ExternalLogin.cshtml.cs 9.6 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223
  1. // Licensed to the .NET Foundation under one or more agreements.
  2. // The .NET Foundation licenses this file to you under the MIT license.
  3. #nullable disable
  4. using System;
  5. using System.ComponentModel.DataAnnotations;
  6. using System.Security.Claims;
  7. using System.Text;
  8. using System.Text.Encodings.Web;
  9. using System.Threading;
  10. using System.Threading.Tasks;
  11. using Microsoft.AspNetCore.Authorization;
  12. using Microsoft.Extensions.Options;
  13. using Microsoft.AspNetCore.Identity;
  14. using Microsoft.AspNetCore.Identity.UI.Services;
  15. using Microsoft.AspNetCore.Mvc;
  16. using Microsoft.AspNetCore.Mvc.RazorPages;
  17. using Microsoft.AspNetCore.WebUtilities;
  18. using Microsoft.Extensions.Logging;
  19. namespace bitforum.Areas.Identity.Pages.Account
  20. {
  21. [AllowAnonymous]
  22. public class ExternalLoginModel : PageModel
  23. {
  24. private readonly SignInManager<IdentityUser> _signInManager;
  25. private readonly UserManager<IdentityUser> _userManager;
  26. private readonly IUserStore<IdentityUser> _userStore;
  27. private readonly IUserEmailStore<IdentityUser> _emailStore;
  28. private readonly IEmailSender _emailSender;
  29. private readonly ILogger<ExternalLoginModel> _logger;
  30. public ExternalLoginModel(
  31. SignInManager<IdentityUser> signInManager,
  32. UserManager<IdentityUser> userManager,
  33. IUserStore<IdentityUser> userStore,
  34. ILogger<ExternalLoginModel> logger,
  35. IEmailSender emailSender)
  36. {
  37. _signInManager = signInManager;
  38. _userManager = userManager;
  39. _userStore = userStore;
  40. _emailStore = GetEmailStore();
  41. _logger = logger;
  42. _emailSender = emailSender;
  43. }
  44. /// <summary>
  45. /// This API supports the ASP.NET Core Identity default UI infrastructure and is not intended to be used
  46. /// directly from your code. This API may change or be removed in future releases.
  47. /// </summary>
  48. [BindProperty]
  49. public InputModel Input { get; set; }
  50. /// <summary>
  51. /// This API supports the ASP.NET Core Identity default UI infrastructure and is not intended to be used
  52. /// directly from your code. This API may change or be removed in future releases.
  53. /// </summary>
  54. public string ProviderDisplayName { get; set; }
  55. /// <summary>
  56. /// This API supports the ASP.NET Core Identity default UI infrastructure and is not intended to be used
  57. /// directly from your code. This API may change or be removed in future releases.
  58. /// </summary>
  59. public string ReturnUrl { get; set; }
  60. /// <summary>
  61. /// This API supports the ASP.NET Core Identity default UI infrastructure and is not intended to be used
  62. /// directly from your code. This API may change or be removed in future releases.
  63. /// </summary>
  64. [TempData]
  65. public string ErrorMessage { get; set; }
  66. /// <summary>
  67. /// This API supports the ASP.NET Core Identity default UI infrastructure and is not intended to be used
  68. /// directly from your code. This API may change or be removed in future releases.
  69. /// </summary>
  70. public class InputModel
  71. {
  72. /// <summary>
  73. /// This API supports the ASP.NET Core Identity default UI infrastructure and is not intended to be used
  74. /// directly from your code. This API may change or be removed in future releases.
  75. /// </summary>
  76. [Required]
  77. [EmailAddress]
  78. public string Email { get; set; }
  79. }
  80. public IActionResult OnGet() => RedirectToPage("./Login");
  81. public IActionResult OnPost(string provider, string returnUrl = null)
  82. {
  83. // Request a redirect to the external login provider.
  84. var redirectUrl = Url.Page("./ExternalLogin", pageHandler: "Callback", values: new { returnUrl });
  85. var properties = _signInManager.ConfigureExternalAuthenticationProperties(provider, redirectUrl);
  86. return new ChallengeResult(provider, properties);
  87. }
  88. public async Task<IActionResult> OnGetCallbackAsync(string returnUrl = null, string remoteError = null)
  89. {
  90. returnUrl = returnUrl ?? Url.Content("~/");
  91. if (remoteError != null)
  92. {
  93. ErrorMessage = $"Error from external provider: {remoteError}";
  94. return RedirectToPage("./Login", new { ReturnUrl = returnUrl });
  95. }
  96. var info = await _signInManager.GetExternalLoginInfoAsync();
  97. if (info == null)
  98. {
  99. ErrorMessage = "Error loading external login information.";
  100. return RedirectToPage("./Login", new { ReturnUrl = returnUrl });
  101. }
  102. // Sign in the user with this external login provider if the user already has a login.
  103. var result = await _signInManager.ExternalLoginSignInAsync(info.LoginProvider, info.ProviderKey, isPersistent: false, bypassTwoFactor: true);
  104. if (result.Succeeded)
  105. {
  106. _logger.LogInformation("{Name} logged in with {LoginProvider} provider.", info.Principal.Identity.Name, info.LoginProvider);
  107. return LocalRedirect(returnUrl);
  108. }
  109. if (result.IsLockedOut)
  110. {
  111. return RedirectToPage("./Lockout");
  112. }
  113. else
  114. {
  115. // If the user does not have an account, then ask the user to create an account.
  116. ReturnUrl = returnUrl;
  117. ProviderDisplayName = info.ProviderDisplayName;
  118. if (info.Principal.HasClaim(c => c.Type == ClaimTypes.Email))
  119. {
  120. Input = new InputModel
  121. {
  122. Email = info.Principal.FindFirstValue(ClaimTypes.Email)
  123. };
  124. }
  125. return Page();
  126. }
  127. }
  128. public async Task<IActionResult> OnPostConfirmationAsync(string returnUrl = null)
  129. {
  130. returnUrl = returnUrl ?? Url.Content("~/");
  131. // Get the information about the user from the external login provider
  132. var info = await _signInManager.GetExternalLoginInfoAsync();
  133. if (info == null)
  134. {
  135. ErrorMessage = "Error loading external login information during confirmation.";
  136. return RedirectToPage("./Login", new { ReturnUrl = returnUrl });
  137. }
  138. if (ModelState.IsValid)
  139. {
  140. var user = CreateUser();
  141. await _userStore.SetUserNameAsync(user, Input.Email, CancellationToken.None);
  142. await _emailStore.SetEmailAsync(user, Input.Email, CancellationToken.None);
  143. var result = await _userManager.CreateAsync(user);
  144. if (result.Succeeded)
  145. {
  146. result = await _userManager.AddLoginAsync(user, info);
  147. if (result.Succeeded)
  148. {
  149. _logger.LogInformation("User created an account using {Name} provider.", info.LoginProvider);
  150. var userId = await _userManager.GetUserIdAsync(user);
  151. var code = await _userManager.GenerateEmailConfirmationTokenAsync(user);
  152. code = WebEncoders.Base64UrlEncode(Encoding.UTF8.GetBytes(code));
  153. var callbackUrl = Url.Page(
  154. "/Account/ConfirmEmail",
  155. pageHandler: null,
  156. values: new { area = "Identity", userId = userId, code = code },
  157. protocol: Request.Scheme);
  158. await _emailSender.SendEmailAsync(Input.Email, "Confirm your email",
  159. $"Please confirm your account by <a href='{HtmlEncoder.Default.Encode(callbackUrl)}'>clicking here</a>.");
  160. // If account confirmation is required, we need to show the link if we don't have a real email sender
  161. if (_userManager.Options.SignIn.RequireConfirmedAccount)
  162. {
  163. return RedirectToPage("./RegisterConfirmation", new { Email = Input.Email });
  164. }
  165. await _signInManager.SignInAsync(user, isPersistent: false, info.LoginProvider);
  166. return LocalRedirect(returnUrl);
  167. }
  168. }
  169. foreach (var error in result.Errors)
  170. {
  171. ModelState.AddModelError(string.Empty, error.Description);
  172. }
  173. }
  174. ProviderDisplayName = info.ProviderDisplayName;
  175. ReturnUrl = returnUrl;
  176. return Page();
  177. }
  178. private IdentityUser CreateUser()
  179. {
  180. try
  181. {
  182. return Activator.CreateInstance<IdentityUser>();
  183. }
  184. catch
  185. {
  186. throw new InvalidOperationException($"Can't create an instance of '{nameof(IdentityUser)}'. " +
  187. $"Ensure that '{nameof(IdentityUser)}' is not an abstract class and has a parameterless constructor, or alternatively " +
  188. $"override the external login page in /Areas/Identity/Pages/Account/ExternalLogin.cshtml");
  189. }
  190. }
  191. private IUserEmailStore<IdentityUser> GetEmailStore()
  192. {
  193. if (!_userManager.SupportsUserEmail)
  194. {
  195. throw new NotSupportedException("The default UI requires a user store with email support.");
  196. }
  197. return (IUserEmailStore<IdentityUser>)_userStore;
  198. }
  199. }
  200. }