Program.cs 6.1 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126
  1. using Hangfire;
  2. using Hangfire.Redis.StackExchange;
  3. using Microsoft.AspNetCore.Authentication.JwtBearer;
  4. using Microsoft.Extensions.DependencyInjection.Extensions;
  5. using Microsoft.IdentityModel.Tokens;
  6. using System.IdentityModel.Tokens.Jwt;
  7. using TEAMModelOS.SDK.DI;
  8. using TEAMModelOS.SDK;
  9. using HTEX.Complex.Services;
  10. namespace HTEX.Complex
  11. {
  12. public class Program
  13. {
  14. public static void Main(string[] args)
  15. {
  16. var builder = WebApplication.CreateBuilder(args);
  17. // Add services to the container.
  18. JwtSecurityTokenHandler.DefaultMapInboundClaims = false;
  19. builder.Services.AddAuthentication(options => options.DefaultScheme = JwtBearerDefaults.AuthenticationScheme)
  20. .AddJwtBearer(options => //AzureADJwtBearer
  21. {
  22. //options.SaveToken = true; //驗證令牌由服務器生成才有效,不適用於服務重啟或分布式架構
  23. options.Authority ="https://login.chinacloudapi.cn/4807e9cf-87b8-4174-aa5b-e76497d7392b/v2.0";// builder.Configuration["Option:Authority"];
  24. options.Audience = "72643704-b2e7-4b26-b881-bd5865e7a7a5";//builder.Configuration["Option:Audience"];
  25. options.RequireHttpsMetadata = true;
  26. options.TokenValidationParameters = new TokenValidationParameters
  27. {
  28. RoleClaimType = "roles",
  29. //ValidAudiences = new string[] { builder.Configuration["Option:Audience"], $"api://{builder.Configuration["Option:Audience"]}" }
  30. ValidAudiences = new string[] { "72643704-b2e7-4b26-b881-bd5865e7a7a5", $"api://72643704-b2e7-4b26-b881-bd5865e7a7a5" }
  31. };
  32. options.Events = new JwtBearerEvents();
  33. //下列事件有需要紀錄則打開
  34. //options.Events.OnMessageReceived = async context => { await Task.FromResult(0); };
  35. //options.Events.OnForbidden = async context => { await Task.FromResult(0); };
  36. //options.Events.OnChallenge = async context => { await Task.FromResult(0); };
  37. //options.Events.OnAuthenticationFailed = async context => { await Task.FromResult(0); };
  38. options.Events.OnTokenValidated = async context =>
  39. {
  40. if (!context.Principal.Claims.Any(x => x.Type.Equals("http://schemas.microsoft.com/identity/claims/scope")) //ClaimConstants.Scope
  41. && !context.Principal.Claims.Any(y => y.Type.Equals("roles"))) //ClaimConstants.Roles //http://schemas.microsoft.com/ws/2008/06/identity/claims/role
  42. {
  43. //TODO 需處理額外授權非角色及範圍的訪問異常紀錄
  44. throw new UnauthorizedAccessException("Neither scope or roles claim was found in the bearer token.");
  45. }
  46. await Task.FromResult(0);
  47. };
  48. });
  49. builder.Services.AddControllers();
  50. #if DEBUG
  51. builder.WebHost.UseUrls(new[] { "https://*:7298" });
  52. #endif
  53. // Learn more about configuring Swagger/OpenAPI at https://aka.ms/aspnetcore/swashbuckle
  54. builder.Services.AddEndpointsApiExplorer();
  55. //builder.Services.AddSwaggerGen();
  56. builder.Services.AddHttpClient();
  57. string? StorageConnectionString = builder.Configuration.GetValue<string>("Azure:Storage:ConnectionString");
  58. string? RedisConnectionString = builder.Configuration.GetValue<string>("Azure:Redis:ConnectionString");
  59. string? CosmosConnectionString = builder.Configuration.GetValue<string>("Azure:Cosmos:ConnectionString");
  60. //Storage
  61. builder.Services.AddAzureStorage(StorageConnectionString, "Default");
  62. //Redis
  63. builder.Services.AddAzureRedis(RedisConnectionString, "Default");
  64. //Cosmos
  65. builder.Services.AddAzureCosmos(CosmosConnectionString, "Default");
  66. //MQTT 服务端API 发送消息到MQTT客户端 https://www.cnblogs.com/weskynet/p/16441219.html
  67. builder.Services.AddSignalR();
  68. builder.Services.AddHttpContextAccessor();
  69. builder.Services.AddHttpClient<DingDing>();
  70. string path = $"{builder.Environment.ContentRootPath}/JsonFiles";
  71. builder.Services.TryAddSingleton(new Region2LongitudeLatitudeTranslator(path));
  72. builder.Services.AddIPSearcher(path);
  73. builder.Services.AddCors(options =>
  74. {
  75. options.AddDefaultPolicy(
  76. builder =>
  77. {
  78. builder.AllowAnyOrigin()
  79. .AllowAnyHeader()
  80. .AllowAnyMethod();
  81. });
  82. });
  83. #if !DEBUG
  84. builder.Services.AddHangfire(config => {
  85. config.UseRedisStorage(builder.Configuration.GetValue<string>("Azure:Redis:ConnectionString"));
  86. });
  87. builder.Services.AddHangfireServer();
  88. #endif
  89. builder.Services.AddControllersWithViews();
  90. var app = builder.Build();
  91. // Configure the HTTP request pipeline.
  92. if (!app.Environment.IsDevelopment())
  93. {
  94. app.UseExceptionHandler("/Home/Error");
  95. // The default HSTS value is 30 days. You may want to change this for production scenarios, see https://aka.ms/aspnetcore-hsts.
  96. app.UseHsts();
  97. }
  98. app.UseHttpsRedirection();
  99. app.UseStaticFiles();
  100. app.UseRouting();
  101. app.UseCors(); //使用跨域設定
  102. app.UseHttpsRedirection(); //開發中暫時關掉
  103. app.UseAuthentication();
  104. app.UseAuthorization();
  105. //app.MapControllerRoute(
  106. // name: "default",
  107. // pattern: "{controller=Home}/{action=Index}/{id?}");
  108. app.UseEndpoints(endpoints => {
  109. endpoints.MapControllers();
  110. endpoints.MapFallbackToFile("index.html");
  111. endpoints.MapHub<SignalRScreenServerHub>("/signalr/screen").RequireCors("any");
  112. });
  113. app.Run();
  114. }
  115. }
  116. }