se agrego rc102

This commit is contained in:
jrojas
2026-07-06 19:30:28 +02:00
parent 319fd3dfb0
commit 9e2246a459
15 changed files with 170 additions and 212 deletions
+98 -149
View File
@@ -5,11 +5,12 @@ using adas_core.Domain.Models.MongoModels;
using adas_core.LdapLogin.Configuration;
using FluentValidation;
using Microsoft.AspNetCore.Http;
using Microsoft.AspNetCore.Http.HttpResults;
using Microsoft.Extensions.Logging;
using Microsoft.Extensions.Options;
using MongoDB.Bson;
using Novell.Directory.Ldap;
using System.DirectoryServices.Protocols;
using System.Net;
using Authorization = adas_core.Domain.Models.MongoModels.Authorization;
namespace adas_core.LdapLogin;
@@ -39,157 +40,128 @@ public class LdapLoginService : ILoginService
public async Task<User> Login(string username, string password)
{
// Check for LDAP config
if (_ldapConfig.Server == null) throw new LoginServicesException("LDAP Config not found");
var conn = new LdapConnection();
if (_ldapConfig.Server == null)
throw new LoginServicesException("LDAP Config not found");
var identifier = new LdapDirectoryIdentifier(_ldapConfig.Server, _ldapConfig.Port ?? 389);
var connection = new LdapConnection(identifier);
try
{
await conn.ConnectAsync(_ldapConfig.Server, _ldapConfig.Port ?? 389);
}
catch (Exception e)
{
_logger.LogError("[LDAP] Error connecting to {server}, port {port}, Exception: {e}", _ldapConfig.Server,
_ldapConfig.Port, e.Message);
throw;
}
if (_ldapConfig.LdapUser != null)
{
_logger.LogInformation("[LDAP] _ldapConfig.LdapUser is enabled with {LdapUser}", _ldapConfig.LdapUser);
await conn.BindAsync(_ldapConfig.LdapUser, _ldapConfig.LdapPassword);
}
else
{
var ldapUser = (!string.IsNullOrEmpty(_ldapConfig.UserDomainName)
? _ldapConfig.UserDomainName + @"\"
: "") + username;
try
if (_ldapConfig.LdapUser != null)
{
await conn.BindAsync(ldapUser, password);
_logger.LogInformation("[LDAP] Using configured LDAP user {LdapUser}", _ldapConfig.LdapUser);
connection.Credential = new NetworkCredential(_ldapConfig.LdapUser, _ldapConfig.LdapPassword);
}
catch (LdapException e)
else
{
_logger.LogError("[LDAP] Error binding ldapUser: {LdapUser} and password", ldapUser);
var ldapUser = (!string.IsNullOrEmpty(_ldapConfig.UserDomainName)
? _ldapConfig.UserDomainName + @"\"
: "") + username;
throw new UserNotFoundException(username, e);
}
}
var results = await conn.SearchAsync(
_ldapConfig.SearchBase,
LdapConnection.ScopeSub,
$"({_ldapConfig.UserNameProperty}={username})",
null,
false);
LdapEntry? entry = null;
while (await results.HasMoreAsync())
{
LdapEntry? current = null;
try
{
current = await results.NextAsync();
}
catch (LdapException ex)
{
_logger.LogWarning("[LDAP] Skipping invalid entry: {error}", ex.Message);
continue;
connection.Credential = new NetworkCredential(ldapUser, password);
}
if (current != null)
connection.AuthType = AuthType.Basic;
connection.Bind();
}
catch (LdapException e)
{
_logger.LogError("[LDAP] Error binding user {username}", username);
throw new UserNotFoundException(username, e);
}
SearchResultEntry? entry = null;
try
{
var request = new SearchRequest(
_ldapConfig.SearchBase,
$"({_ldapConfig.UserNameProperty}={username})",
SearchScope.Subtree
);
var response = (SearchResponse)connection.SendRequest(request);
foreach (SearchResultEntry current in response.Entries)
{
entry = current;
break;
}
}
catch (Exception e)
{
_logger.LogError("[LDAP] Search error for user {username}: {error}", username, e.Message);
throw;
}
if (entry == null)
throw new LoginServicesException("LDAP User not found");
if (entry == null) throw new LoginServicesException("LDAP User not found");
var userEntryLdap = GetUser(entry);
var user = await GetOrCreateUser(userEntryLdap, entry);
_logger.LogInformation("[LDAP] entry is {entry} and user {user}", entry, user);
// user.Authorization.AddRange(GetAuthorities(entry));
conn.Disconnect();
_logger.LogInformation("[LDAP] entry found and user {user}", user);
connection.Dispose();
return user ?? throw new LoginServicesException("LDAP User not found");
}
public Task<User> Login(HttpContext context)
{
throw new LoginServicesException("Not implemented");
}
=> throw new LoginServicesException("Not implemented");
public Task<User> Authenticate(string username, string password)
{
throw new LoginServicesException("Not implemented");
}
=> throw new LoginServicesException("Not implemented");
public Task<User?> GetById(ObjectId id)
{
throw new LoginServicesException("Not implemented");
}
=> throw new LoginServicesException("Not implemented");
public Task<User?> GetByEmail(string email)
{
throw new LoginServicesException("Not implemented");
}
=> throw new LoginServicesException("Not implemented");
public Task<User?> GetByUsername(string username)
{
throw new LoginServicesException("Not implemented");
}
=> throw new LoginServicesException("Not implemented");
public Task<List<User>> GetAllUsers()
{
throw new LoginServicesException("Not implemented");
}
=> throw new LoginServicesException("Not implemented");
private async Task<User?> GetOrCreateUser(User userEntryLdap, LdapEntry entry)
private async Task<User?> GetOrCreateUser(User userEntryLdap, SearchResultEntry entry)
{
var userToReturn = (await _userService.Value.GetUserByUserName(userEntryLdap.UserName) ??
await _userService.Value.GetUserByName(userEntryLdap.Name)) ??
await _userService.Value.CreateUser(userEntryLdap);
if (userToReturn == null) return userToReturn;
userToReturn.Authorization = [];
var authorities = await CheckAuthorities(userToReturn, entry);
userToReturn.Authorization.AddRange(authorities);
//foreach (var authorization in userToReturn.Authorization)
//{
// Enum.TryParse<RolesType>(authorization.Rol, out var compareRole);
// if (compareRole == RolesType.Admin) userToReturn.Rol = RolesType.Admin;
//}
return userToReturn;
}
private async Task<List<Authorization>> CheckAuthorities(User user, LdapEntry entry)
private async Task<List<Authorization>> CheckAuthorities(User user, SearchResultEntry entry)
{
try
{
var authorizationMap = GetAuthoritiesMap(entry, user);
var authorizationWhiteList = GetAuthoritiesWhiteList(entry, user);
_logger.LogInformation(
"[LDAP] user {user} authorizationMap count is {authorizationMap}, authorizationWhiteList count is {authorizationWhiteList}",
user.UserName, authorizationMap.Count, authorizationWhiteList.Count);
// Primero, creamos un HashSet con los DisplayID de la lista blanca para búsqueda eficiente
var whiteListDisplayIds = new HashSet<string?>(authorizationWhiteList.Select(a => a.DisplayId));
// Filtramos los elementos de authorizationMap que no están en la lista blanca, basándonos en DisplayID
var uniqueMapAuthorizations = authorizationMap.Where(a => !whiteListDisplayIds.Contains(a.DisplayId));
var uniqueMapAuthorizations = authorizationMap
.Where(a => !whiteListDisplayIds.Contains(a.DisplayId));
// Finalmente, combinamos los elementos únicos de authorizationMap con los de authorizationWhiteList
var combinedList = authorizationWhiteList.Concat(uniqueMapAuthorizations).ToList();
var userAuthorities = await _authorityService.GetUserAuthorities(user.Id);
foreach (var auth in combinedList)
{
var authFound = userAuthorities.Find(c => c.DisplayId == auth.DisplayId);
if (authFound is { CanUpdate: true })
{
authFound.Rol = auth.Rol;
@@ -205,36 +177,32 @@ public class LdapLoginService : ILoginService
}
catch (Exception e)
{
_logger.LogError("[LDAP] CheckAuthorities for user {user} has exception {ex}", user.UserName, e.Message);
_logger.LogError("[LDAP] CheckAuthorities error for user {user}: {error}",
user.UserName, e.Message);
return [];
}
}
private List<Authorization> GetAuthoritiesWhiteList(LdapEntry entry, User user)
private List<Authorization> GetAuthoritiesWhiteList(SearchResultEntry entry, User user)
{
try
{
var userWhiteList = new List<Authorization>();
var userNameProperty = _ldapConfig.UserNameProperty;
var result = new List<Authorization>();
var whiteList = _ldapConfig.WhiteList.FindAll(u =>
(u.Name != null && entry.Dn.Contains(u.Name, StringComparison.CurrentCultureIgnoreCase)) ||
(u.Name != null && entry.DistinguishedName.Contains(u.Name, StringComparison.CurrentCultureIgnoreCase)) ||
(u.Username != null &&
userNameProperty != null &&
entry.GetAttributeSet().TryGetValue(userNameProperty, out var attr) &&
attr.StringValue != null &&
attr.StringValue.Equals(u.Username, StringComparison.CurrentCultureIgnoreCase))
entry.Attributes[_ldapConfig.UserNameProperty]?[0]?.ToString()
?.Equals(u.Username, StringComparison.CurrentCultureIgnoreCase) == true)
);
if (whiteList.Count == 0) return userWhiteList;
foreach (var authorityMap in whiteList)
{
if (!Enum.TryParse<PermissionEnum.RolesType>(authorityMap.Rol, out _))
continue;
userWhiteList.Add(new Authorization
result.Add(new Authorization
{
UserId = user.Id,
DisplayId = authorityMap.DisplayId,
@@ -242,59 +210,42 @@ public class LdapLoginService : ILoginService
});
}
return userWhiteList;
return result;
}
catch (Exception e)
{
_logger.LogError("[LDAP] GetAuthoritiesWhiteList for user {user} has exception {ex}", user.UserName,
e.Message);
_logger.LogError("[LDAP] GetAuthoritiesWhiteList error: {error}", e.Message);
return [];
}
}
private User GetUser(LdapEntry ldapEntry)
private User GetUser(SearchResultEntry entry)
{
var attributes = ldapEntry.GetAttributeSet();
var user = new User();
// UserName
if (!string.IsNullOrWhiteSpace(_ldapConfig.UserNameProperty) &&
attributes.TryGetValue(_ldapConfig.UserNameProperty, out var userAttr) &&
userAttr?.StringValue != null)
var user = new User
{
user.UserName = userAttr.StringValue;
}
else
UserName = entry.Attributes[_ldapConfig.UserNameProperty]?[0]?.ToString() ?? ""
};
if (!string.IsNullOrWhiteSpace(_ldapConfig.FirstNameProperty))
{
user.UserName = "";
var first = entry.Attributes[_ldapConfig.FirstNameProperty]?[0]?.ToString();
if (first != null)
user.Name = first;
}
_logger.LogInformation("[LDAP] GetUser UserName is {UserName} ", user.UserName);
// First name
if (!string.IsNullOrWhiteSpace(_ldapConfig.FirstNameProperty) &&
attributes.TryGetValue(_ldapConfig.FirstNameProperty, out var firstNameAttr) &&
firstNameAttr?.StringValue != null)
if (!string.IsNullOrWhiteSpace(_ldapConfig.LastNameProperty))
{
user.Name = firstNameAttr.StringValue;
}
// Last name
if (!string.IsNullOrWhiteSpace(_ldapConfig.LastNameProperty) &&
attributes.TryGetValue(_ldapConfig.LastNameProperty, out var lastNameAttr) &&
lastNameAttr?.StringValue != null)
{
user.Name = string.IsNullOrEmpty(user.Name)
? lastNameAttr.StringValue
: $"{user.Name} {lastNameAttr.StringValue}";
var last = entry.Attributes[_ldapConfig.LastNameProperty]?[0]?.ToString();
if (last != null)
user.Name = string.IsNullOrEmpty(user.Name)
? last
: $"{user.Name} {last}";
}
return user;
}
private List<Authorization> GetAuthoritiesMap(LdapEntry ldapEntry, User user)
private List<Authorization> GetAuthoritiesMap(SearchResultEntry entry, User user)
{
try
{
@@ -303,16 +254,14 @@ public class LdapLoginService : ILoginService
if (!_ldapConfig.AuthoritiesMap.Any())
return authorities;
var attributes = ldapEntry.GetAttributeSet();
var groupAttr = entry.Attributes[_ldapConfig.GroupsProperty];
if (!string.IsNullOrWhiteSpace(_ldapConfig.GroupsProperty) ||
!attributes.TryGetValue(_ldapConfig.GroupsProperty!, out var groupsAttr) ||
groupsAttr?.StringValueArray == null)
{
if (groupAttr == null)
return authorities;
}
var groups = groupsAttr.StringValueArray.ToList();
var groups = groupAttr.GetValues(typeof(string))
.Cast<string>()
.ToList();
foreach (var authorityMap in _ldapConfig.AuthoritiesMap)
{
@@ -335,8 +284,8 @@ public class LdapLoginService : ILoginService
}
catch (Exception e)
{
_logger.LogError("Error getting Authorities Map. Return new empty list. Exception: {e}", e);
_logger.LogError("[LDAP] GetAuthoritiesMap error: {error}", e.Message);
return [];
}
}
}
}