Startup.cs 16 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406
  1. // Admin.NET 项目的版权、商标、专利和其他相关权利均受相应法律法规的保护。使用本项目应遵守相关法律法规和许可证的要求。
  2. //
  3. // 本项目主要遵循 MIT 许可证和 Apache 许可证(版本 2.0)进行分发和使用。许可证位于源代码树根目录中的 LICENSE-MIT 和 LICENSE-APACHE 文件。
  4. //
  5. // 不得利用本项目从事危害国家安全、扰乱社会秩序、侵犯他人合法权益等法律法规禁止的活动!任何基于本项目二次开发而产生的一切法律纠纷和责任,我们不承担任何责任!
  6. using Admin.NET.Core;
  7. using Admin.NET.Core.ElasticSearch;
  8. using Admin.NET.Core.Service;
  9. using AspNetCoreRateLimit;
  10. using Furion;
  11. using Furion.Logging;
  12. using Furion.SpecificationDocument;
  13. using Furion.VirtualFileServer;
  14. using IPTools.Core;
  15. using Microsoft.AspNetCore.Authentication.JwtBearer;
  16. using Microsoft.AspNetCore.Builder;
  17. using Microsoft.AspNetCore.Hosting;
  18. using Microsoft.AspNetCore.Http;
  19. using Microsoft.AspNetCore.HttpOverrides;
  20. using Microsoft.AspNetCore.ResponseCompression;
  21. using Microsoft.Extensions.DependencyInjection;
  22. using Microsoft.Extensions.Hosting;
  23. using Newtonsoft.Json;
  24. using OnceMi.AspNetCore.OSS;
  25. using Scalar.AspNetCore;
  26. using SixLabors.ImageSharp.Web.DependencyInjection;
  27. using System;
  28. using System.Linq;
  29. using System.Text.Encodings.Web;
  30. using System.Text.Json;
  31. using System.Text.Unicode;
  32. using System.Threading.Tasks;
  33. #if NET10_0_OR_GREATER
  34. using Admin.NET.Core.Update;
  35. #endif
  36. namespace Admin.NET.Web.Core;
  37. [AppStartup(int.MaxValue)]
  38. public class Startup : AppStartup
  39. {
  40. public void ConfigureServices(IServiceCollection services)
  41. {
  42. // 配置选项
  43. services.AddProjectOptions();
  44. // 缓存注册
  45. services.AddCache();
  46. // SqlSugar
  47. services.AddSqlSugar();
  48. // JWT
  49. services.AddJwt<JwtHandler>(enableGlobalAuthorize: true, jwtBearerConfigure: options =>
  50. {
  51. // 实现 JWT 身份验证过程控制
  52. options.Events = new JwtBearerEvents
  53. {
  54. OnMessageReceived = context =>
  55. {
  56. var httpContext = context.HttpContext;
  57. // 若请求 Url 包含 token 参数,则设置 Token 值
  58. if (httpContext.Request.Query.ContainsKey("token"))
  59. context.Token = httpContext.Request.Query["token"];
  60. return Task.CompletedTask;
  61. }
  62. };
  63. }).AddSignatureAuthentication(options => // 添加 Signature 身份验证
  64. {
  65. options.Events = SysOpenAccessService.GetSignatureAuthenticationEventImpl();
  66. });
  67. // 允许跨域
  68. services.AddCorsAccessor();
  69. // 远程请求
  70. services.AddHttpRemote();
  71. // 任务队列
  72. services.AddTaskQueue();
  73. // 任务调度
  74. services.AddSchedule(options =>
  75. {
  76. options.AddPersistence<DbJobPersistence>(); // 添加作业持久化器
  77. options.AddMonitor<JobMonitor>(); // 添加作业执行监视器
  78. });
  79. // 脱敏检测
  80. services.AddSensitiveDetection();
  81. // Json序列化设置
  82. static void SetNewtonsoftJsonSetting(JsonSerializerSettings setting)
  83. {
  84. setting.DateFormatHandling = DateFormatHandling.IsoDateFormat;
  85. setting.DateTimeZoneHandling = DateTimeZoneHandling.Local;
  86. //setting.Converters.AddDateTimeTypeConverters(localized: false); // 时间本地化
  87. setting.DateFormatString = "yyyy-MM-dd HH:mm:ss"; // 时间格式化
  88. setting.ReferenceLoopHandling = ReferenceLoopHandling.Ignore; // 忽略循环引用
  89. // setting.ContractResolver = new CamelCasePropertyNamesContractResolver(); // 解决动态对象属性名大写
  90. // setting.NullValueHandling = NullValueHandling.Ignore; // 忽略空值
  91. setting.Converters.AddLongTypeConverters(); // long转string(防止js精度溢出) 超过17位开启
  92. // setting.MetadataPropertyHandling = MetadataPropertyHandling.Ignore; // 解决DateTimeOffset异常
  93. // setting.DateParseHandling = DateParseHandling.None; // 解决DateTimeOffset异常
  94. // setting.Converters.Add(new IsoDateTimeConverter { DateTimeStyles = DateTimeStyles.AssumeUniversal }); // 解决DateTimeOffset异常
  95. }
  96. ;
  97. services.AddControllersWithViews()
  98. .AddAppLocalization()
  99. .AddNewtonsoftJson(options => SetNewtonsoftJsonSetting(options.SerializerSettings))
  100. //.AddXmlSerializerFormatters()
  101. //.AddXmlDataContractSerializerFormatters()
  102. .AddInjectWithUnifyResult<AdminResultProvider>()
  103. .AddJsonOptions(options =>
  104. {
  105. options.JsonSerializerOptions.Encoder = JavaScriptEncoder.Create(UnicodeRanges.All); // 禁止Unicode转码
  106. options.JsonSerializerOptions.Converters.AddDateTimeTypeConverters("yyyy-MM-dd HH:mm:ss"); // 时间格式化
  107. });
  108. // 三方授权登录OAuth
  109. services.AddOAuth();
  110. // ElasticSearch
  111. services.AddElasticSearchClients();
  112. // 配置Nginx转发获取客户端真实IP
  113. // 注1:如果负载均衡不是在本机通过 Loopback 地址转发请求的,一定要加上options.KnownNetworks.Clear()和options.KnownProxies.Clear()
  114. // 注2:如果设置环境变量 ASPNETCORE_FORWARDEDHEADERS_ENABLED 为 True,则不需要下面的配置代码
  115. services.Configure<ForwardedHeadersOptions>(options =>
  116. {
  117. options.ForwardedHeaders = ForwardedHeaders.All;
  118. options.KnownNetworks.Clear();
  119. options.KnownProxies.Clear();
  120. });
  121. // 限流服务
  122. services.AddInMemoryRateLimiting();
  123. services.AddSingleton<IRateLimitConfiguration, RateLimitConfiguration>();
  124. // 事件总线
  125. services.AddEventBus(options =>
  126. {
  127. options.UseUtcTimestamp = false;
  128. // 不启用事件日志
  129. options.LogEnabled = false;
  130. // 事件执行器(失败重试)
  131. options.AddExecutor<RetryEventHandlerExecutor>();
  132. // 事件执行器(重试后依然处理未处理异常的处理器)
  133. options.UnobservedTaskExceptionHandler = (obj, args) =>
  134. {
  135. if (args.Exception?.Message != null)
  136. Log.Error($"EeventBus 有未处理异常 :{args.Exception?.Message} ", args.Exception);
  137. };
  138. // 事件执行器-监视器(每一次处理都会进入)
  139. options.AddMonitor<EventHandlerMonitor>();
  140. #region Redis消息队列
  141. // 替换事件源存储器为Redis
  142. var cacheOptions = App.GetConfig<CacheOptions>("Cache", true);
  143. if (cacheOptions.CacheType == CacheTypeEnum.Redis.ToString())
  144. {
  145. options.ReplaceStorer(serviceProvider =>
  146. {
  147. var cacheProvider = serviceProvider.GetRequiredService<NewLife.Caching.ICacheProvider>();
  148. // 创建默认内存通道事件源对象,可自定义队列路由key,如:adminnet_eventsource_queue
  149. return new RedisEventSourceStorer(cacheProvider, "adminnet_eventsource_queue", 3000);
  150. });
  151. }
  152. #endregion Redis消息队列
  153. #region RabbitMQ消息队列
  154. //// 创建默认内存通道事件源对象,可自定义队列路由key,如:adminnet
  155. //var eventBusOpt = App.GetConfig<EventBusOptions>("EventBus", true);
  156. //var rbmqEventSourceStorer = new RabbitMQEventSourceStore(new ConnectionFactory
  157. //{
  158. // UserName = eventBusOpt.RabbitMQ.UserName,
  159. // Password = eventBusOpt.RabbitMQ.Password,
  160. // HostName = eventBusOpt.RabbitMQ.HostName,
  161. // Port = eventBusOpt.RabbitMQ.Port
  162. //}, "adminnet", 3000);
  163. //// 替换默认事件总线存储器
  164. //options.ReplaceStorer(serviceProvider =>
  165. //{
  166. // return rbmqEventSourceStorer;
  167. //});
  168. #endregion RabbitMQ消息队列
  169. });
  170. // 图像处理
  171. services.AddImageSharp();
  172. // OSS对象存储
  173. var ossOpt = App.GetConfig<OSSProviderOptions>("OSSProvider", true);
  174. services.AddOSSService(Enum.GetName(ossOpt.Provider), "OSSProvider");
  175. // 文件存储服务
  176. services.AddTransient<SysFileProviderService>();
  177. services.AddSingleton<IOSSServiceManager, OSSServiceManager>(); // 改为单例以保持缓存
  178. services.AddTransient<MultiOSSFileProvider>();
  179. // 模板引擎
  180. services.AddViewEngine();
  181. // 即时通讯
  182. services.AddSignalR(options =>
  183. {
  184. options.EnableDetailedErrors = true;
  185. options.KeepAliveInterval = TimeSpan.FromSeconds(15); // 服务器端向客户端ping的间隔
  186. options.ClientTimeoutInterval = TimeSpan.FromSeconds(30); // 客户端向服务器端ping的间隔
  187. options.MaximumReceiveMessageSize = 1024 * 1014 * 10; // 数据包大小10M,默认最大为32K
  188. }).AddNewtonsoftJsonProtocol(options => SetNewtonsoftJsonSetting(options.PayloadSerializerSettings));
  189. // 系统日志
  190. services.AddLoggingSetup();
  191. // 验证码
  192. services.AddCaptcha();
  193. // 控制台logo
  194. services.AddConsoleLogo();
  195. //// Swagger 时间格式化
  196. //services.AddSwaggerGen(c =>
  197. //{
  198. // c.MapType<DateTime>(() => new Microsoft.OpenApi.Models.OpenApiSchema
  199. // {
  200. // Type = "string",
  201. // Format = "date-time",
  202. // Example = new Microsoft.OpenApi.Any.OpenApiString(DateTime.Now.ToString("yyyy-MM-dd HH:mm:ss")) // 示例值
  203. // });
  204. // // 确保生成的文档包含 OpenAPI 版本字段
  205. // c.SwaggerDoc("v1", new Microsoft.OpenApi.Models.OpenApiInfo
  206. // {
  207. // Version = "v1",
  208. // Title = "Admin.NET API",
  209. // Description = "Admin.NET 通用权限开发平台"
  210. // });
  211. // c.OperationFilter<TenantHeaderOperationFilter>();
  212. //});
  213. // 将IP地址数据库文件完全加载到内存,提升查询速度(以空间换时间,内存将会增加60-70M)
  214. IpToolSettings.LoadInternationalDbToMemory = true;
  215. // 设置默认查询器China和International
  216. //IpToolSettings.DefalutSearcherType = IpSearcherType.China;
  217. IpToolSettings.DefalutSearcherType = IpSearcherType.International;
  218. // 配置gzip与br的压缩等级为最优
  219. //services.Configure<BrotliCompressionProviderOptions>(options =>
  220. //{
  221. // options.Level = CompressionLevel.Optimal;
  222. //});
  223. //services.Configure<GzipCompressionProviderOptions>(options =>
  224. //{
  225. // options.Level = CompressionLevel.Optimal;
  226. //});
  227. // 注册压缩响应
  228. services.AddResponseCompression((options) =>
  229. {
  230. options.EnableForHttps = true;
  231. options.Providers.Add<BrotliCompressionProvider>();
  232. options.Providers.Add<GzipCompressionProvider>();
  233. options.MimeTypes = ResponseCompressionDefaults.MimeTypes.Concat(
  234. [
  235. "text/html; charset=utf-8",
  236. "application/xhtml+xml",
  237. "application/atom+xml",
  238. "image/svg+xml"
  239. ]);
  240. });
  241. // 注册虚拟文件系统服务
  242. services.AddVirtualFileServer();
  243. }
  244. public void Configure(IApplicationBuilder app, IWebHostEnvironment env)
  245. {
  246. // 响应压缩
  247. app.UseResponseCompression();
  248. app.UseForwardedHeaders();
  249. if (env.IsDevelopment())
  250. {
  251. app.UseDeveloperExceptionPage();
  252. }
  253. else
  254. {
  255. app.UseExceptionHandler("/Home/Error");
  256. app.UseHsts();
  257. }
  258. app.Use(async (context, next) =>
  259. {
  260. context.Response.Headers.Append("Admin.NET", "Admin.NET");
  261. await next();
  262. });
  263. // 图像处理
  264. app.UseImageSharp();
  265. // 特定文件类型(文件后缀)处理
  266. var contentTypeProvider = FS.GetFileExtensionContentTypeProvider();
  267. // contentTypeProvider.Mappings[".文件后缀"] = "MIME 类型";
  268. app.UseStaticFiles(new StaticFileOptions
  269. {
  270. ContentTypeProvider = contentTypeProvider
  271. });
  272. // 二级目录文件路径解析
  273. if (!string.IsNullOrEmpty(App.Settings.VirtualPath))
  274. app.UseStaticFiles(new StaticFileOptions
  275. {
  276. RequestPath = App.Settings.VirtualPath,
  277. FileProvider = App.WebHostEnvironment.WebRootFileProvider
  278. });
  279. //// 启用HTTPS
  280. //app.UseHttpsRedirection();
  281. // 启用OAuth
  282. app.UseOAuth();
  283. // 添加状态码拦截中间件
  284. app.UseUnifyResultStatusCodes();
  285. // 启用多语言,必须在 UseRouting 之前
  286. app.UseAppLocalization();
  287. // 路由注册
  288. app.UseRouting();
  289. // 启用跨域,必须在 UseRouting 和 UseAuthentication 之间注册
  290. app.UseCorsAccessor();
  291. // 启用鉴权授权
  292. app.UseAuthentication();
  293. app.UseAuthorization();
  294. // 限流组件(在跨域之后)
  295. app.UseIpRateLimiting();
  296. app.UseClientRateLimiting();
  297. app.UsePolicyRateLimit();
  298. // 任务调度看板
  299. app.UseScheduleUI(options =>
  300. {
  301. options.RequestPath = "/schedule"; // 必须以 / 开头且不以 / 结尾
  302. options.DisableOnProduction = false; // 是否在生产环境中关闭
  303. options.DisplayEmptyTriggerJobs = true; // 是否显示空作业触发器的作业
  304. options.DisplayHead = false; // 是否显示页头
  305. options.DefaultExpandAllJobs = false; // 是否默认展开所有作业
  306. options.EnableDirectoryBrowsing = false; // 是否启用目录浏览
  307. options.Title = "定时任务看板"; // 自定义看板标题
  308. options.LoginConfig.OnLoging = async (username, password, httpContext) =>
  309. {
  310. var res = await httpContext.RequestServices.GetRequiredService<SysAuthService>().SwaggerSubmitUrl(new SpecificationAuth { UserName = username, Password = password });
  311. return res == 200;
  312. };
  313. options.LoginConfig.DefaultUsername = "";
  314. options.LoginConfig.DefaultPassword = "";
  315. options.LoginConfig.SessionKey = "schedule_session_key"; // 登录客户端存储的 Session 键
  316. });
  317. app.UseInject(string.Empty, options =>
  318. {
  319. foreach (var groupInfo in SpecificationDocumentBuilder.GetOpenApiGroups())
  320. {
  321. groupInfo.Description += "<br/><u><b><font color='FF0000'> 👮不得利用本项目从事危害国家安全、扰乱社会秩序、侵犯他人合法权益等法律法规禁止的活动!任何基于本项目二次开发而产生的一切法律纠纷和责任,我们不承担任何责任!</font></b></u>";
  322. }
  323. options.ConfigureSwagger(m =>
  324. {
  325. m.OpenApiVersion = Microsoft.OpenApi.OpenApiSpecVersion.OpenApi3_0;
  326. });
  327. });
  328. #if NET10_0_OR_GREATER
  329. app.UseAutoVersionUpdate();
  330. #endif
  331. app.UseEndpoints(endpoints =>
  332. {
  333. // 配置 Scalar 第三方 UI 集成(路由前缀一致代表独立,不同则代表共存)
  334. if (App.GetConfig<bool>("AppSettings:InjectSpecificationDocument", true))
  335. {
  336. endpoints.MapScalarApiReference("sapi", options =>
  337. {
  338. options.WithTitle("Admin.NET");
  339. // 配置 OpenAPI 文档
  340. foreach (var groupInfo in SpecificationDocumentBuilder.GetOpenApiGroups())
  341. {
  342. options.AddDocument(groupInfo.Group, groupInfo.Title, groupInfo.RouteTemplate);
  343. }
  344. });
  345. }
  346. // 注册集线器
  347. endpoints.MapHubs();
  348. endpoints.MapControllerRoute(
  349. name: "default",
  350. pattern: "{controller=Home}/{action=Index}/{id?}");
  351. });
  352. }
  353. }