AuthService.cs 30 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857858859860861862863864865866867868869870871872873874875876877878879880881882883884885886887888889890891892893894895896897898899900901902903904905906907908909910911912913914
  1. using System;
  2. using System.Collections.Generic;
  3. using System.Drawing;
  4. using System.IO;
  5. using System.Net;
  6. using System.Security.Authentication;
  7. using System.Security.Cryptography;
  8. using System.Text;
  9. using System.Diagnostics;
  10. using System.Threading.Tasks;
  11. using System.Collections.Specialized;
  12. using FastReport.Utils;
  13. namespace FastReport.Auth
  14. {
  15. /// <summary>
  16. /// Service for working with auth in the Fast Report.
  17. /// </summary>
  18. public class AuthService
  19. {
  20. #region Private Fields
  21. private string code;
  22. private string code_verifier;
  23. private string nonce;
  24. private string scopes;
  25. private string session;
  26. private string state;
  27. private string redirectUri;
  28. #endregion Private Fields
  29. #region Public Properties
  30. /// <summary>
  31. /// Instance of default Service.
  32. /// </summary>
  33. public static AuthService Instance { get; } = new AuthService();
  34. /// <summary>
  35. /// Gets or sets indicator to enable or disable personalisation service
  36. /// </summary>
  37. public bool IsEnable { get; set; } = true;
  38. /// <summary>
  39. /// Setting of the service.
  40. /// </summary>
  41. public AppSettings Settings { get; } = new AppSettings();
  42. /// <summary>
  43. /// User of the service.
  44. /// </summary>
  45. public AppUser User { get; } = new AppUser();
  46. #endregion Public Properties
  47. #region Public Methods
  48. /// <summary>
  49. /// The method creates an sign in link.
  50. /// </summary>
  51. /// <returns></returns>
  52. public string GenerateSignInUri(string redirectURI)
  53. {
  54. try
  55. {
  56. this.nonce = NewRandomString(10);
  57. this.state = NewRandomString(64);
  58. this.code_verifier = NewRandomString(128);
  59. string codeChallenge = Sha256Url(code_verifier);
  60. StringBuilder sb = new StringBuilder(1024);
  61. sb.Append(Settings.Host + Settings.AuthorizationEndpoint).Append('?')
  62. .Append("response_type=").Append(Uri.EscapeDataString(Settings.ResponseType))
  63. .Append('&')
  64. .Append("client_id=").Append(Uri.EscapeDataString(Settings.ClientId))
  65. .Append('&')
  66. .Append("nonce=").Append(Uri.EscapeDataString(this.nonce))
  67. .Append('&')
  68. .Append("redirect_uri=").Append(Uri.EscapeDataString(redirectURI))
  69. .Append('&')
  70. .Append("scope=").Append(Uri.EscapeDataString(Settings.Scopes))
  71. //.Append('&')
  72. //.Append("response_mode=").Append(Uri.EscapeDataString(Settings.ResponseMode))
  73. .Append('&')
  74. .Append("code_challenge_method=").Append(Uri.EscapeDataString(Settings.CodeChallengeMethod))
  75. .Append('&')
  76. .Append("code_challenge=").Append(Uri.EscapeDataString(codeChallenge))
  77. .Append('&')
  78. .Append("state=").Append(Uri.EscapeDataString(this.state));
  79. ;
  80. return sb.ToString();
  81. }
  82. catch (Exception e)
  83. {
  84. throw new AuthenticationException("Error generating sign in uri, maybe one of the path parameters is null.", e);
  85. }
  86. }
  87. /// <summary>
  88. /// The method creates an sign out link.
  89. /// </summary>
  90. /// <returns></returns>
  91. public string GenerateSignOutUri(string redirectURI)
  92. {
  93. try
  94. {
  95. StringBuilder sb = new StringBuilder(1024);
  96. sb.Append(Settings.Host + Settings.EndSessionEndpoint).Append('?')
  97. .Append("id_token_hint=")
  98. .Append(Uri.EscapeDataString(User.IdToken))
  99. .Append("&post_logout_redirect_uri=")
  100. .Append(Uri.EscapeDataString(redirectURI));
  101. return sb.ToString();
  102. }
  103. catch (Exception e)
  104. {
  105. throw new AuthenticationException("Error generating sign out uri, maybe one of the path parameters is null.", e);
  106. }
  107. }
  108. /// <summary>
  109. /// Returns true, if user has offline_access scope and refresh_token is not null
  110. /// </summary>
  111. public bool CanRefresh
  112. {
  113. get
  114. {
  115. return !String.IsNullOrEmpty(User.RefreshToken) && (User.Scopes == null || User.Scopes != null && Contains(User.Scopes, "offline_access"));
  116. }
  117. }
  118. /// <summary>
  119. /// If possible, the method updates the user credentials.
  120. /// </summary>
  121. /// <returns>True if success</returns>
  122. public bool Refresh()
  123. {
  124. try
  125. {
  126. if (CanRefresh)
  127. {
  128. var request = HttpWebRequest.Create(new Uri(Settings.Host + Settings.TokenEndpoint));
  129. request.Method = "POST";
  130. request.ContentType = "application/x-www-form-urlencoded";
  131. using (Stream requestStream = request.GetRequestStream())
  132. {
  133. byte[] bytes = Encoding.UTF8.GetBytes(GenerateTokenRequestBodyByRefresh());
  134. requestStream.Write(bytes, 0, bytes.Length);
  135. }
  136. using (var response = request.GetResponse())
  137. {
  138. using (Stream responseStream = response.GetResponseStream())
  139. {
  140. using (TextReader tr = new StreamReader(responseStream, Encoding.UTF8))
  141. {
  142. var result = tr.ReadToEnd();
  143. SaveTokens(result);
  144. ValidateTokens();
  145. ParseTokens();
  146. }
  147. }
  148. }
  149. }
  150. return true;
  151. }
  152. catch (Exception ex)
  153. {
  154. User.RefreshToken = null;
  155. }
  156. return false;
  157. }
  158. /// <summary>
  159. /// The method resets auth, without sign out process.
  160. /// </summary>
  161. public void Reset()
  162. {
  163. User.Reset();
  164. }
  165. /// <summary>
  166. /// The method shows sign in form and auth the user.
  167. /// </summary>
  168. public void SignIn()
  169. {
  170. NameValueCollection queryString;
  171. using(var authServer = new TCPServerListener())
  172. {
  173. redirectUri = authServer.RedirectURL;
  174. redirectUri = redirectUri.Remove(redirectUri.Length - 1);
  175. var uri = GenerateSignInUri(redirectUri + Settings.RedirectSignInUri);
  176. authServer.Open();
  177. ProcessHelper.StartProcess(uri);
  178. var context = authServer.WaitConnect();
  179. var response = context.Response;
  180. var request = context.Request;
  181. response.Redirect(Settings.Host + Settings.RedirectSignInUri);
  182. response.OutputStream.Close();
  183. queryString = request.QueryString;
  184. }
  185. SignInCalback(queryString);
  186. }
  187. /// <summary>
  188. /// The method shows sign out form and resets the user credentials.
  189. /// </summary>
  190. public void SignOut()
  191. {
  192. using (var authServer = new TCPServerListener())
  193. {
  194. redirectUri = authServer.RedirectURL;
  195. redirectUri = redirectUri.Remove(redirectUri.Length - 1);
  196. string uri = GenerateSignOutUri(redirectUri + Settings.RedirectSignOutUri);
  197. authServer.Open();
  198. ProcessHelper.StartProcess(uri);
  199. var context = authServer.WaitConnect();
  200. var response = context.Response;
  201. response.Redirect(Settings.Host + Settings.RedirectSignInUri);
  202. response.OutputStream.Close();
  203. }
  204. User.Reset();
  205. }
  206. #endregion Public Methods
  207. #region Internal Methods
  208. internal static string NewRandomString(int v)
  209. {
  210. const string chars = "abcdefghijklmnopqrstuvwxyz1234567890";
  211. Random r = new Random();
  212. StringBuilder sb = new StringBuilder(v);
  213. for (int i = 0; i < v; i++)
  214. {
  215. sb.Append(chars[r.Next(chars.Length)]);
  216. }
  217. return sb.ToString();
  218. }
  219. #endregion Internal Methods
  220. #region Private Methods
  221. private void SignInCalback(NameValueCollection queryString)
  222. {
  223. // Checks for errors.
  224. if (HasError(queryString))
  225. return;
  226. Process(queryString);
  227. SignInPart2SecondRequest();
  228. }
  229. private bool HasError(NameValueCollection query)
  230. {
  231. var error = query.Get("error");
  232. if (error != null)
  233. {
  234. if (error == "access_denied")
  235. return true;
  236. else
  237. throw new AuthenticationException(error);
  238. //output(String.Format("OAuth authorization error: {0}.", error));
  239. }
  240. return false;
  241. }
  242. private static string Base64UrlToBase64(string base64url)
  243. {
  244. string base64 = base64url.Replace('-', '+').Replace('_', '/');
  245. if (base64.Length % 4 != 0)
  246. {
  247. base64 += new string('=', 4 - base64.Length % 4);
  248. }
  249. return base64;
  250. }
  251. private static string ConvertToString(object v, string defaultValue)
  252. {
  253. if (v != null)
  254. return v.ToString();
  255. return defaultValue;
  256. }
  257. private static string Sha256Url(string input)
  258. {
  259. if (String.IsNullOrEmpty(input))
  260. return string.Empty;
  261. using (var sha = SHA256.Create())
  262. {
  263. var bytes = Encoding.UTF8.GetBytes(input);
  264. var hash = sha.ComputeHash(bytes);
  265. return Convert.ToBase64String(hash).Replace('+', '-').Replace('/', '_').Replace("=", "");
  266. }
  267. }
  268. private static bool Contains(IEnumerable<string> scopes, string value)
  269. {
  270. foreach (string scope in scopes)
  271. {
  272. if (scope == value)
  273. return true;
  274. }
  275. return false;
  276. }
  277. private Stream Download(string url)
  278. {
  279. MemoryStream memoryStream = new MemoryStream();
  280. #if MONO
  281. ServicePointManager.Expect100Continue = true;
  282. ServicePointManager.SecurityProtocol = SecurityProtocolType.Tls12;
  283. #endif
  284. try
  285. {
  286. // send second request
  287. var request = HttpWebRequest.Create(new Uri(url));
  288. request.Method = "GET";
  289. using (var response = request.GetResponse())
  290. {
  291. using (Stream responseStream = response.GetResponseStream())
  292. {
  293. responseStream.CopyTo(memoryStream);
  294. }
  295. }
  296. }
  297. catch
  298. {
  299. }
  300. memoryStream.Position = 0;
  301. return memoryStream;
  302. }
  303. private string GenerateTokenRequestBodyByCode(string redirectUri)
  304. {
  305. try
  306. {
  307. StringBuilder sb = new StringBuilder(1024);
  308. sb
  309. .Append("grant_type=authorization_code")
  310. //.Append(Uri.EscapeDataString(Settings.GrandType))
  311. .Append("&client_id=").Append(Uri.EscapeDataString(Settings.ClientId))
  312. .Append("&scope=").Append(Uri.EscapeDataString(this.scopes))
  313. .Append("&redirect_uri=").Append(Uri.EscapeDataString(redirectUri))
  314. .Append("&code=").Append(Uri.EscapeDataString(this.code))
  315. .Append("&code_verifier=").Append(Uri.EscapeDataString(this.code_verifier))
  316. .Append("&client_secret=").Append(Uri.EscapeDataString(Settings.ClientSecret));
  317. return sb.ToString();
  318. }
  319. catch (Exception e)
  320. {
  321. throw new AuthenticationException("Error generating token request body, maybe one of the path parameters is null.", e);
  322. }
  323. }
  324. private string GenerateTokenRequestBodyByRefresh()
  325. {
  326. try
  327. {
  328. StringBuilder sb = new StringBuilder(1024);
  329. sb
  330. .Append("grant_type=refresh_token")
  331. //.Append(Uri.EscapeDataString(Settings.GrandType))
  332. .Append("&client_id=").Append(Uri.EscapeDataString(Settings.ClientId))
  333. .Append("&refresh_token=").Append(Uri.EscapeDataString(User.RefreshToken))
  334. .Append("&client_secret=").Append(Uri.EscapeDataString(Settings.ClientSecret));
  335. ;
  336. if (User.Scopes != null && User.Scopes.Length > 0)
  337. {
  338. sb.Append("&scope=").Append(Uri.EscapeDataString(String.Join(" ", User.Scopes)));
  339. }
  340. return sb.ToString();
  341. }
  342. catch (Exception e)
  343. {
  344. throw new AuthenticationException("Error generating token request body, maybe one of the path parameters is null.", e);
  345. }
  346. }
  347. private string Gravatar(string email)
  348. {
  349. MD5 md5Hasher = MD5.Create();
  350. byte[] data = md5Hasher.ComputeHash(Encoding.Default.GetBytes(email));
  351. StringBuilder sBuilder = new StringBuilder("https://www.gravatar.com/avatar/");
  352. for (int i = 0; i < data.Length; i++)
  353. {
  354. sBuilder.Append(data[i].ToString("x2"));
  355. }
  356. sBuilder.Append("?s=150");
  357. return sBuilder.ToString();
  358. }
  359. /// <summary>
  360. /// Do not make this method public, use refresh token for save-load. <br/>
  361. /// You need only refresh token (<see cref="AppUser.RefreshToken"/>) to get a new token set.<br/>
  362. /// This method is used to save time for starting a designer.
  363. /// </summary>
  364. internal void ParseTokens(bool isProgramStart = false)
  365. {
  366. try
  367. {
  368. if (!String.IsNullOrEmpty(User.IdToken))
  369. {
  370. string[] token = User.IdToken.Split('.');
  371. string payload = token[1];
  372. JsonBase json
  373. = JsonBase.FromString(
  374. Encoding.UTF8.GetString(
  375. Convert.FromBase64String(
  376. Base64UrlToBase64(payload)
  377. )
  378. )
  379. );
  380. User.Subject = ConvertToString(json["sub"], "");
  381. User.Email = ConvertToString(json["email"], "");
  382. User.Username = ConvertToString(json["preferred_username"], User.Email);
  383. User.FullName = ConvertToString(json["name"], "");
  384. if ((ConvertToString(json["nonce"], nonce) != nonce) && !isProgramStart)
  385. {
  386. throw new AuthenticationException("Nonce check error, token is not valid.");
  387. }
  388. try
  389. {
  390. var url = Gravatar(User.Email);
  391. var ms = Download(url);
  392. User.Avatar = Image.FromStream(ms);
  393. }
  394. catch (Exception e)
  395. {
  396. User.Avatar = null;
  397. }
  398. }
  399. }
  400. catch (AuthenticationException e)
  401. {
  402. User.IdToken = "";
  403. throw e;
  404. }
  405. catch (Exception e)
  406. {
  407. User.IdToken = "";
  408. throw new AuthenticationException("Identity token parse error!", e);
  409. }
  410. try
  411. {
  412. if (!String.IsNullOrEmpty(User.Token))
  413. {
  414. string[] token = User.Token.Split('.');
  415. string payload = token[1];
  416. JsonBase json
  417. = JsonBase.FromString(
  418. Encoding.UTF8.GetString(
  419. Convert.FromBase64String(
  420. Base64UrlToBase64(payload)
  421. )
  422. )
  423. );
  424. double nbf = Convert.ToDouble(json["nbf"]);
  425. double exp = Convert.ToDouble(json["exp"]);
  426. double time = exp - nbf;
  427. User.ExpiresIn = new DateTime(1970, 1, 1, 0, 0, 0, 0).AddSeconds(exp).ToLocalTime();
  428. User.ExpiresInternal = new DateTime(1970, 1, 1, 0, 0, 0, 0).AddSeconds(nbf + time * 0.95).ToLocalTime();
  429. JsonBase scopes = json["scope"] as JsonBase;
  430. if (scopes != null && scopes.IsArray)
  431. {
  432. List<string> allowedScopes = new List<string>();
  433. for (int i = 0; i < scopes.Count; i++)
  434. {
  435. allowedScopes.Add(scopes[i].ToString());
  436. }
  437. User.Scopes = allowedScopes.ToArray();
  438. }
  439. }
  440. }
  441. catch (AuthenticationException e)
  442. {
  443. User.Token = "";
  444. throw e;
  445. }
  446. catch (Exception e)
  447. {
  448. User.Token = "";
  449. throw new AuthenticationException("Access token parse error!", e);
  450. }
  451. }
  452. private void Process(NameValueCollection query)
  453. {
  454. foreach (var key in query.AllKeys)
  455. {
  456. var value = query[key];
  457. switch (key.ToLower())
  458. {
  459. case "code":
  460. this.code = value;
  461. break;
  462. case "scope":
  463. scopes = value;
  464. break;
  465. case "state":
  466. if (value != this.state)
  467. throw new Exception("State is not valid");
  468. break;
  469. case "session_state":
  470. this.session = value;
  471. break;
  472. }
  473. }
  474. }
  475. private void SaveTokens(string result)
  476. {
  477. JsonBase json = JsonBase.FromString(result);
  478. if (json.ContainsKey("expires_in"))
  479. {
  480. var expiresIn = Convert.ToSingle(json["expires_in"]);
  481. User.ExpiresIn = DateTime.Now.AddSeconds(expiresIn);
  482. User.ExpiresInternal = DateTime.Now.AddSeconds(expiresIn * 0.95);
  483. }
  484. else
  485. {
  486. // if no expires_in value, then default token lifetime
  487. User.ExpiresIn = DateTime.Now.AddMinutes(5);
  488. User.ExpiresInternal = User.ExpiresIn;
  489. }
  490. if (!json.ContainsKey("id_token"))
  491. {
  492. throw new AuthenticationException("No id token provided in server response.");
  493. }
  494. if (!json.ContainsKey("access_token"))
  495. {
  496. throw new AuthenticationException("No access token provided in server response.");
  497. }
  498. if (!json.ContainsKey("token_type"))
  499. {
  500. throw new AuthenticationException("No token type provided in server response.");
  501. }
  502. User.IdToken = json.ReadString("id_token");
  503. User.Token = json.ReadString("access_token");
  504. User.TokenType = json.ReadString("token_type");
  505. User.RefreshToken = json.ReadString("refresh_token");
  506. }
  507. private void SignInPart2SecondRequest()
  508. {
  509. var request = HttpWebRequest.Create(new Uri(Settings.Host + Settings.TokenEndpoint));
  510. request.Method = "POST";
  511. request.ContentType = "application/x-www-form-urlencoded";
  512. using (Stream requestStream = request.GetRequestStream())
  513. {
  514. string requestBody = GenerateTokenRequestBodyByCode(redirectUri + Settings.RedirectSignInUri);
  515. byte[] bytes = Encoding.UTF8.GetBytes(requestBody);
  516. requestStream.Write(bytes, 0, bytes.Length);
  517. }
  518. using (var response = request.GetResponse())
  519. {
  520. using (Stream responseStream = response.GetResponseStream())
  521. {
  522. using (TextReader tr = new StreamReader(responseStream, Encoding.UTF8))
  523. {
  524. var result = tr.ReadToEnd();
  525. SaveTokens(result);
  526. ValidateTokens();
  527. ParseTokens();
  528. }
  529. }
  530. }
  531. }
  532. private void ValidateTokens()
  533. {
  534. // External library for validation signature on tokens
  535. User.IsValid = false;
  536. }
  537. #endregion Private Methods
  538. #region Public Classes
  539. /// <summary>
  540. /// Class for store appsettings, by default appsettings is hardcoded.
  541. /// </summary>
  542. public class AppSettings
  543. {
  544. internal const string DefaultBackendHost = "https://fastreport.cloud";
  545. #region Public Properties
  546. /// <summary>
  547. /// Authorization Endpoint from the OAuth2 specification.
  548. /// </summary>
  549. public string AuthorizationEndpoint { get; set; } = "/connect/authorize";
  550. /// <summary>
  551. /// Host for callback requests.
  552. /// </summary>
  553. public string CallbackHost { get; set; } = "https://id.fast-report.com";
  554. /// <summary>
  555. /// Client identifier or client name from the OAuth2 specification.
  556. /// </summary>
  557. public string ClientId { get; set; } = "FastReport.Net.Designer";
  558. /// <summary>
  559. /// Client secret or client name from the OAuth2 specification.
  560. /// </summary>
  561. public string ClientSecret { get; set; } = "91d18a32-1630-66d5-7f43-05d6e2caf02f";
  562. /// <summary>
  563. /// Code challenge method from the OAuth2 specification.
  564. /// </summary>
  565. public string CodeChallengeMethod { get; set; } = "S256";
  566. /// <summary>
  567. /// EndSession Endpoint from the OAuth2 specification.
  568. /// </summary>
  569. public string EndSessionEndpoint { get; set; } = "/connect/endsession";
  570. /// <summary>
  571. /// Host for sign in requests
  572. /// </summary>
  573. public string Host { get; set; } = "https://id.fast-report.com";
  574. // TODO:
  575. internal string BackendHost { get; set; } = DefaultBackendHost;
  576. /// <summary>
  577. /// JSON Web Key Set Endpoint from the OAuth2 specification.
  578. /// </summary>
  579. public string JwksEndpoint { get; set; } = "/.well-known/openid-configuration/jwks";
  580. /// <summary>
  581. /// Error result
  582. /// </summary>
  583. public string RedirectError { get; set; } = "/home/error";
  584. /// <summary>
  585. /// Redirent sign in link for this application.
  586. /// </summary>
  587. public string RedirectSignInUri { get; set; } = "/native/sign-in";
  588. /// <summary>
  589. /// Redirent sign out link for this application.
  590. /// </summary>
  591. public string RedirectSignOutUri { get; set; } = "/native/sign-out";
  592. /// <summary>
  593. /// Success result
  594. /// </summary>
  595. public string RedirectSuccess { get; set; } = "/home/success";
  596. /// <summary>
  597. /// Type of the reponse from the OAuth2 specification.
  598. /// </summary>
  599. public string ResponseType { get; set; } = "code";
  600. /// <summary>
  601. /// Scopes for the request from the OAuth2 specification, splited by space.
  602. /// </summary>
  603. public string Scopes { get; set; } = "openid email profile offline_access";
  604. /// <summary>
  605. /// Token Endpoint from the OAuth2 specification.
  606. /// </summary>
  607. public string TokenEndpoint { get; set; } = "/connect/token";
  608. #endregion Public Properties
  609. }
  610. public class AppUser
  611. {
  612. #region Private Fields
  613. private Image avatar;
  614. private Image defaultAvatar;
  615. #endregion Private Fields
  616. #region Public Properties
  617. /// <summary>
  618. /// Avatar of the user, by default is 150x150 picture.
  619. /// </summary>
  620. public Image Avatar
  621. {
  622. get { return avatar; }
  623. set
  624. {
  625. if (avatar != null)
  626. avatar.Dispose();
  627. avatar = value;
  628. }
  629. }
  630. /// <summary>
  631. /// Returns the display avatar of the user, cannot return null
  632. /// </summary>
  633. /// <returns></returns>
  634. public Image DisplayAvatar
  635. {
  636. get
  637. {
  638. if (avatar != null)
  639. return avatar;
  640. if (defaultAvatar == null)
  641. defaultAvatar = ResourceLoader.GetBitmap("defaultAvatar.jpg");
  642. return defaultAvatar;
  643. }
  644. }
  645. /// <summary>
  646. /// Returns the display email of the user, cannot return null
  647. /// </summary>
  648. /// <returns></returns>
  649. public string DisplayEmail
  650. {
  651. get
  652. {
  653. if (Email == null)
  654. return "";
  655. return Email;
  656. }
  657. }
  658. /// <summary>
  659. /// Returns the display name of the user, cannot return null
  660. /// </summary>
  661. /// <returns></returns>
  662. public string DisplayName
  663. {
  664. get
  665. {
  666. if (String.IsNullOrEmpty(FullName))
  667. {
  668. if (String.IsNullOrEmpty(Username))
  669. {
  670. if (String.IsNullOrEmpty(Subject))
  671. {
  672. return "";
  673. }
  674. return Subject;
  675. }
  676. return Username;
  677. }
  678. return FullName;
  679. }
  680. }
  681. /// <summary>
  682. /// Email of the user.
  683. /// </summary>
  684. public string Email { get; set; }
  685. /// <summary>
  686. /// Local time when the token will go out.
  687. /// </summary>
  688. public DateTime ExpiresIn { get; set; }
  689. /// <summary>
  690. /// Full name of the user.
  691. /// </summary>
  692. public string FullName { get; set; }
  693. /// <summary>
  694. /// Returns true if user is authenticated.
  695. /// </summary>
  696. public bool IsAuthenticated
  697. {
  698. get
  699. {
  700. return !String.IsNullOrEmpty(IdToken) && !String.IsNullOrEmpty(Token);
  701. }
  702. }
  703. /// <summary>
  704. /// Returns true if token is expired and is need to referesh
  705. /// </summary>
  706. public bool IsExpired
  707. {
  708. get
  709. {
  710. return ExpiresInternal < DateTime.Now;
  711. }
  712. }
  713. /// <summary>
  714. /// Indicates that token is check by external method, see <see cref="TokenValidator.CustomValidator"/> for details.
  715. /// </summary>
  716. public bool IsValid { get; set; }
  717. /// <summary>
  718. /// List of allowed scopes.
  719. /// </summary>
  720. public string[] Scopes { get; set; }
  721. /// <summary>
  722. /// Identifier of the user.
  723. /// </summary>
  724. public string Subject { get; set; }
  725. /// <summary>
  726. /// Type of token for resource request header, e.g. Bearer.
  727. /// </summary>
  728. public string TokenType { get; set; }
  729. /// <summary>
  730. /// Preferred username of the user.
  731. /// </summary>
  732. public string Username { get; set; }
  733. /// <summary>
  734. /// User's api key.
  735. /// </summary>
  736. public string ApiKey { get; set; }
  737. #endregion Public Properties
  738. #region Internal Properties
  739. /// <summary>
  740. /// Local time when the token needs to be updated.
  741. /// </summary>
  742. internal DateTime ExpiresInternal { get; set; }
  743. internal string IdToken { get; set; }
  744. internal string RefreshToken { get; set; }
  745. internal string Token { get; set; }
  746. #endregion Internal Properties
  747. #region Public Methods
  748. /// <summary>
  749. /// Reset the values
  750. /// </summary>
  751. public void Reset()
  752. {
  753. Avatar = null;
  754. Email = null;
  755. ExpiresIn = DateTime.MinValue;
  756. FullName = null;
  757. IdToken = null;
  758. IsValid = false;
  759. RefreshToken = null;
  760. Scopes = null;
  761. Subject = null;
  762. Token = null;
  763. TokenType = null;
  764. Username = null;
  765. }
  766. #endregion Public Methods
  767. }
  768. #endregion Public Classes
  769. }
  770. }