SuperApiAop.cs 4.4 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111
  1. // Admin.NET 项目的版权、商标、专利和其他相关权利均受相应法律法规的保护。使用本项目应遵守相关法律法规和许可证的要求。
  2. //
  3. // 本项目主要遵循 MIT 许可证和 Apache 许可证(版本 2.0)进行分发和使用。许可证位于源代码树根目录中的 LICENSE-MIT 和 LICENSE-APACHE 文件。
  4. //
  5. // 不得利用本项目从事危害国家安全、扰乱社会秩序、侵犯他人合法权益等法律法规禁止的活动!任何基于本项目二次开发而产生的一切法律纠纷和责任,我们不承担任何责任!
  6. using Admin.NET.Core;
  7. using Furion.ClayObject;
  8. using Furion.DataEncryption;
  9. using Furion.FriendlyException;
  10. using Furion.JsonSerialization;
  11. using Microsoft.AspNetCore.Authentication;
  12. using Microsoft.AspNetCore.Authentication.JwtBearer;
  13. using Microsoft.AspNetCore.Http;
  14. using Microsoft.Extensions.Logging;
  15. using ReZero.SuperAPI;
  16. namespace Admin.NET.Plugin.ReZero.Service;
  17. /// <summary>
  18. /// 超级API接口拦截器
  19. /// </summary>
  20. public class SuperApiAop : DefaultSuperApiAop
  21. {
  22. public override async Task OnExecutingAsync(InterfaceContext aopContext)
  23. {
  24. //if (aopContext.InterfaceType == InterfaceType.DynamicApi)
  25. //{
  26. var authenticateResult = await aopContext.HttpContext.AuthenticateAsync(JwtBearerDefaults.AuthenticationScheme);
  27. if (!authenticateResult.Succeeded)
  28. throw Oops.Oh("没权限 Unauthorized");
  29. //}
  30. var accessToken = aopContext.HttpContext.Request.Headers["Authorization"].ToString();
  31. var (isValid, tokenData, validationResult) = JWTEncryption.Validate(accessToken.Replace("Bearer ", ""));
  32. if (!isValid)
  33. throw Oops.Oh("Token 无效");
  34. await base.OnExecutingAsync(aopContext);
  35. }
  36. public override async Task OnExecutedAsync(InterfaceContext aopContext)
  37. {
  38. InitLogContext(aopContext, LogLevel.Information);
  39. await base.OnExecutedAsync(aopContext);
  40. }
  41. public override async Task OnErrorAsync(InterfaceContext aopContext)
  42. {
  43. InitLogContext(aopContext, LogLevel.Error);
  44. await base.OnErrorAsync(aopContext);
  45. }
  46. /// <summary>
  47. /// 保存超级API接口日志
  48. /// </summary>
  49. /// <param name="aopContext"></param>
  50. /// <param name="logLevel"></param>
  51. private void InitLogContext(InterfaceContext aopContext, LogLevel logLevel)
  52. {
  53. var api = aopContext.InterfaceInfo;
  54. var context = aopContext.HttpContext;
  55. var accessToken = context.Request.Headers["Authorization"].ToString();
  56. if (!string.IsNullOrWhiteSpace(accessToken) && accessToken.StartsWith("Bearer "))
  57. accessToken = accessToken.Replace("Bearer ", "");
  58. var claims = JWTEncryption.ReadJwtToken(accessToken)?.Claims;
  59. var userName = claims?.FirstOrDefault(u => u.Type == ClaimConst.Account)?.Value;
  60. var realName = claims?.FirstOrDefault(u => u.Type == ClaimConst.RealName)?.Value;
  61. var paths = api.Url.Split('/');
  62. var actionName = paths[paths.Length - 1];
  63. var apiInfo = Clay.Object(new
  64. {
  65. requestUrl = api.Url,
  66. httpMethod = api.HttpMethod,
  67. displayTitle = api.Name,
  68. actionTypeName = actionName,
  69. controllerName = aopContext.InterfaceType == InterfaceType.DynamicApi ? $"ReZero动态-{api.GroupName}" : $"ReZero系统-{api.GroupName}",
  70. remoteIPv4 = context.GetRemoteIpAddressToIPv4(),
  71. userAgent = context.Request.Headers["User-Agent"],
  72. returnInformation = new
  73. {
  74. httpStatusCode = context.Response.StatusCode,
  75. },
  76. authorizationClaims = new[]
  77. {
  78. new
  79. {
  80. type = ClaimConst.Account,
  81. value = userName
  82. },
  83. new
  84. {
  85. type = ClaimConst.RealName,
  86. value = realName
  87. },
  88. },
  89. exception = aopContext.Exception == null ? null : JSON.Serialize(aopContext.Exception)
  90. });
  91. var logger = App.GetRequiredService<ILoggerFactory>().CreateLogger(CommonConst.SysLogCategoryName);
  92. using var scope = logger.ScopeContext(new Dictionary<object, object> {
  93. { "loggingMonitor", apiInfo.ToString() }
  94. });
  95. logger.Log(logLevel, "ReZero超级API接口日志");
  96. }
  97. }