ManageController.cs 14 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374
  1. using System;
  2. using System.Collections.Generic;
  3. using System.Linq;
  4. using System.Threading.Tasks;
  5. using Microsoft.AspNetCore.Authorization;
  6. using Microsoft.AspNetCore.Identity;
  7. using Microsoft.AspNetCore.Mvc;
  8. using Microsoft.Extensions.Logging;
  9. using Microsoft.Extensions.Options;
  10. using Winsoft.GOV.XF.WXCore.Models;
  11. using Winsoft.GOV.XF.WXCore.Models.ManageViewModels;
  12. using Winsoft.GOV.XF.WXCore.Services;
  13. namespace Winsoft.GOV.XF.WXCore.Controllers
  14. {
  15. [Authorize]
  16. public class ManageController : Controller
  17. {
  18. private readonly UserManager<ApplicationUser> _userManager;
  19. private readonly SignInManager<ApplicationUser> _signInManager;
  20. private readonly string _externalCookieScheme;
  21. private readonly IEmailSender _emailSender;
  22. private readonly ISmsSender _smsSender;
  23. private readonly ILogger _logger;
  24. public ManageController(
  25. UserManager<ApplicationUser> userManager,
  26. SignInManager<ApplicationUser> signInManager,
  27. IOptions<IdentityCookieOptions> identityCookieOptions,
  28. IEmailSender emailSender,
  29. ISmsSender smsSender,
  30. ILoggerFactory loggerFactory)
  31. {
  32. _userManager = userManager;
  33. _signInManager = signInManager;
  34. _externalCookieScheme = identityCookieOptions.Value.ExternalCookieAuthenticationScheme;
  35. _emailSender = emailSender;
  36. _smsSender = smsSender;
  37. _logger = loggerFactory.CreateLogger<ManageController>();
  38. }
  39. //
  40. // GET: /Manage/Index
  41. [HttpGet]
  42. public async Task<IActionResult> Index(ManageMessageId? message = null)
  43. {
  44. ViewData["StatusMessage"] =
  45. message == ManageMessageId.ChangePasswordSuccess ? "Your password has been changed."
  46. : message == ManageMessageId.SetPasswordSuccess ? "Your password has been set."
  47. : message == ManageMessageId.SetTwoFactorSuccess ? "Your two-factor authentication provider has been set."
  48. : message == ManageMessageId.Error ? "An error has occurred."
  49. : message == ManageMessageId.AddPhoneSuccess ? "Your phone number was added."
  50. : message == ManageMessageId.RemovePhoneSuccess ? "Your phone number was removed."
  51. : "";
  52. var user = await GetCurrentUserAsync();
  53. if (user == null)
  54. {
  55. return View("Error");
  56. }
  57. var model = new IndexViewModel
  58. {
  59. HasPassword = await _userManager.HasPasswordAsync(user),
  60. PhoneNumber = await _userManager.GetPhoneNumberAsync(user),
  61. TwoFactor = await _userManager.GetTwoFactorEnabledAsync(user),
  62. Logins = await _userManager.GetLoginsAsync(user),
  63. BrowserRemembered = await _signInManager.IsTwoFactorClientRememberedAsync(user)
  64. };
  65. return View(model);
  66. }
  67. //
  68. // POST: /Manage/RemoveLogin
  69. [HttpPost]
  70. [ValidateAntiForgeryToken]
  71. public async Task<IActionResult> RemoveLogin(RemoveLoginViewModel account)
  72. {
  73. ManageMessageId? message = ManageMessageId.Error;
  74. var user = await GetCurrentUserAsync();
  75. if (user != null)
  76. {
  77. var result = await _userManager.RemoveLoginAsync(user, account.LoginProvider, account.ProviderKey);
  78. if (result.Succeeded)
  79. {
  80. await _signInManager.SignInAsync(user, isPersistent: false);
  81. message = ManageMessageId.RemoveLoginSuccess;
  82. }
  83. }
  84. return RedirectToAction(nameof(ManageLogins), new { Message = message });
  85. }
  86. //
  87. // GET: /Manage/AddPhoneNumber
  88. public IActionResult AddPhoneNumber()
  89. {
  90. return View();
  91. }
  92. //
  93. // POST: /Manage/AddPhoneNumber
  94. [HttpPost]
  95. [ValidateAntiForgeryToken]
  96. public async Task<IActionResult> AddPhoneNumber(AddPhoneNumberViewModel model)
  97. {
  98. if (!ModelState.IsValid)
  99. {
  100. return View(model);
  101. }
  102. // Generate the token and send it
  103. var user = await GetCurrentUserAsync();
  104. if (user == null)
  105. {
  106. return View("Error");
  107. }
  108. var code = await _userManager.GenerateChangePhoneNumberTokenAsync(user, model.PhoneNumber);
  109. await _smsSender.SendSmsAsync(model.PhoneNumber, "Your security code is: " + code);
  110. return RedirectToAction(nameof(VerifyPhoneNumber), new { PhoneNumber = model.PhoneNumber });
  111. }
  112. //
  113. // POST: /Manage/EnableTwoFactorAuthentication
  114. [HttpPost]
  115. [ValidateAntiForgeryToken]
  116. public async Task<IActionResult> EnableTwoFactorAuthentication()
  117. {
  118. var user = await GetCurrentUserAsync();
  119. if (user != null)
  120. {
  121. await _userManager.SetTwoFactorEnabledAsync(user, true);
  122. await _signInManager.SignInAsync(user, isPersistent: false);
  123. _logger.LogInformation(1, "User enabled two-factor authentication.");
  124. }
  125. return RedirectToAction(nameof(Index), "Manage");
  126. }
  127. //
  128. // POST: /Manage/DisableTwoFactorAuthentication
  129. [HttpPost]
  130. [ValidateAntiForgeryToken]
  131. public async Task<IActionResult> DisableTwoFactorAuthentication()
  132. {
  133. var user = await GetCurrentUserAsync();
  134. if (user != null)
  135. {
  136. await _userManager.SetTwoFactorEnabledAsync(user, false);
  137. await _signInManager.SignInAsync(user, isPersistent: false);
  138. _logger.LogInformation(2, "User disabled two-factor authentication.");
  139. }
  140. return RedirectToAction(nameof(Index), "Manage");
  141. }
  142. //
  143. // GET: /Manage/VerifyPhoneNumber
  144. [HttpGet]
  145. public async Task<IActionResult> VerifyPhoneNumber(string phoneNumber)
  146. {
  147. var user = await GetCurrentUserAsync();
  148. if (user == null)
  149. {
  150. return View("Error");
  151. }
  152. var code = await _userManager.GenerateChangePhoneNumberTokenAsync(user, phoneNumber);
  153. // Send an SMS to verify the phone number
  154. return phoneNumber == null ? View("Error") : View(new VerifyPhoneNumberViewModel { PhoneNumber = phoneNumber });
  155. }
  156. //
  157. // POST: /Manage/VerifyPhoneNumber
  158. [HttpPost]
  159. [ValidateAntiForgeryToken]
  160. public async Task<IActionResult> VerifyPhoneNumber(VerifyPhoneNumberViewModel model)
  161. {
  162. if (!ModelState.IsValid)
  163. {
  164. return View(model);
  165. }
  166. var user = await GetCurrentUserAsync();
  167. if (user != null)
  168. {
  169. var result = await _userManager.ChangePhoneNumberAsync(user, model.PhoneNumber, model.Code);
  170. if (result.Succeeded)
  171. {
  172. await _signInManager.SignInAsync(user, isPersistent: false);
  173. return RedirectToAction(nameof(Index), new { Message = ManageMessageId.AddPhoneSuccess });
  174. }
  175. }
  176. // If we got this far, something failed, redisplay the form
  177. ModelState.AddModelError(string.Empty, "Failed to verify phone number");
  178. return View(model);
  179. }
  180. //
  181. // POST: /Manage/RemovePhoneNumber
  182. [HttpPost]
  183. [ValidateAntiForgeryToken]
  184. public async Task<IActionResult> RemovePhoneNumber()
  185. {
  186. var user = await GetCurrentUserAsync();
  187. if (user != null)
  188. {
  189. var result = await _userManager.SetPhoneNumberAsync(user, null);
  190. if (result.Succeeded)
  191. {
  192. await _signInManager.SignInAsync(user, isPersistent: false);
  193. return RedirectToAction(nameof(Index), new { Message = ManageMessageId.RemovePhoneSuccess });
  194. }
  195. }
  196. return RedirectToAction(nameof(Index), new { Message = ManageMessageId.Error });
  197. }
  198. //
  199. // GET: /Manage/ChangePassword
  200. [HttpGet]
  201. public IActionResult ChangePassword()
  202. {
  203. return View();
  204. }
  205. //
  206. // POST: /Manage/ChangePassword
  207. [HttpPost]
  208. [ValidateAntiForgeryToken]
  209. public async Task<IActionResult> ChangePassword(ChangePasswordViewModel model)
  210. {
  211. if (!ModelState.IsValid)
  212. {
  213. return View(model);
  214. }
  215. var user = await GetCurrentUserAsync();
  216. if (user != null)
  217. {
  218. var result = await _userManager.ChangePasswordAsync(user, model.OldPassword, model.NewPassword);
  219. if (result.Succeeded)
  220. {
  221. await _signInManager.SignInAsync(user, isPersistent: false);
  222. _logger.LogInformation(3, "User changed their password successfully.");
  223. return RedirectToAction(nameof(Index), new { Message = ManageMessageId.ChangePasswordSuccess });
  224. }
  225. AddErrors(result);
  226. return View(model);
  227. }
  228. return RedirectToAction(nameof(Index), new { Message = ManageMessageId.Error });
  229. }
  230. //
  231. // GET: /Manage/SetPassword
  232. [HttpGet]
  233. public IActionResult SetPassword()
  234. {
  235. return View();
  236. }
  237. //
  238. // POST: /Manage/SetPassword
  239. [HttpPost]
  240. [ValidateAntiForgeryToken]
  241. public async Task<IActionResult> SetPassword(SetPasswordViewModel model)
  242. {
  243. if (!ModelState.IsValid)
  244. {
  245. return View(model);
  246. }
  247. var user = await GetCurrentUserAsync();
  248. if (user != null)
  249. {
  250. var result = await _userManager.AddPasswordAsync(user, model.NewPassword);
  251. if (result.Succeeded)
  252. {
  253. await _signInManager.SignInAsync(user, isPersistent: false);
  254. return RedirectToAction(nameof(Index), new { Message = ManageMessageId.SetPasswordSuccess });
  255. }
  256. AddErrors(result);
  257. return View(model);
  258. }
  259. return RedirectToAction(nameof(Index), new { Message = ManageMessageId.Error });
  260. }
  261. //GET: /Manage/ManageLogins
  262. [HttpGet]
  263. public async Task<IActionResult> ManageLogins(ManageMessageId? message = null)
  264. {
  265. ViewData["StatusMessage"] =
  266. message == ManageMessageId.RemoveLoginSuccess ? "The external login was removed."
  267. : message == ManageMessageId.AddLoginSuccess ? "The external login was added."
  268. : message == ManageMessageId.Error ? "An error has occurred."
  269. : "";
  270. var user = await GetCurrentUserAsync();
  271. if (user == null)
  272. {
  273. return View("Error");
  274. }
  275. var userLogins = await _userManager.GetLoginsAsync(user);
  276. var otherLogins = _signInManager.GetExternalAuthenticationSchemes().Where(auth => userLogins.All(ul => auth.AuthenticationScheme != ul.LoginProvider)).ToList();
  277. ViewData["ShowRemoveButton"] = user.PasswordHash != null || userLogins.Count > 1;
  278. return View(new ManageLoginsViewModel
  279. {
  280. CurrentLogins = userLogins,
  281. OtherLogins = otherLogins
  282. });
  283. }
  284. //
  285. // POST: /Manage/LinkLogin
  286. [HttpPost]
  287. [ValidateAntiForgeryToken]
  288. public async Task<IActionResult> LinkLogin(string provider)
  289. {
  290. // Clear the existing external cookie to ensure a clean login process
  291. await HttpContext.Authentication.SignOutAsync(_externalCookieScheme);
  292. // Request a redirect to the external login provider to link a login for the current user
  293. var redirectUrl = Url.Action(nameof(LinkLoginCallback), "Manage");
  294. var properties = _signInManager.ConfigureExternalAuthenticationProperties(provider, redirectUrl, _userManager.GetUserId(User));
  295. return Challenge(properties, provider);
  296. }
  297. //
  298. // GET: /Manage/LinkLoginCallback
  299. [HttpGet]
  300. public async Task<ActionResult> LinkLoginCallback()
  301. {
  302. var user = await GetCurrentUserAsync();
  303. if (user == null)
  304. {
  305. return View("Error");
  306. }
  307. var info = await _signInManager.GetExternalLoginInfoAsync(await _userManager.GetUserIdAsync(user));
  308. if (info == null)
  309. {
  310. return RedirectToAction(nameof(ManageLogins), new { Message = ManageMessageId.Error });
  311. }
  312. var result = await _userManager.AddLoginAsync(user, info);
  313. var message = ManageMessageId.Error;
  314. if (result.Succeeded)
  315. {
  316. message = ManageMessageId.AddLoginSuccess;
  317. // Clear the existing external cookie to ensure a clean login process
  318. await HttpContext.Authentication.SignOutAsync(_externalCookieScheme);
  319. }
  320. return RedirectToAction(nameof(ManageLogins), new { Message = message });
  321. }
  322. #region Helpers
  323. private void AddErrors(IdentityResult result)
  324. {
  325. foreach (var error in result.Errors)
  326. {
  327. ModelState.AddModelError(string.Empty, error.Description);
  328. }
  329. }
  330. public enum ManageMessageId
  331. {
  332. AddPhoneSuccess,
  333. AddLoginSuccess,
  334. ChangePasswordSuccess,
  335. SetTwoFactorSuccess,
  336. SetPasswordSuccess,
  337. RemoveLoginSuccess,
  338. RemovePhoneSuccess,
  339. Error
  340. }
  341. private Task<ApplicationUser> GetCurrentUserAsync()
  342. {
  343. return _userManager.GetUserAsync(HttpContext.User);
  344. }
  345. #endregion
  346. }
  347. }