser.User.FirstName} {loggedOnUser.User.SurName}", cookieOption); Response.Cookies.Append("NickName", $"{loggedOnUser.User.NickName}", cookieOption); Response.Cookies.Append("KeepHistory", $"{loggedOnUser.KeepHistory}", cookieOption); bool canEditContent = false; var divanEntity = loggedOnUser.SecurableItem.Where(s => s.ShortName == RMuseumSecurableItem.DivanEntityShortName).SingleOrDefault(); if (divanEntity != null) { var op = divanEntity.Operations.Where(o => o.ShortName == SecurableItem.ModifyOperationShortName).SingleOrDefault(); if (op != null) { canEditContent = op.Status; } } Response.Cookies.Append("CanEdit", canEditContent.ToString(), cookieOption); _FillViewData(); return Redirect($"{Configuration["SiteUrl"]}/User"); } } }