Startup.cs 16 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407
  1. // Admin.NET 项目的版权、商标、专利和其他相关权利均受相应法律法规的保护。使用本项目应遵守相关法律法规和许可证的要求。
  2. //
  3. // 本项目主要遵循 MIT 许可证和 Apache 许可证(版本 2.0)进行分发和使用。许可证位于源代码树根目录中的 LICENSE-MIT 和 LICENSE-APACHE 文件。
  4. //
  5. // 不得利用本项目从事危害国家安全、扰乱社会秩序、侵犯他人合法权益等法律法规禁止的活动!任何基于本项目二次开发而产生的一切法律纠纷和责任,我们不承担任何责任!
  6. using Admin.NET.Core;
  7. using Admin.NET.Core.ElasticSearch;
  8. using Admin.NET.Core.Service;
  9. using AspNetCoreRateLimit;
  10. using Furion;
  11. using Furion.Logging;
  12. using Furion.SpecificationDocument;
  13. using Furion.VirtualFileServer;
  14. using IPTools.Core;
  15. using Microsoft.AspNetCore.Authentication.JwtBearer;
  16. using Microsoft.AspNetCore.Builder;
  17. using Microsoft.AspNetCore.Hosting;
  18. using Microsoft.AspNetCore.Http;
  19. using Microsoft.AspNetCore.HttpOverrides;
  20. using Microsoft.AspNetCore.ResponseCompression;
  21. using Microsoft.Extensions.DependencyInjection;
  22. using Microsoft.Extensions.Hosting;
  23. using Newtonsoft.Json;
  24. using OnceMi.AspNetCore.OSS;
  25. using Scalar.AspNetCore;
  26. using SixLabors.ImageSharp.Web.DependencyInjection;
  27. using System;
  28. using System.Linq;
  29. using System.Text.Encodings.Web;
  30. using System.Text.Json;
  31. using System.Text.Unicode;
  32. using System.Threading.Tasks;
  33. #if NET10_0_OR_GREATER
  34. using Admin.NET.Core.Update;
  35. #endif
  36. namespace Admin.NET.Web.Core;
  37. [AppStartup(int.MaxValue)]
  38. public class Startup : AppStartup
  39. {
  40. public void ConfigureServices(IServiceCollection services)
  41. {
  42. // 配置选项
  43. services.AddProjectOptions();
  44. // 缓存注册
  45. services.AddCache();
  46. // SqlSugar
  47. services.AddSqlSugar();
  48. // JWT
  49. services.AddJwt<JwtHandler>(enableGlobalAuthorize: true, jwtBearerConfigure: options =>
  50. {
  51. // 实现 JWT 身份验证过程控制
  52. options.Events = new JwtBearerEvents
  53. {
  54. OnMessageReceived = context =>
  55. {
  56. var httpContext = context.HttpContext;
  57. // 若请求 Url 包含 token 参数,则设置 Token 值
  58. if (httpContext.Request.Query.ContainsKey("token"))
  59. context.Token = httpContext.Request.Query["token"];
  60. return Task.CompletedTask;
  61. }
  62. };
  63. }).AddSignatureAuthentication(options => // 添加 Signature 身份验证
  64. {
  65. options.Events = SysOpenAccessService.GetSignatureAuthenticationEventImpl();
  66. });
  67. // 允许跨域
  68. services.AddCorsAccessor();
  69. // 远程请求
  70. services.AddHttpRemote();
  71. // 任务队列
  72. services.AddTaskQueue();
  73. // 任务调度
  74. services.AddSchedule(options =>
  75. {
  76. options.AddPersistence<DbJobPersistence>(); // 添加作业持久化器
  77. options.AddMonitor<JobMonitor>(); // 添加作业执行监视器
  78. });
  79. // 脱敏检测
  80. services.AddSensitiveDetection();
  81. // Json序列化设置
  82. static void SetNewtonsoftJsonSetting(JsonSerializerSettings setting)
  83. {
  84. setting.DateFormatHandling = DateFormatHandling.IsoDateFormat;
  85. setting.DateTimeZoneHandling = DateTimeZoneHandling.Local;
  86. //setting.Converters.AddDateTimeTypeConverters(localized: false); // 时间本地化
  87. setting.DateFormatString = "yyyy-MM-dd HH:mm:ss"; // 时间格式化
  88. setting.ReferenceLoopHandling = ReferenceLoopHandling.Ignore; // 忽略循环引用
  89. // setting.ContractResolver = new CamelCasePropertyNamesContractResolver(); // 解决动态对象属性名大写
  90. // setting.NullValueHandling = NullValueHandling.Ignore; // 忽略空值
  91. setting.Converters.AddLongTypeConverters(); // long转string(防止js精度溢出) 超过17位开启
  92. // setting.MetadataPropertyHandling = MetadataPropertyHandling.Ignore; // 解决DateTimeOffset异常
  93. // setting.DateParseHandling = DateParseHandling.None; // 解决DateTimeOffset异常
  94. // setting.Converters.Add(new IsoDateTimeConverter { DateTimeStyles = DateTimeStyles.AssumeUniversal }); // 解决DateTimeOffset异常
  95. }
  96. ;
  97. services.AddControllersWithViews()
  98. .AddAppLocalization()
  99. .AddNewtonsoftJson(options => SetNewtonsoftJsonSetting(options.SerializerSettings))
  100. //.AddXmlSerializerFormatters()
  101. //.AddXmlDataContractSerializerFormatters()
  102. .AddInjectWithUnifyResult<AdminResultProvider>()
  103. .AddJsonOptions(options =>
  104. {
  105. options.JsonSerializerOptions.Encoder = JavaScriptEncoder.Create(UnicodeRanges.All); // 禁止Unicode转码
  106. options.JsonSerializerOptions.Converters.AddDateTimeTypeConverters("yyyy-MM-dd HH:mm:ss"); // 时间格式化
  107. })
  108. .AddApplicationPart(typeof(Admin.NET.Plugin.AiDOP.Startup).Assembly);
  109. // 三方授权登录OAuth
  110. services.AddOAuth();
  111. // ElasticSearch
  112. services.AddElasticSearchClients();
  113. // 配置Nginx转发获取客户端真实IP
  114. // 注1:如果负载均衡不是在本机通过 Loopback 地址转发请求的,一定要加上options.KnownNetworks.Clear()和options.KnownProxies.Clear()
  115. // 注2:如果设置环境变量 ASPNETCORE_FORWARDEDHEADERS_ENABLED 为 True,则不需要下面的配置代码
  116. services.Configure<ForwardedHeadersOptions>(options =>
  117. {
  118. options.ForwardedHeaders = ForwardedHeaders.All;
  119. options.KnownNetworks.Clear();
  120. options.KnownProxies.Clear();
  121. });
  122. // 限流服务
  123. services.AddInMemoryRateLimiting();
  124. services.AddSingleton<IRateLimitConfiguration, RateLimitConfiguration>();
  125. // 事件总线
  126. services.AddEventBus(options =>
  127. {
  128. options.UseUtcTimestamp = false;
  129. // 不启用事件日志
  130. options.LogEnabled = false;
  131. // 事件执行器(失败重试)
  132. options.AddExecutor<RetryEventHandlerExecutor>();
  133. // 事件执行器(重试后依然处理未处理异常的处理器)
  134. options.UnobservedTaskExceptionHandler = (obj, args) =>
  135. {
  136. if (args.Exception?.Message != null)
  137. Log.Error($"EeventBus 有未处理异常 :{args.Exception?.Message} ", args.Exception);
  138. };
  139. // 事件执行器-监视器(每一次处理都会进入)
  140. options.AddMonitor<EventHandlerMonitor>();
  141. #region Redis消息队列
  142. // 替换事件源存储器为Redis
  143. var cacheOptions = App.GetConfig<CacheOptions>("Cache", true);
  144. if (cacheOptions.CacheType == CacheTypeEnum.Redis.ToString())
  145. {
  146. options.ReplaceStorer(serviceProvider =>
  147. {
  148. var cacheProvider = serviceProvider.GetRequiredService<NewLife.Caching.ICacheProvider>();
  149. // 创建默认内存通道事件源对象,可自定义队列路由key,如:adminnet_eventsource_queue
  150. return new RedisEventSourceStorer(cacheProvider, "adminnet_eventsource_queue", 3000);
  151. });
  152. }
  153. #endregion Redis消息队列
  154. #region RabbitMQ消息队列
  155. //// 创建默认内存通道事件源对象,可自定义队列路由key,如:adminnet
  156. //var eventBusOpt = App.GetConfig<EventBusOptions>("EventBus", true);
  157. //var rbmqEventSourceStorer = new RabbitMQEventSourceStore(new ConnectionFactory
  158. //{
  159. // UserName = eventBusOpt.RabbitMQ.UserName,
  160. // Password = eventBusOpt.RabbitMQ.Password,
  161. // HostName = eventBusOpt.RabbitMQ.HostName,
  162. // Port = eventBusOpt.RabbitMQ.Port
  163. //}, "adminnet", 3000);
  164. //// 替换默认事件总线存储器
  165. //options.ReplaceStorer(serviceProvider =>
  166. //{
  167. // return rbmqEventSourceStorer;
  168. //});
  169. #endregion RabbitMQ消息队列
  170. });
  171. // 图像处理
  172. services.AddImageSharp();
  173. // OSS对象存储
  174. var ossOpt = App.GetConfig<OSSProviderOptions>("OSSProvider", true);
  175. services.AddOSSService(Enum.GetName(ossOpt.Provider), "OSSProvider");
  176. // 文件存储服务
  177. services.AddTransient<SysFileProviderService>();
  178. services.AddSingleton<IOSSServiceManager, OSSServiceManager>(); // 改为单例以保持缓存
  179. services.AddTransient<MultiOSSFileProvider>();
  180. // 模板引擎
  181. services.AddViewEngine();
  182. // 即时通讯
  183. services.AddSignalR(options =>
  184. {
  185. options.EnableDetailedErrors = true;
  186. options.KeepAliveInterval = TimeSpan.FromSeconds(15); // 服务器端向客户端ping的间隔
  187. options.ClientTimeoutInterval = TimeSpan.FromSeconds(30); // 客户端向服务器端ping的间隔
  188. options.MaximumReceiveMessageSize = 1024 * 1014 * 10; // 数据包大小10M,默认最大为32K
  189. }).AddNewtonsoftJsonProtocol(options => SetNewtonsoftJsonSetting(options.PayloadSerializerSettings));
  190. // 系统日志
  191. services.AddLoggingSetup();
  192. // 验证码
  193. services.AddCaptcha();
  194. // 控制台logo
  195. services.AddConsoleLogo();
  196. //// Swagger 时间格式化
  197. //services.AddSwaggerGen(c =>
  198. //{
  199. // c.MapType<DateTime>(() => new Microsoft.OpenApi.Models.OpenApiSchema
  200. // {
  201. // Type = "string",
  202. // Format = "date-time",
  203. // Example = new Microsoft.OpenApi.Any.OpenApiString(DateTime.Now.ToString("yyyy-MM-dd HH:mm:ss")) // 示例值
  204. // });
  205. // // 确保生成的文档包含 OpenAPI 版本字段
  206. // c.SwaggerDoc("v1", new Microsoft.OpenApi.Models.OpenApiInfo
  207. // {
  208. // Version = "v1",
  209. // Title = "Admin.NET API",
  210. // Description = "Admin.NET 通用权限开发平台"
  211. // });
  212. // c.OperationFilter<TenantHeaderOperationFilter>();
  213. //});
  214. // 将IP地址数据库文件完全加载到内存,提升查询速度(以空间换时间,内存将会增加60-70M)
  215. IpToolSettings.LoadInternationalDbToMemory = true;
  216. // 设置默认查询器China和International
  217. //IpToolSettings.DefalutSearcherType = IpSearcherType.China;
  218. IpToolSettings.DefalutSearcherType = IpSearcherType.International;
  219. // 配置gzip与br的压缩等级为最优
  220. //services.Configure<BrotliCompressionProviderOptions>(options =>
  221. //{
  222. // options.Level = CompressionLevel.Optimal;
  223. //});
  224. //services.Configure<GzipCompressionProviderOptions>(options =>
  225. //{
  226. // options.Level = CompressionLevel.Optimal;
  227. //});
  228. // 注册压缩响应
  229. services.AddResponseCompression((options) =>
  230. {
  231. options.EnableForHttps = true;
  232. options.Providers.Add<BrotliCompressionProvider>();
  233. options.Providers.Add<GzipCompressionProvider>();
  234. options.MimeTypes = ResponseCompressionDefaults.MimeTypes.Concat(
  235. [
  236. "text/html; charset=utf-8",
  237. "application/xhtml+xml",
  238. "application/atom+xml",
  239. "image/svg+xml"
  240. ]);
  241. });
  242. // 注册虚拟文件系统服务
  243. services.AddVirtualFileServer();
  244. }
  245. public void Configure(IApplicationBuilder app, IWebHostEnvironment env)
  246. {
  247. // 响应压缩
  248. app.UseResponseCompression();
  249. app.UseForwardedHeaders();
  250. if (env.IsDevelopment())
  251. {
  252. app.UseDeveloperExceptionPage();
  253. }
  254. else
  255. {
  256. app.UseExceptionHandler("/Home/Error");
  257. app.UseHsts();
  258. }
  259. app.Use(async (context, next) =>
  260. {
  261. context.Response.Headers.Append("Admin.NET", "Admin.NET");
  262. await next();
  263. });
  264. // 图像处理
  265. app.UseImageSharp();
  266. // 特定文件类型(文件后缀)处理
  267. var contentTypeProvider = FS.GetFileExtensionContentTypeProvider();
  268. // contentTypeProvider.Mappings[".文件后缀"] = "MIME 类型";
  269. app.UseStaticFiles(new StaticFileOptions
  270. {
  271. ContentTypeProvider = contentTypeProvider
  272. });
  273. // 二级目录文件路径解析
  274. if (!string.IsNullOrEmpty(App.Settings.VirtualPath))
  275. app.UseStaticFiles(new StaticFileOptions
  276. {
  277. RequestPath = App.Settings.VirtualPath,
  278. FileProvider = App.WebHostEnvironment.WebRootFileProvider
  279. });
  280. //// 启用HTTPS
  281. //app.UseHttpsRedirection();
  282. // 启用OAuth
  283. app.UseOAuth();
  284. // 添加状态码拦截中间件
  285. app.UseUnifyResultStatusCodes();
  286. // 启用多语言,必须在 UseRouting 之前
  287. app.UseAppLocalization();
  288. // 路由注册
  289. app.UseRouting();
  290. // 启用跨域,必须在 UseRouting 和 UseAuthentication 之间注册
  291. app.UseCorsAccessor();
  292. // 启用鉴权授权
  293. app.UseAuthentication();
  294. app.UseAuthorization();
  295. // 限流组件(在跨域之后)
  296. app.UseIpRateLimiting();
  297. app.UseClientRateLimiting();
  298. app.UsePolicyRateLimit();
  299. // 任务调度看板
  300. app.UseScheduleUI(options =>
  301. {
  302. options.RequestPath = "/schedule"; // 必须以 / 开头且不以 / 结尾
  303. options.DisableOnProduction = false; // 是否在生产环境中关闭
  304. options.DisplayEmptyTriggerJobs = true; // 是否显示空作业触发器的作业
  305. options.DisplayHead = false; // 是否显示页头
  306. options.DefaultExpandAllJobs = false; // 是否默认展开所有作业
  307. options.EnableDirectoryBrowsing = false; // 是否启用目录浏览
  308. options.Title = "定时任务看板"; // 自定义看板标题
  309. options.LoginConfig.OnLoging = async (username, password, httpContext) =>
  310. {
  311. var res = await httpContext.RequestServices.GetRequiredService<SysAuthService>().SwaggerSubmitUrl(new SpecificationAuth { UserName = username, Password = password });
  312. return res == 200;
  313. };
  314. options.LoginConfig.DefaultUsername = "";
  315. options.LoginConfig.DefaultPassword = "";
  316. options.LoginConfig.SessionKey = "schedule_session_key"; // 登录客户端存储的 Session 键
  317. });
  318. app.UseInject(string.Empty, options =>
  319. {
  320. foreach (var groupInfo in SpecificationDocumentBuilder.GetOpenApiGroups())
  321. {
  322. groupInfo.Description += "<br/><u><b><font color='FF0000'> 👮不得利用本项目从事危害国家安全、扰乱社会秩序、侵犯他人合法权益等法律法规禁止的活动!任何基于本项目二次开发而产生的一切法律纠纷和责任,我们不承担任何责任!</font></b></u>";
  323. }
  324. options.ConfigureSwagger(m =>
  325. {
  326. m.OpenApiVersion = Microsoft.OpenApi.OpenApiSpecVersion.OpenApi3_0;
  327. });
  328. });
  329. #if NET10_0_OR_GREATER
  330. app.UseAutoVersionUpdate();
  331. #endif
  332. app.UseEndpoints(endpoints =>
  333. {
  334. // 配置 Scalar 第三方 UI 集成(路由前缀一致代表独立,不同则代表共存)
  335. if (App.GetConfig<bool>("AppSettings:InjectSpecificationDocument", true))
  336. {
  337. endpoints.MapScalarApiReference("sapi", options =>
  338. {
  339. options.WithTitle("Admin.NET");
  340. // 配置 OpenAPI 文档
  341. foreach (var groupInfo in SpecificationDocumentBuilder.GetOpenApiGroups())
  342. {
  343. options.AddDocument(groupInfo.Group, groupInfo.Title, groupInfo.RouteTemplate);
  344. }
  345. });
  346. }
  347. // 注册集线器
  348. endpoints.MapHubs();
  349. endpoints.MapControllerRoute(
  350. name: "default",
  351. pattern: "{controller=Home}/{action=Index}/{id?}");
  352. });
  353. }
  354. }