Startup.cs 15 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384
  1. // Admin.NET 项目的版权、商标、专利和其他相关权利均受相应法律法规的保护。使用本项目应遵守相关法律法规和许可证的要求。
  2. //
  3. // 本项目主要遵循 MIT 许可证和 Apache 许可证(版本 2.0)进行分发和使用。许可证位于源代码树根目录中的 LICENSE-MIT 和 LICENSE-APACHE 文件。
  4. //
  5. // 不得利用本项目从事危害国家安全、扰乱社会秩序、侵犯他人合法权益等法律法规禁止的活动!任何基于本项目二次开发而产生的一切法律纠纷和责任,我们不承担任何责任!
  6. using Admin.NET.Core;
  7. using Admin.NET.Core.Service;
  8. using AspNetCoreRateLimit;
  9. using Furion;
  10. using Furion.Logging;
  11. using Furion.SpecificationDocument;
  12. using Furion.VirtualFileServer;
  13. using IGeekFan.AspNetCore.Knife4jUI;
  14. using IPTools.Core;
  15. using Microsoft.AspNetCore.Authentication.JwtBearer;
  16. using Microsoft.AspNetCore.Builder;
  17. using Microsoft.AspNetCore.Hosting;
  18. using Microsoft.AspNetCore.Http;
  19. using Microsoft.AspNetCore.HttpOverrides;
  20. using Microsoft.AspNetCore.ResponseCompression;
  21. using Microsoft.Extensions.DependencyInjection;
  22. using Microsoft.Extensions.Hosting;
  23. using Newtonsoft.Json;
  24. using OnceMi.AspNetCore.OSS;
  25. using SixLabors.ImageSharp.Web.DependencyInjection;
  26. using System;
  27. using System.Linq;
  28. using System.Text.Encodings.Web;
  29. using System.Text.Json;
  30. using System.Text.Unicode;
  31. using System.Threading.Tasks;
  32. #if NET9_0_OR_GREATER
  33. using Admin.NET.Core.Update;
  34. #endif
  35. namespace Admin.NET.Web.Core;
  36. [AppStartup(int.MaxValue)]
  37. public class Startup : AppStartup
  38. {
  39. public void ConfigureServices(IServiceCollection services)
  40. {
  41. // 配置选项
  42. services.AddProjectOptions();
  43. // 缓存注册
  44. services.AddCache();
  45. // SqlSugar
  46. services.AddSqlSugar();
  47. // JWT
  48. services.AddJwt<JwtHandler>(enableGlobalAuthorize: true, jwtBearerConfigure: options =>
  49. {
  50. // 实现 JWT 身份验证过程控制
  51. options.Events = new JwtBearerEvents
  52. {
  53. OnMessageReceived = context =>
  54. {
  55. var httpContext = context.HttpContext;
  56. // 若请求 Url 包含 token 参数,则设置 Token 值
  57. if (httpContext.Request.Query.ContainsKey("token"))
  58. context.Token = httpContext.Request.Query["token"];
  59. return Task.CompletedTask;
  60. }
  61. };
  62. }).AddSignatureAuthentication(options => // 添加 Signature 身份验证
  63. {
  64. options.Events = SysOpenAccessService.GetSignatureAuthenticationEventImpl();
  65. });
  66. // 允许跨域
  67. services.AddCorsAccessor();
  68. // 远程请求
  69. services.AddHttpRemote();
  70. // 任务队列
  71. services.AddTaskQueue();
  72. // 任务调度
  73. services.AddSchedule(options =>
  74. {
  75. options.AddPersistence<DbJobPersistence>(); // 添加作业持久化器
  76. options.AddMonitor<JobMonitor>(); // 添加作业执行监视器
  77. });
  78. // 脱敏检测
  79. services.AddSensitiveDetection();
  80. // Json序列化设置
  81. static void SetNewtonsoftJsonSetting(JsonSerializerSettings setting)
  82. {
  83. setting.DateFormatHandling = DateFormatHandling.IsoDateFormat;
  84. setting.DateTimeZoneHandling = DateTimeZoneHandling.Local;
  85. //setting.Converters.AddDateTimeTypeConverters(localized: false); // 时间本地化
  86. setting.DateFormatString = "yyyy-MM-dd HH:mm:ss"; // 时间格式化
  87. setting.ReferenceLoopHandling = ReferenceLoopHandling.Ignore; // 忽略循环引用
  88. // setting.ContractResolver = new CamelCasePropertyNamesContractResolver(); // 解决动态对象属性名大写
  89. // setting.NullValueHandling = NullValueHandling.Ignore; // 忽略空值
  90. setting.Converters.AddLongTypeConverters(); // long转string(防止js精度溢出) 超过17位开启
  91. // setting.MetadataPropertyHandling = MetadataPropertyHandling.Ignore; // 解决DateTimeOffset异常
  92. // setting.DateParseHandling = DateParseHandling.None; // 解决DateTimeOffset异常
  93. // setting.Converters.Add(new IsoDateTimeConverter { DateTimeStyles = DateTimeStyles.AssumeUniversal }); // 解决DateTimeOffset异常
  94. }
  95. ;
  96. services.AddControllersWithViews()
  97. .AddAppLocalization()
  98. .AddNewtonsoftJson(options => SetNewtonsoftJsonSetting(options.SerializerSettings))
  99. //.AddXmlSerializerFormatters()
  100. //.AddXmlDataContractSerializerFormatters()
  101. .AddInjectWithUnifyResult<AdminResultProvider>()
  102. .AddJsonOptions(options =>
  103. {
  104. options.JsonSerializerOptions.Encoder = JavaScriptEncoder.Create(UnicodeRanges.All); // 禁止Unicode转码
  105. options.JsonSerializerOptions.Converters.AddDateTimeTypeConverters("yyyy-MM-dd HH:mm:ss"); // 时间格式化
  106. });
  107. // 三方授权登录OAuth
  108. services.AddOAuth();
  109. // ElasticSearch
  110. services.AddElasticSearch();
  111. // 配置Nginx转发获取客户端真实IP
  112. // 注1:如果负载均衡不是在本机通过 Loopback 地址转发请求的,一定要加上options.KnownNetworks.Clear()和options.KnownProxies.Clear()
  113. // 注2:如果设置环境变量 ASPNETCORE_FORWARDEDHEADERS_ENABLED 为 True,则不需要下面的配置代码
  114. services.Configure<ForwardedHeadersOptions>(options =>
  115. {
  116. options.ForwardedHeaders = ForwardedHeaders.All;
  117. options.KnownNetworks.Clear();
  118. options.KnownProxies.Clear();
  119. });
  120. // 限流服务
  121. services.AddInMemoryRateLimiting();
  122. services.AddSingleton<IRateLimitConfiguration, RateLimitConfiguration>();
  123. // 事件总线
  124. services.AddEventBus(options =>
  125. {
  126. options.UseUtcTimestamp = false;
  127. // 不启用事件日志
  128. options.LogEnabled = false;
  129. // 事件执行器(失败重试)
  130. options.AddExecutor<RetryEventHandlerExecutor>();
  131. // 事件执行器(重试后依然处理未处理异常的处理器)
  132. options.UnobservedTaskExceptionHandler = (obj, args) =>
  133. {
  134. if (args.Exception?.Message != null)
  135. Log.Error($"EeventBus 有未处理异常 :{args.Exception?.Message} ", args.Exception);
  136. };
  137. // 事件执行器-监视器(每一次处理都会进入)
  138. options.AddMonitor<EventHandlerMonitor>();
  139. #region Redis消息队列
  140. // 替换事件源存储器为Redis
  141. var cacheOptions = App.GetConfig<CacheOptions>("Cache", true);
  142. if (cacheOptions.CacheType == CacheTypeEnum.Redis.ToString())
  143. {
  144. options.ReplaceStorer(serviceProvider =>
  145. {
  146. var cacheProvider = serviceProvider.GetRequiredService<NewLife.Caching.ICacheProvider>();
  147. // 创建默认内存通道事件源对象,可自定义队列路由key,如:adminnet_eventsource_queue
  148. return new RedisEventSourceStorer(cacheProvider, "adminnet_eventsource_queue", 3000);
  149. });
  150. }
  151. #endregion Redis消息队列
  152. #region RabbitMQ消息队列
  153. //// 创建默认内存通道事件源对象,可自定义队列路由key,如:adminnet
  154. //var eventBusOpt = App.GetConfig<EventBusOptions>("EventBus", true);
  155. //var rbmqEventSourceStorer = new RabbitMQEventSourceStore(new ConnectionFactory
  156. //{
  157. // UserName = eventBusOpt.RabbitMQ.UserName,
  158. // Password = eventBusOpt.RabbitMQ.Password,
  159. // HostName = eventBusOpt.RabbitMQ.HostName,
  160. // Port = eventBusOpt.RabbitMQ.Port
  161. //}, "adminnet", 3000);
  162. //// 替换默认事件总线存储器
  163. //options.ReplaceStorer(serviceProvider =>
  164. //{
  165. // return rbmqEventSourceStorer;
  166. //});
  167. #endregion RabbitMQ消息队列
  168. });
  169. // 图像处理
  170. services.AddImageSharp();
  171. // OSS对象存储
  172. var ossOpt = App.GetConfig<OSSProviderOptions>("OSSProvider", true);
  173. services.AddOSSService(Enum.GetName(ossOpt.Provider), "OSSProvider");
  174. // 模板引擎
  175. services.AddViewEngine();
  176. // 即时通讯
  177. services.AddSignalR(options =>
  178. {
  179. options.EnableDetailedErrors = true;
  180. options.KeepAliveInterval = TimeSpan.FromSeconds(15); // 服务器端向客户端ping的间隔
  181. options.ClientTimeoutInterval = TimeSpan.FromSeconds(30); // 客户端向服务器端ping的间隔
  182. options.MaximumReceiveMessageSize = 1024 * 1014 * 10; // 数据包大小10M,默认最大为32K
  183. }).AddNewtonsoftJsonProtocol(options => SetNewtonsoftJsonSetting(options.PayloadSerializerSettings));
  184. // 系统日志
  185. services.AddLoggingSetup();
  186. // 验证码
  187. services.AddCaptcha();
  188. // 控制台logo
  189. services.AddConsoleLogo();
  190. // Swagger 时间格式化
  191. services.AddSwaggerGen(c =>
  192. {
  193. c.MapType<DateTime>(() => new Microsoft.OpenApi.Models.OpenApiSchema
  194. {
  195. Type = "string",
  196. Format = "date-time",
  197. Example = new Microsoft.OpenApi.Any.OpenApiString(DateTime.Now.ToString("yyyy-MM-dd HH:mm:ss")) // 示例值
  198. });
  199. });
  200. // 将IP地址数据库文件完全加载到内存,提升查询速度(以空间换时间,内存将会增加60-70M)
  201. IpToolSettings.LoadInternationalDbToMemory = true;
  202. // 设置默认查询器China和International
  203. //IpToolSettings.DefalutSearcherType = IpSearcherType.China;
  204. IpToolSettings.DefalutSearcherType = IpSearcherType.International;
  205. // 配置gzip与br的压缩等级为最优
  206. //services.Configure<BrotliCompressionProviderOptions>(options =>
  207. //{
  208. // options.Level = CompressionLevel.Optimal;
  209. //});
  210. //services.Configure<GzipCompressionProviderOptions>(options =>
  211. //{
  212. // options.Level = CompressionLevel.Optimal;
  213. //});
  214. // 注册压缩响应
  215. services.AddResponseCompression((options) =>
  216. {
  217. options.EnableForHttps = true;
  218. options.Providers.Add<BrotliCompressionProvider>();
  219. options.Providers.Add<GzipCompressionProvider>();
  220. options.MimeTypes = ResponseCompressionDefaults.MimeTypes.Concat(
  221. [
  222. "text/html; charset=utf-8",
  223. "application/xhtml+xml",
  224. "application/atom+xml",
  225. "image/svg+xml"
  226. ]);
  227. });
  228. // 注册虚拟文件系统服务
  229. services.AddVirtualFileServer();
  230. }
  231. public void Configure(IApplicationBuilder app, IWebHostEnvironment env)
  232. {
  233. // 响应压缩
  234. app.UseResponseCompression();
  235. app.UseForwardedHeaders();
  236. if (env.IsDevelopment())
  237. {
  238. app.UseDeveloperExceptionPage();
  239. }
  240. else
  241. {
  242. app.UseExceptionHandler("/Home/Error");
  243. app.UseHsts();
  244. }
  245. app.Use(async (context, next) =>
  246. {
  247. context.Response.Headers.Append("Admin.NET", "Admin.NET");
  248. await next();
  249. });
  250. // 图像处理
  251. app.UseImageSharp();
  252. // 特定文件类型(文件后缀)处理
  253. var contentTypeProvider = FS.GetFileExtensionContentTypeProvider();
  254. // contentTypeProvider.Mappings[".文件后缀"] = "MIME 类型";
  255. app.UseStaticFiles(new StaticFileOptions
  256. {
  257. ContentTypeProvider = contentTypeProvider
  258. });
  259. // 二级目录文件路径解析
  260. if (!string.IsNullOrEmpty(App.Settings.VirtualPath))
  261. app.UseStaticFiles(new StaticFileOptions
  262. {
  263. RequestPath = App.Settings.VirtualPath,
  264. FileProvider = App.WebHostEnvironment.WebRootFileProvider
  265. });
  266. //// 启用HTTPS
  267. //app.UseHttpsRedirection();
  268. // 启用OAuth
  269. app.UseOAuth();
  270. // 添加状态码拦截中间件
  271. app.UseUnifyResultStatusCodes();
  272. // 启用多语言,必须在 UseRouting 之前
  273. app.UseAppLocalization();
  274. // 路由注册
  275. app.UseRouting();
  276. // 启用跨域,必须在 UseRouting 和 UseAuthentication 之间注册
  277. app.UseCorsAccessor();
  278. // 启用鉴权授权
  279. app.UseAuthentication();
  280. app.UseAuthorization();
  281. // 限流组件(在跨域之后)
  282. app.UseIpRateLimiting();
  283. app.UseClientRateLimiting();
  284. app.UsePolicyRateLimit();
  285. // 任务调度看板
  286. app.UseScheduleUI(options =>
  287. {
  288. options.RequestPath = "/schedule"; // 必须以 / 开头且不以 / 结尾
  289. options.DisableOnProduction = false; // 是否在生产环境中关闭
  290. options.DisplayEmptyTriggerJobs = true; // 是否显示空作业触发器的作业
  291. options.DisplayHead = false; // 是否显示页头
  292. options.DefaultExpandAllJobs = false; // 是否默认展开所有作业
  293. options.EnableDirectoryBrowsing = false; // 是否启用目录浏览
  294. options.Title = "定时任务看板"; // 自定义看板标题
  295. options.LoginConfig.OnLoging = async (username, password, httpContext) =>
  296. {
  297. var res = await httpContext.RequestServices.GetRequiredService<SysAuthService>().SwaggerSubmitUrl(new SpecificationAuth { UserName = username, Password = password });
  298. return res == 200;
  299. };
  300. options.LoginConfig.DefaultUsername = "";
  301. options.LoginConfig.DefaultPassword = "";
  302. options.LoginConfig.SessionKey = "schedule_session_key"; // 登录客户端存储的 Session 键
  303. });
  304. // 配置Swagger-Knife4UI(路由前缀一致代表独立,不同则代表共存)
  305. app.UseKnife4UI(options =>
  306. {
  307. options.RoutePrefix = "kapi";
  308. foreach (var groupInfo in SpecificationDocumentBuilder.GetOpenApiGroups())
  309. {
  310. options.SwaggerEndpoint("/" + groupInfo.RouteTemplate, groupInfo.Title);
  311. }
  312. });
  313. app.UseInject(string.Empty, options =>
  314. {
  315. foreach (var groupInfo in SpecificationDocumentBuilder.GetOpenApiGroups())
  316. {
  317. groupInfo.Description += "<br/><u><b><font color='FF0000'> 👮不得利用本项目从事危害国家安全、扰乱社会秩序、侵犯他人合法权益等法律法规禁止的活动!任何基于本项目二次开发而产生的一切法律纠纷和责任,我们不承担任何责任!</font></b></u>";
  318. }
  319. options.ConfigureSwagger(m => { m.OpenApiVersion = Microsoft.OpenApi.OpenApiSpecVersion.OpenApi3_0; });
  320. });
  321. #if NET9_0_OR_GREATER
  322. app.UseAutoVersionUpdate();
  323. #endif
  324. app.UseEndpoints(endpoints =>
  325. {
  326. // 注册集线器
  327. endpoints.MapHubs();
  328. endpoints.MapControllerRoute(
  329. name: "default",
  330. pattern: "{controller=Home}/{action=Index}/{id?}");
  331. });
  332. }
  333. }