API

RegisterController.cs 5.2KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170
  1. using System;
  2. using System.Collections.Generic;
  3. using System.IdentityModel.Tokens.Jwt;
  4. using System.Linq;
  5. using System.Security.Claims;
  6. using System.Text;
  7. using System.Threading.Tasks;
  8. using AutoMapper;
  9. using Microsoft.AspNetCore.Authorization;
  10. using Microsoft.AspNetCore.Mvc;
  11. using Microsoft.Extensions.Options;
  12. using Microsoft.IdentityModel.Tokens;
  13. using UnivateProperties_API.Containers.Users;
  14. using UnivateProperties_API.Helpers;
  15. using UnivateProperties_API.Model.Users;
  16. using UnivateProperties_API.Repository;
  17. using UnivateProperties_API.Repository.Users;
  18. using System.Net.Http;
  19. using System.Net;
  20. using System.Web.Http;
  21. namespace UnivateProperties_API.Controllers.Users
  22. {
  23. [Route("api/[controller]")]
  24. [ApiController]
  25. public class RegisterController : ControllerBase
  26. {
  27. private readonly IRegisterRepository _Repo;
  28. private IMapper _mapper;
  29. private readonly AppSettings _appSettings;
  30. public RegisterController(IRegisterRepository repo, IMapper mapper, IOptions<AppSettings> appSettings)
  31. {
  32. _Repo = repo;
  33. _mapper = mapper;
  34. _appSettings = appSettings.Value;
  35. }
  36. //Works
  37. [AllowAnonymous]
  38. [HttpPost("authenticate")]
  39. public IActionResult Authenticate([FromBody]UserDto userDto)
  40. {
  41. var user = _Repo.Authenticate(userDto.Username, userDto.Password);
  42. //HttpResponseMessage response = Request.CreateResponse(HttpStatusCode.Unauthorized, "value");
  43. if (user == null)
  44. return BadRequest(new { message = "Username or password is incorrect" });
  45. var tokenHandler = new JwtSecurityTokenHandler();
  46. var key = Encoding.ASCII.GetBytes(_appSettings.Secret);
  47. var tokenDescriptor = new SecurityTokenDescriptor
  48. {
  49. Subject = new ClaimsIdentity(new Claim[]
  50. {
  51. new Claim(ClaimTypes.Name, user.Id.ToString()),
  52. //new Claim(ClaimTypes.Role, user.Role)
  53. }),
  54. Expires = DateTime.UtcNow.AddMinutes(15),
  55. SigningCredentials = new SigningCredentials(new SymmetricSecurityKey(key), SecurityAlgorithms.HmacSha256Signature)
  56. };
  57. var token = tokenHandler.CreateToken(tokenDescriptor);
  58. var tokenString = tokenHandler.WriteToken(token);
  59. // return basic user info (without password) and token to store client side
  60. return Ok(new
  61. {
  62. user.Id,
  63. user.Username,
  64. Token = tokenString
  65. });
  66. }
  67. //Writes to DB
  68. [AllowAnonymous]
  69. [HttpPost("register")]
  70. public IActionResult Register([FromBody]UserDto individual)
  71. {
  72. _mapper.Map<Individual>(individual);
  73. try
  74. {
  75. _Repo.CreatePerson(individual, PersonType.Individual, true, null);
  76. return Ok();
  77. }
  78. catch (AppException ex)
  79. {
  80. return BadRequest(new { messge = ex.Message });
  81. }
  82. }
  83. //Writes to DB
  84. [AllowAnonymous]
  85. [HttpPost("registeragency")]
  86. public IActionResult RegisterAgency([FromBody]AgencyDto agency)
  87. {
  88. // map dto to entity
  89. _mapper.Map<Agency>(agency);
  90. try
  91. {
  92. // save
  93. _Repo.CreateAgency(agency);
  94. return Ok();
  95. }
  96. catch (AppException ex)
  97. {
  98. // return error message if there was an exception
  99. return BadRequest(new { message = ex.Message });
  100. }
  101. }
  102. //[HttpGet("{id}")]
  103. //public IActionResult GetById(int id)
  104. //{
  105. // var user = _Repo.GetById(id);
  106. // var userDto = _mapper.Map<UserDto>(user);
  107. // if (user == null)
  108. // {
  109. // return NotFound();
  110. // }
  111. // // Only allow SuperAdmins to access other user records
  112. // var currentUserId = int.Parse(User.Identity.Name);
  113. // if (id != currentUserId && !User.IsInRole(Role.SuperAdmin))
  114. // {
  115. // return Forbid();
  116. // }
  117. // return Ok(userDto);
  118. //}
  119. //[HttpGet("{id}")]
  120. //public IActionResult GetByAgencyId(int id)
  121. //{
  122. // var agency = _Repo.GetByAgencyId(id);
  123. // var agencyDto = _mapper.Map<AgencyDto>(agency);
  124. // if (agency == null)
  125. // {
  126. // return NotFound();
  127. // }
  128. // var currentAgencyId = int.Parse(User.Identity.Name);
  129. // if (id != currentAgencyId && !User.IsInRole(Role.Agency))
  130. // {
  131. // return Forbid();
  132. // }
  133. // return Ok(agencyDto);
  134. //}
  135. //[Authorize(Roles = Role.SuperAdmin)]
  136. //[HttpDelete("{id}")]
  137. //public IActionResult Delete(User user)
  138. //{
  139. // _Repo.Delete(user.Id);
  140. // return Ok();
  141. //}
  142. //[Authorize(Roles = Role.SuperAdmin)]
  143. //[HttpDelete("{id}")]
  144. //public IActionResult DeleteAgency(Agency agency)
  145. //{
  146. // _Repo.DeleteAgency(agency.Id);
  147. // return Ok();
  148. //}
  149. }
  150. }