AuthorizationFilter.cs 7.2 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144
  1. using System.Text;
  2. using System.Web;
  3. using Common;
  4. using Extensions;
  5. using Infrastructure;
  6. using Infrastructure.Model;
  7. using Microsoft.AspNetCore.Mvc;
  8. using Microsoft.AspNetCore.Mvc.Filters;
  9. using Services;
  10. //本命名空间暂时先不改,改动比较大2023年9月2日
  11. namespace Filters
  12. {
  13. /// <summary>
  14. /// </summary>
  15. public class AuthorizationFilter : IAuthorizationFilter
  16. {
  17. private readonly ISysLoginService SysLoginService;
  18. public AuthorizationFilter(ISysLoginService sysLoginService)
  19. {
  20. this.SysLoginService = sysLoginService;
  21. }
  22. /// <summary>
  23. /// </summary>
  24. /// <param name="context"></param>
  25. public void OnAuthorization(AuthorizationFilterContext context)
  26. {
  27. var request = context.HttpContext.Request;
  28. if(request.Path.Value.ToLower().Contains("v1/"))
  29. {
  30. string content = "";
  31. if(context.HttpContext.Request.Method.ToLower() == "get")
  32. {
  33. content = context.HttpContext.GetQueryString();
  34. content = content.Substring(content.IndexOf("=") + 1);
  35. content = HttpUtility.UrlDecode(content);
  36. content = Decrypt(content);
  37. content = HttpUtility.UrlDecode(content);
  38. if(!string.IsNullOrEmpty(content))
  39. {
  40. Dictionary<string, object> dic = Newtonsoft.Json.JsonConvert.DeserializeObject<Dictionary<string, object>>(content);
  41. string queryString = "";
  42. var parameters = context.ActionDescriptor.Parameters;
  43. foreach(var parameter in parameters)
  44. {
  45. string parameterName = parameter.Name;
  46. Type objectType = parameter.ParameterType;
  47. if(objectType.FullName != "System.String")
  48. {
  49. System.Reflection.Assembly assembly = System.Reflection.Assembly.GetAssembly(objectType);
  50. var entry = assembly.CreateInstance(objectType.FullName);
  51. Type type = entry.GetType();
  52. System.Reflection.PropertyInfo[] propertyInfos = type.GetProperties();
  53. for (int i = 0; i < propertyInfos.Length; i++)
  54. {
  55. foreach (string key in dic.Keys)
  56. {
  57. if (propertyInfos[i].Name == key)
  58. {
  59. object value = dic[key];
  60. string ParameterType = propertyInfos[i].GetMethod.ReturnParameter.ParameterType.Name;
  61. if (ParameterType == "Int32")
  62. {
  63. if(value == null || value == "") value = "0";
  64. value = Convert.ToInt32(value);
  65. }
  66. else if (ParameterType == "Int64[]")
  67. {
  68. value = Tools.SpitLongArrary(Newtonsoft.Json.JsonConvert.SerializeObject(value).Replace("[", "").Replace("]", "").Trim('"'), ',');
  69. }
  70. else if (ParameterType == "Int32[]")
  71. {
  72. value = Tools.SpitIntArrary(Newtonsoft.Json.JsonConvert.SerializeObject(value).Replace("[", "").Replace("]", "").Trim('"'), ',');
  73. }
  74. else if (ParameterType == "List`1")
  75. {
  76. string val = Newtonsoft.Json.JsonConvert.SerializeObject(value).Replace("[", "").Replace("]", "").Trim('"');
  77. value = Tools.SpitLongArrary(val, ',').ToList();
  78. }
  79. else if(ParameterType == "Nullable`1" && value == null)
  80. {
  81. string fullName = Function.CheckNull(propertyInfos[i].GetMethod.ReturnParameter.ParameterType.FullName);
  82. if(fullName.Contains("System.Int32"))
  83. {
  84. value = -99;
  85. }
  86. }
  87. if(value.ToString() == "-1") value = -1;
  88. if(value.ToString() == "[]") value = "";
  89. queryString += key + "=" + value.ToString() + "&";
  90. break;
  91. }
  92. }
  93. }
  94. }
  95. }
  96. request.QueryString = new QueryString("?" + queryString.TrimEnd('&'));
  97. }
  98. }
  99. else if(context.HttpContext.Request.Method.ToLower() == "delete")
  100. {
  101. string path = request.Path.Value;
  102. string value = path.Substring(path.LastIndexOf("/") + 1);
  103. path = path.Substring(0, path.LastIndexOf("/") + 1);
  104. value = Decrypt(value);
  105. path += value;
  106. request.Path = new PathString(path);
  107. request.RouteValues["id"] = value;
  108. }
  109. else
  110. {
  111. content = context.HttpContext.GetBody();
  112. content = Decrypt(content);
  113. request.Body = new MemoryStream(Encoding.UTF8.GetBytes(content));
  114. //验证登录接口
  115. if(request.Path.Value.EndsWith("/oauth2/token"))
  116. {
  117. var scope = request.Query["scope"].ToString();
  118. var grantType = request.Query["grant_type"].ToString();
  119. bool checkLogin = SysLoginService.CheckLogin(scope, grantType, context.HttpContext.GetToken().Replace("Basic ", ""));
  120. if(!checkLogin)
  121. {
  122. string msg = $"请求访问失败,无法访问系统资源";
  123. context.Result = new JsonResult(ApiResult.Error(ResultCode.DENY, msg));
  124. }
  125. }
  126. }
  127. }
  128. }
  129. public string Decrypt(string str)
  130. {
  131. str = str.Trim('"');
  132. str = Encoding.UTF8.GetString(Convert.FromBase64String(str));
  133. return Dbconn.AesDecrypt(str, Base.GlobalConstant.ApiKey, Base.GlobalConstant.ApiIv);
  134. }
  135. }
  136. }