diff --git a/LaaProductionWeb/LaaProductionWeb.Services/AccountService.cs b/LaaProductionWeb/LaaProductionWeb.Services/AccountService.cs index 75f8f836..ca28f65b 100644 --- a/LaaProductionWeb/LaaProductionWeb.Services/AccountService.cs +++ b/LaaProductionWeb/LaaProductionWeb.Services/AccountService.cs @@ -4,187 +4,29 @@ using LaaProductionWeb.Services.Interfaces; using LaaProductionWeb.Services.Models; - using System.Collections.Generic; - using System.Linq; - public class AccountService : IAccountService { - private readonly ISqlClient dbContext; + private readonly ISqlClient sqlClient; - public AccountService(ISqlClient dbContext) - => this.dbContext = dbContext; + public AccountService(ISqlClient sqlClient) + => this.sqlClient = sqlClient; - public WindowsUser GetOrCreateWindowsUser(string primarySID, string domainName, string userName) + public Employee FindEmployee(string firstName, string lastName) { - var user = this.dbContext.FirstOrDefault($@" - DECLARE @userId INT; - - SELECT @userId = [Account].[WindowsUsers].[UserId] - FROM [Account].[WindowsUsers] - WHERE [Account].[WindowsUsers].[PrimarySID] = @{nameof(primarySID)} - - IF @userId IS NULL - INSERT INTO [Account].[WindowsUsers] ( - [PrimarySID] - , [DomainName] - , [UserName]) - OUTPUT [Inserted].[UserId] - VALUES (@{nameof(primarySID)} - , @{nameof(domainName)} - , @{nameof(userName)}) - ELSE SELECT @userId", + var permissions = this.sqlClient.ExecuteReader($@" + SELECT [MitarbeiterRechte].[Recht] + FROM [Mitarbeiter] + JOIN [MitarbeiterRechte] + ON [MitarbeiterRechte].[MitarbeiterNr] = [Mitarbeiter].[MitarbeiterNr] + WHERE [Vorname] LIKE @{nameof(firstName)} + AND [Name] LIKE @{nameof(lastName)} + AND [MitarbeiterRechte].[Recht] LIKE 'WEB_%'", parameters => parameters - .Add(nameof(primarySID), primarySID) - .Add(nameof(domainName), domainName) - .Add(nameof(userName), userName), - reader => new WindowsUser - { - UserId = reader.GetValue(0) - }) - ?? new WindowsUser(); - - user.Roles = this - .GetUserRoles(user.UserId) - .Select(x => x.RoleName); + .Add(nameof(firstName), firstName) + .Add(nameof(lastName), lastName), + reader => reader.GetString()); - return user; - } - - public PermissionsModel GetPermissionModelForUser(int userId, string role) - { - var roleModel = this.GetRoleForUser(role); - - return new PermissionsModel - { - UserId = userId, - Role = roleModel - }; - } - - public UserRole GetRoleForUser(string role) - => this.dbContext.FirstOrDefault($@" - SELECT [Account].[Roles].[RoleId] - , [Account].[Roles].[RoleName] - , [Account].[Roles].[DisplayName] - , [Account].[UsersRoles].[Approved] - FROM [Account].[Roles] - LEFT JOIN [Account].[UsersRoles] - ON [Account].[UsersRoles].[RoleId] = [Account].[Roles].[RoleId] - WHERE [Account].[Roles].[RoleName] = @{nameof(role)}", - parameters => parameters.Add(nameof(role), role), - reader => new UserRole - { - RoleId = reader.GetValue(0), - RoleName = reader.GetString(1), - DisplayName = reader.GetString(2), - Pending = reader.GetValue(3), - }) ?? new UserRole(); - - public IEnumerable GetUserRoles(int userId) - => this.dbContext.ExecuteReader($@" - SELECT [Account].[Roles].[RoleId] - , [Account].[Roles].[RoleName] - , [Account].[Roles].[DisplayName] - FROM [Account].[Roles] - JOIN [Account].[UsersRoles] - ON [Account].[UsersRoles].[RoleId] = [Account].[Roles].[RoleId] - AND [Account].[UsersRoles].[UserId] = @{nameof(userId)} - AND [Account].[UsersRoles].[Approved] = 1", - parameters => parameters.Add(nameof(userId), userId), - reader => new UserRole - { - RoleId = reader.GetValue(0), - RoleName = reader.GetString(1), - DisplayName = reader.GetString(2), - }); - - public List GetUsersWithPendingRoles() - => this.dbContext.ExecuteReader($@" - SELECT [Account].[Users].[UserId] - , [Account].[Users].[FirstName] + ' ' + [Account].[Users].[LastName] - , [Account].[Roles].[RoleId] - , [Account].[Roles].[RoleName] - , [Account].[UsersRoles].[Approved] - FROM [Account].[UsersRoles] - JOIN [Account].[Roles] ON [Account].[Roles].[RoleId] = [Account].[UsersRoles].[RoleId] - JOIN [Account].[Users] ON [Account].[Users].[UserId] = [Account].[UsersRoles].[UserId] - WHERE [Account].[UsersRoles].[Approved] = 0", - reader => new - { - UserId = reader.GetValue(0), - DisplayName = reader.GetString(1), - RoleId = reader.GetValue(2), - RoleName = reader.GetString(3), - Approved = reader.GetValue(4) - }) - .GroupBy(x => new UserPermissions - { - UserId = x.UserId, - DisplayName = x.DisplayName - }, UserPermissionsComparer.Current) - .Select(x => new UserPermissions - { - UserId = x.Key.UserId, - DisplayName = x.Key.DisplayName, - Roles = x - .AsEnumerable() - .Select(r => new RoleModel - { - RoleId = r.RoleId, - RoleName = r.RoleName, - Approved = r.Approved - }) - .ToList() - }) - .ToList(); - - public void RequestPermissions(PermissionsModel model) - { - this.dbContext.ExecuteNonQuery($@" - INSERT INTO [Auftrag].[Account].[Users] ( - [UserId] - , [FirstName] - , [LastName]) - VALUES (@{nameof(model.UserId)} - , @{nameof(model.FirstName)} - , @{nameof(model.LastName)})", - parameters => parameters - .Add(nameof(model.UserId), model.UserId) - .Add(nameof(model.FirstName), model.FirstName) - .Add(nameof(model.LastName), model.LastName)); - - model.Role.Pending = this.dbContext.ExecuteNonQuery($@" - INSERT INTO [Auftrag].[Account].[UsersRoles] ( - [UserId] - , [RoleId]) - VALUES (@{nameof(model.UserId)} - , @{nameof(model.Role.RoleId)})", - parameters => parameters - .Add(nameof(model.UserId), model.UserId) - .Add(nameof(model.Role.RoleId), model.Role.RoleId)) == 1; - } - - public void SaveUserPermissions(IEnumerable usersPermissions) - { - foreach (var user in usersPermissions) - { - foreach (var role in user.Roles) - { - this.dbContext.ExecuteNonQuery( - role.Deleted - ? $@"DELETE FROM [Account].[UsersRoles] - WHERE [Account].[UsersRoles].[UserId] = @{nameof(user.UserId)} - AND [Account].[UsersRoles].[RoleId] = @{nameof(role.RoleId)}" - : $@"UPDATE [Account].[UsersRoles] - SET [Approved] = @{nameof(role.Approved)} - WHERE [Account].[UsersRoles].[UserId] = @{nameof(user.UserId)} - AND [Account].[UsersRoles].[RoleId] = @{nameof(role.RoleId)}", - parameters => parameters - .Add(nameof(user.UserId), user.UserId) - .Add(nameof(role.RoleId), role.RoleId) - .Add(nameof(role.Approved), role.Approved)); - } - } + return new Employee(permissions); } } } diff --git a/LaaProductionWeb/LaaProductionWeb.Services/Interfaces/IAccountService.cs b/LaaProductionWeb/LaaProductionWeb.Services/Interfaces/IAccountService.cs index 81293be3..5fc0ee02 100644 --- a/LaaProductionWeb/LaaProductionWeb.Services/Interfaces/IAccountService.cs +++ b/LaaProductionWeb/LaaProductionWeb.Services/Interfaces/IAccountService.cs @@ -2,22 +2,8 @@ { using LaaProductionWeb.Services.Models; - using System.Collections.Generic; - public interface IAccountService : ITransient { - WindowsUser GetOrCreateWindowsUser(string primarySID, string domainName, string userName); - - PermissionsModel GetPermissionModelForUser(int userId, string role); - - IEnumerable GetUserRoles(int userId); - - List GetUsersWithPendingRoles(); - - UserRole GetRoleForUser(string role); - - void RequestPermissions(PermissionsModel model); - - void SaveUserPermissions(IEnumerable usersPermissions); + Employee FindEmployee(string firstName, string lastName); } } diff --git a/LaaProductionWeb/LaaProductionWeb.Services/LaaProductionWeb.Services.csproj b/LaaProductionWeb/LaaProductionWeb.Services/LaaProductionWeb.Services.csproj index 662a1149..e9b45418 100644 --- a/LaaProductionWeb/LaaProductionWeb.Services/LaaProductionWeb.Services.csproj +++ b/LaaProductionWeb/LaaProductionWeb.Services/LaaProductionWeb.Services.csproj @@ -66,6 +66,7 @@ + @@ -76,10 +77,6 @@ - - - - @@ -88,7 +85,6 @@ - diff --git a/LaaProductionWeb/LaaProductionWeb.Services/Models/Employee.cs b/LaaProductionWeb/LaaProductionWeb.Services/Models/Employee.cs new file mode 100644 index 00000000..1fa70c8d --- /dev/null +++ b/LaaProductionWeb/LaaProductionWeb.Services/Models/Employee.cs @@ -0,0 +1,14 @@ +namespace LaaProductionWeb.Services.Models +{ + using System; + using System.Collections.Generic; + + public class Employee + { + public Employee(IEnumerable permissions) + => this.Permissions = permissions; + + public IEnumerable Permissions { get; } + = Array.Empty(); + } +} diff --git a/LaaProductionWeb/LaaProductionWeb.Services/Models/PermissionsModel.cs b/LaaProductionWeb/LaaProductionWeb.Services/Models/PermissionsModel.cs deleted file mode 100644 index b6d4c08b..00000000 --- a/LaaProductionWeb/LaaProductionWeb.Services/Models/PermissionsModel.cs +++ /dev/null @@ -1,19 +0,0 @@ -namespace LaaProductionWeb.Services.Models -{ - using System.ComponentModel.DataAnnotations; - - public class PermissionsModel - { - public int UserId { get; set; } - - [Display(Name = "Vorname")] - [Required(ErrorMessage = "Die Vorname ist erforderlich.")] - public string FirstName { get; set; } - - [Display(Name = "Name")] - [Required(ErrorMessage = "Die Name ist erforderlich.")] - public string LastName { get; set; } - - public UserRole Role { get; set; } - } -} diff --git a/LaaProductionWeb/LaaProductionWeb.Services/Models/RoleModel.cs b/LaaProductionWeb/LaaProductionWeb.Services/Models/RoleModel.cs deleted file mode 100644 index 798cc9a3..00000000 --- a/LaaProductionWeb/LaaProductionWeb.Services/Models/RoleModel.cs +++ /dev/null @@ -1,13 +0,0 @@ -namespace LaaProductionWeb.Services.Models -{ - public class RoleModel - { - public int RoleId { get; set; } - - public string RoleName { get; set; } - - public bool Approved { get; set; } - - public bool Deleted { get; set; } - } -} diff --git a/LaaProductionWeb/LaaProductionWeb.Services/Models/UserPermissions.cs b/LaaProductionWeb/LaaProductionWeb.Services/Models/UserPermissions.cs deleted file mode 100644 index 21530007..00000000 --- a/LaaProductionWeb/LaaProductionWeb.Services/Models/UserPermissions.cs +++ /dev/null @@ -1,25 +0,0 @@ -namespace LaaProductionWeb.Services.Models -{ - using System.Collections.Generic; - - public class UserPermissions - { - public int UserId { get; set; } - - public string DisplayName { get; set; } - - public List Roles { get; set; } - } - - public class UserPermissionsComparer : IEqualityComparer - { - public bool Equals(UserPermissions x, UserPermissions y) - => x?.UserId == y?.UserId; - - public int GetHashCode(UserPermissions obj) - => obj?.UserId ?? default(int); - - public static UserPermissionsComparer Current - = new UserPermissionsComparer(); - } -} diff --git a/LaaProductionWeb/LaaProductionWeb.Services/Models/UserRole.cs b/LaaProductionWeb/LaaProductionWeb.Services/Models/UserRole.cs deleted file mode 100644 index 73b74ec2..00000000 --- a/LaaProductionWeb/LaaProductionWeb.Services/Models/UserRole.cs +++ /dev/null @@ -1,13 +0,0 @@ -namespace LaaProductionWeb.Services.Models -{ - public class UserRole - { - public int RoleId { get; set; } - - public string RoleName { get; set; } - - public string DisplayName { get; set; } - - public bool? Pending { get; set; } - } -} diff --git a/LaaProductionWeb/LaaProductionWeb.Services/Models/WindowsUser.cs b/LaaProductionWeb/LaaProductionWeb.Services/Models/WindowsUser.cs deleted file mode 100644 index e7d50ade..00000000 --- a/LaaProductionWeb/LaaProductionWeb.Services/Models/WindowsUser.cs +++ /dev/null @@ -1,12 +0,0 @@ -namespace LaaProductionWeb.Services.Models -{ - using System; - using System.Collections.Generic; - - public class WindowsUser - { - public int UserId { get; set; } = -1; - - public IEnumerable Roles { get; set; } = Array.Empty(); - } -} diff --git a/LaaProductionWeb/LaaProductionWeb.Services/OrdersService.cs b/LaaProductionWeb/LaaProductionWeb.Services/OrdersService.cs index 5be6b420..5df21ba3 100644 --- a/LaaProductionWeb/LaaProductionWeb.Services/OrdersService.cs +++ b/LaaProductionWeb/LaaProductionWeb.Services/OrdersService.cs @@ -6,14 +6,14 @@ public class OrdersService : IOrdersService { - private readonly ISqlClient dbContext; + private readonly ISqlClient sqlClient; - public OrdersService(ISqlClient dbContext) - => this.dbContext = dbContext; + public OrdersService(ISqlClient sqlClient) + => this.sqlClient = sqlClient; public OrdersFoundModel FindOrders(string search) { - var ordersFound = this.dbContext.ExecuteReader( + var ordersFound = this.sqlClient.ExecuteReader( query: $@" SELECT DISTINCT [AlleAuftragPositionen].[AuftragNr] -- 0 @@ -39,7 +39,7 @@ public OrderPositions FindPositions(string orderNr) { - var positionsFound = this.dbContext.ExecuteReader( + var positionsFound = this.sqlClient.ExecuteReader( query: $@" SELECT DISTINCT [AlleAuftragPositionen].[PositionNr] -- 0 @@ -55,7 +55,7 @@ public ProductionOrders FindProductionOrders(string productionNr) { - var ordersFound = this.dbContext.ExecuteReader($@" + var ordersFound = this.sqlClient.ExecuteReader($@" SELECT DISTINCT [AlleAuftragPositionen].[FertigungsauftragNr] -- 1 FROM [AlleAuftragPositionen] diff --git a/LaaProductionWeb/LaaProductionWeb.Services/ProtocolService.cs b/LaaProductionWeb/LaaProductionWeb.Services/ProtocolService.cs index 2c0ed159..dfdafccb 100644 --- a/LaaProductionWeb/LaaProductionWeb.Services/ProtocolService.cs +++ b/LaaProductionWeb/LaaProductionWeb.Services/ProtocolService.cs @@ -11,13 +11,13 @@ public class ProtocolService : IProtocolService { - private readonly ISqlClient dbContext; + private readonly ISqlClient sqlClient; - public ProtocolService(ISqlClient dbContext) - => this.dbContext = dbContext; + public ProtocolService(ISqlClient sqlClient) + => this.sqlClient = sqlClient; public bool DeleteFile(int fileId) - => this.dbContext.ExecuteScalar($@" + => this.sqlClient.ExecuteScalar($@" DELETE FROM [File] WHERE [FileId] = @{nameof(fileId)}; DELETE FROM [FilesOrders] @@ -27,7 +27,7 @@ public string FileContent(int? fileId) { - var fileContent = this.dbContext.FirstOrDefault( + var fileContent = this.sqlClient.FirstOrDefault( query: $@" SELECT [dbo].[File].[FileContent] FROM [dbo].[File] @@ -40,7 +40,7 @@ public OrderClientModel FindOrder(int orderId) { - var orderClientModel = this.dbContext.FirstOrDefault( + var orderClientModel = this.sqlClient.FirstOrDefault( query: $@" SELECT DISTINCT [APG].[AuftragNr] @@ -72,7 +72,7 @@ if (orderClientModel != null && orderId > 0) { - orderClientModel.FileId = this.dbContext.FirstOrDefault($@" + orderClientModel.FileId = this.sqlClient.FirstOrDefault($@" SELECT [FileId] FROM [FilesOrders] WHERE [OrderId] = @{nameof(orderId)} @@ -85,7 +85,7 @@ } public IEnumerable> FindOrdersById(int orderno) - => this.dbContext.ExecuteReader($@" + => this.sqlClient.ExecuteReader($@" SELECT DISTINCT [APG].[AuftragNr] , [K].[Name] @@ -104,7 +104,7 @@ value: reader.GetString(1))); public IEnumerable> FindOrdersByClient(string clientName) - => this.dbContext.ExecuteReader( + => this.sqlClient.ExecuteReader( query: $@" SELECT DISTINCT [APG].[AuftragNr] @@ -124,7 +124,7 @@ value: reader.GetString(1))); public IEnumerable LoadTestStatus(int orderId) - => this.dbContext.ExecuteReader( + => this.sqlClient.ExecuteReader( query: $@" SELECT DISTINCT [APS].[PositionNr] AS [PosNr] -- 0 @@ -165,7 +165,7 @@ public bool OrderCompleted(int orderId) { - var sumResults = this.dbContext.ExecuteReader($@" + var sumResults = this.sqlClient.ExecuteReader($@" SELECT CAST(CASE WHEN ISNULL([CPT].[CordonelPressureTest_Valid], 1) = 1 THEN 0 ELSE 1 END AS INT) + CAST(CASE WHEN ISNULL([DP].[Dicht], 1) = 1 THEN 0 ELSE 1 END AS INT) + ISNULL(MAX([APS].[StatusFertigung]) - 30, 0) @@ -199,7 +199,7 @@ var fileName = $"{clientId}_{orderId}.pdf"; var fileContent = this.GetBuffer(fileStream); - return this.dbContext.ExecuteScalar( + return this.sqlClient.ExecuteScalar( query: $@" INSERT INTO [dbo].[File] ( [FileName] diff --git a/LaaProductionWeb/LaaProductionWeb.Services/ReportService.cs b/LaaProductionWeb/LaaProductionWeb.Services/ReportService.cs index dfc00e23..d071c2ae 100644 --- a/LaaProductionWeb/LaaProductionWeb.Services/ReportService.cs +++ b/LaaProductionWeb/LaaProductionWeb.Services/ReportService.cs @@ -10,10 +10,10 @@ public class ReportService : IReportService { - private readonly ISqlClient dbContext; + private readonly ISqlClient sqlClient; - public ReportService(ISqlClient dbContext) - => this.dbContext = dbContext; + public ReportService(ISqlClient sqlClient) + => this.sqlClient = sqlClient; public HeliumReportModel LoadHeliumPressureReport(HeliumReportModel model = null) { @@ -25,7 +25,7 @@ var where = model.Filter.Where(); var orderBy = model.Filter.OrderBy(); - model.Items = this.dbContext.ExecuteReader($@" + model.Items = this.sqlClient.ExecuteReader($@" SELECT [PT].[CordonelPressureTest_FertigungsAuftragsNr] AS [FertigungNr] -- 0 Filter , [POS].[AuftragNr] AS [AuftragNr] -- 1 Filter , [POS].[PositionNr] AS [PositionNr] -- 2 Filter @@ -94,7 +94,7 @@ } public IEnumerable LoadHeliumPressureResults(int testId) - => this.dbContext.ExecuteReader($@" + => this.sqlClient.ExecuteReader($@" SELECT [CordonelPressureTestTestPoints_Id] , [CordonelPressureTest_TestPointNr] , CAST([CordonelPressureTest_TestPointResult] AS NUMERIC(9, 8)) diff --git a/LaaProductionWeb/LaaProductionWeb.Services/ShipmentsService.cs b/LaaProductionWeb/LaaProductionWeb.Services/ShipmentsService.cs index 4827f620..97ece1d5 100644 --- a/LaaProductionWeb/LaaProductionWeb.Services/ShipmentsService.cs +++ b/LaaProductionWeb/LaaProductionWeb.Services/ShipmentsService.cs @@ -11,10 +11,10 @@ public class ShipmentsService : IShipmentsService { - private readonly ISqlClient dbContext; + private readonly ISqlClient sqlClient; - public ShipmentsService(ISqlClient dbContext) - => this.dbContext = dbContext; + public ShipmentsService(ISqlClient sqlClient) + => this.sqlClient = sqlClient; public OrderScanModel DeletePalletEntry(int id) { @@ -30,7 +30,7 @@ public int GetPalletsCount(OrderScanModel model) { - var palletsCount = this.dbContext.FirstOrDefault( + var palletsCount = this.sqlClient.FirstOrDefault( query: $@" SELECT COUNT(1) FROM (SELECT [PalettenNr] AS [PalletNr] @@ -52,7 +52,7 @@ public byte[] LoadBatchBuffer(OrderScanModel model) { - var palletLoad = this.dbContext.ExecuteReader( + var palletLoad = this.sqlClient.ExecuteReader( query: $@" SELECT [PalettenNr] , [SerienNr] @@ -76,7 +76,7 @@ } public IEnumerable LoadBatchItems(OrderScanModel model) - => this.dbContext.ExecuteReader( + => this.sqlClient.ExecuteReader( query: $@" SELECT DISTINCT [PalettenScan].[ID] -- 0 @@ -117,7 +117,7 @@ const string orderNr = nameof(model.OrderNr); const string palNr = nameof(model.PalletNr); - var batchModel = this.dbContext.FirstOrDefault( + var batchModel = this.sqlClient.FirstOrDefault( query: $@" SELECT TOP 1 [Auftrag].[AuftragNr] -- 0 @@ -156,7 +156,7 @@ } private IEnumerable LoadBatchPositions(OrderScanModel model, string orderNr, string palNr) - => this.dbContext.ExecuteReader($@" + => this.sqlClient.ExecuteReader($@" SELECT DISTINCT [Auftrag].[PositionNr] , COUNT(1) @@ -223,7 +223,7 @@ } private OrderScanModel DeletePalletEntryById(int id) - => this.dbContext.FirstOrDefault( + => this.sqlClient.FirstOrDefault( query: $@" DELETE FROM [PalettenScan] @@ -240,7 +240,7 @@ }); private OrderIdentity UpdateOrderIdentifiers(int? orderNr, int? positionNr, string serialNr) - => this.dbContext.FirstOrDefault( + => this.sqlClient.FirstOrDefault( query: $@" SELECT DISTINCT TOP 1 [AuftragPositionSerienNr].[PositionNr] -- 0 @@ -263,7 +263,7 @@ }); private int InsertPalletEntry(OrderScanModel model) - => this.dbContext.ExecuteNonQuery($@" + => this.sqlClient.ExecuteNonQuery($@" INSERT INTO [PalettenScan] ( [PalettenNr] @@ -289,7 +289,7 @@ .Add(nameof(model.Place), model.Place)); private bool PalletsEntryExists(int? orderNr, int? positionNr, string serialNr) - => this.dbContext.FirstOrDefault($@" + => this.sqlClient.FirstOrDefault($@" SELECT CAST(CASE WHEN [PalettenScan].[ID] IS NULL THEN 0 ELSE 1 END AS BIT) FROM [PalettenScan] WHERE [PalettenScan].[AuftragNr] = @{nameof(orderNr)} @@ -300,7 +300,7 @@ reader => reader.GetValue(0)); private bool UpdatePalletsNr(OrderScanModel model) - => this.dbContext.FirstOrDefault($@" + => this.sqlClient.FirstOrDefault($@" BEGIN TRANSACTION ------------------------------------------------------------------------ DECLARE @rowsByAuftragPosition INT = ( diff --git a/LaaProductionWeb/LaaProductionWeb/App_Infrastructure/AllowedRolesAttribute.cs b/LaaProductionWeb/LaaProductionWeb/App_Infrastructure/AllowedRolesAttribute.cs index fa8e2908..78c4ffa2 100644 --- a/LaaProductionWeb/LaaProductionWeb/App_Infrastructure/AllowedRolesAttribute.cs +++ b/LaaProductionWeb/LaaProductionWeb/App_Infrastructure/AllowedRolesAttribute.cs @@ -12,7 +12,8 @@ { if (filterContext.HttpContext.User is ClaimsPrincipal claimsPrincipal) { - filterContext.Result = new RedirectResult($"/Account/Authorize?role={this.Roles}"); + filterContext.Controller.TempData["Unauthorized"] = "Dir fehlen berechtigungen."; + filterContext.Result = new RedirectResult($"/"); } else { diff --git a/LaaProductionWeb/LaaProductionWeb/App_Infrastructure/AuthorizationFilter.cs b/LaaProductionWeb/LaaProductionWeb/App_Infrastructure/AuthorizationFilter.cs index a93c74bf..d2f2b729 100644 --- a/LaaProductionWeb/LaaProductionWeb/App_Infrastructure/AuthorizationFilter.cs +++ b/LaaProductionWeb/LaaProductionWeb/App_Infrastructure/AuthorizationFilter.cs @@ -1,48 +1,34 @@ namespace LaaProductionWeb.App_Infrastructure { using LaaProductionWeb.Services.Interfaces; - - using System; + using System.Collections.Generic; - using System.Linq; + using System.DirectoryServices.AccountManagement; using System.Security.Claims; + using System.Security.Principal; using System.Web.Mvc; public class AuthorizationFilter : IAuthorizationFilter { public void OnAuthorization(AuthorizationContext filterContext) { - if (filterContext.HttpContext.User is ClaimsPrincipal claimsPrincipal) + if (filterContext.HttpContext.User is WindowsPrincipal windowsPrincipal) { - this.GetWindowsUser(claimsPrincipal, out string primarySID, out string domainName, out string userName); - - var accountService = ServiceProvider.Current.GetService(); - var windowsUser = accountService.GetOrCreateWindowsUser(primarySID, domainName, userName); - var claims = new List { new Claim(ClaimTypes.NameIdentifier, $"{windowsUser.UserId}") }; - - foreach (var role in windowsUser.Roles) + using (var principalContext = new PrincipalContext(ContextType.Domain)) { - claims.Add(new Claim(ClaimTypes.Role, role)); + var userPrincipal = UserPrincipal.FindByIdentity(principalContext, windowsPrincipal.Identity.Name); + var accountService = ServiceProvider.Current.GetService(); + var employee = accountService.FindEmployee(userPrincipal.GivenName, userPrincipal.Surname); + var permissionsClaims = new List { new Claim(ClaimTypes.Name, $"{userPrincipal.GivenName} {userPrincipal.Surname}") }; + + foreach (var permission in employee.Permissions) + { + permissionsClaims.Add(new Claim(ClaimTypes.Role, permission)); + } + + windowsPrincipal.AddIdentity(new ClaimsIdentity(permissionsClaims, nameof(ClaimsPrincipal), ClaimTypes.Name, ClaimTypes.Role)); } - - var claimsIdentity = new ClaimsIdentity(claims, nameof(ClaimsPrincipal), ClaimTypes.Name, ClaimTypes.Role); - - claimsPrincipal.AddIdentity(claimsIdentity); } } - - private void GetWindowsUser(ClaimsPrincipal claimsPrincipal, out string primarySID, out string domainName, out string userName) - { - var nameTokens = claimsPrincipal - .FindFirst(ClaimTypes.Name) - ?.Value - ?.ToLower() - ?.Split(new[] { '\\', '/' }, StringSplitOptions.RemoveEmptyEntries) - ?? Array.Empty(); - - primarySID = claimsPrincipal.FindFirst(ClaimTypes.PrimarySid)?.Value; - domainName = nameTokens.FirstOrDefault(); - userName = nameTokens.LastOrDefault(); - } } } \ No newline at end of file diff --git a/LaaProductionWeb/LaaProductionWeb/App_Infrastructure/ControllersExtensions.cs b/LaaProductionWeb/LaaProductionWeb/App_Infrastructure/ControllersExtensions.cs index e4c6b966..b50cecd8 100644 --- a/LaaProductionWeb/LaaProductionWeb/App_Infrastructure/ControllersExtensions.cs +++ b/LaaProductionWeb/LaaProductionWeb/App_Infrastructure/ControllersExtensions.cs @@ -38,24 +38,16 @@ return serviceProvider; } - public static int NameIdentifier(this IPrincipal principal) + public static string Name(this IPrincipal principal) { if (principal is ClaimsPrincipal claimsPrincipal) { - var nameIdentifier = claimsPrincipal.FindFirst(ClaimTypes.NameIdentifier)?.Value; - - if (int.TryParse($"{nameIdentifier}", out int userId)) - { - return userId; - } + return claimsPrincipal + .FindAll(ClaimTypes.Name) + .LastOrDefault()?.Value; } - return -1; - } - - public static T NameIdentifier(this ViewContext viewContext) - { - return default(T); + return ""; } public static string Display(this T model, Expression> expression) diff --git a/LaaProductionWeb/LaaProductionWeb/App_Infrastructure/UserRoles.cs b/LaaProductionWeb/LaaProductionWeb/App_Infrastructure/UserRoles.cs new file mode 100644 index 00000000..8088bf08 --- /dev/null +++ b/LaaProductionWeb/LaaProductionWeb/App_Infrastructure/UserRoles.cs @@ -0,0 +1,11 @@ +namespace LaaProductionWeb.App_Infrastructure +{ + public class UserRoles + { + public const string WEB_Admin = nameof(WEB_Admin); + public const string WEB_HeReport = nameof(WEB_HeReport); + public const string WEB_PalettenScan = nameof(WEB_PalettenScan); + public const string WEB_ProdApproval = nameof(WEB_ProdApproval); + public const string WEB_PuneProtokoll = nameof(WEB_PuneProtokoll); + } +} \ No newline at end of file diff --git a/LaaProductionWeb/LaaProductionWeb/Controllers/AccountController.cs b/LaaProductionWeb/LaaProductionWeb/Controllers/AccountController.cs deleted file mode 100644 index e4aca18b..00000000 --- a/LaaProductionWeb/LaaProductionWeb/Controllers/AccountController.cs +++ /dev/null @@ -1,61 +0,0 @@ -namespace LaaProductionWeb.Controllers -{ - using LaaProductionWeb.App_Infrastructure; - using LaaProductionWeb.Services.Interfaces; - using LaaProductionWeb.Services.Models; - - using System.Collections.Generic; - using System.Web.Mvc; - - [Authorize] - public class AccountController : Controller - { - private readonly IAccountService accountService; - - public AccountController(IAccountService accountService) - => this.accountService = accountService; - - [HttpGet] - public ActionResult Authorize(string role) - { - var userId = this.User.NameIdentifier(); - var permissionsModel = this.accountService - .GetPermissionModelForUser(userId, role); - - return this.View(model: permissionsModel); - } - - [HttpPost] - [ValidateAntiForgeryToken] - public ActionResult Authorize(PermissionsModel model) - { - if (this.ModelState.IsValid) - { - this.accountService.RequestPermissions(model); - } - - return this.View(model); - } - - [HttpGet] - [AllowedRoles("Admin")] - public ActionResult Permissions() - { - var model = this.accountService.GetUsersWithPendingRoles(); - - return this.View(model); - } - - [HttpPost] - [AllowedRoles("Admin")] - [ValidateAntiForgeryToken] - public ActionResult Permissions(List model) - { - this.accountService.SaveUserPermissions(model); - - model = this.accountService.GetUsersWithPendingRoles(); - - return this.View(model); - } - } -} \ No newline at end of file diff --git a/LaaProductionWeb/LaaProductionWeb/Controllers/AdminController.cs b/LaaProductionWeb/LaaProductionWeb/Controllers/AdminController.cs new file mode 100644 index 00000000..15a70ceb --- /dev/null +++ b/LaaProductionWeb/LaaProductionWeb/Controllers/AdminController.cs @@ -0,0 +1,20 @@ +namespace LaaProductionWeb.Controllers +{ + using LaaProductionWeb.App_Infrastructure; + using LaaProductionWeb.Services.Interfaces; + + using System.Web.Mvc; + + [Authorize] + [AllowedRoles(UserRoles.WEB_Admin)] + public class AdminController : Controller + { + private readonly IAccountService accountService; + + public AdminController(IAccountService accountService) + => this.accountService = accountService; + + public ActionResult Index() + => this.View(); + } +} \ No newline at end of file diff --git a/LaaProductionWeb/LaaProductionWeb/Controllers/ApprovalsController.cs b/LaaProductionWeb/LaaProductionWeb/Controllers/ApprovalsController.cs index 35ed2246..2d90f433 100644 --- a/LaaProductionWeb/LaaProductionWeb/Controllers/ApprovalsController.cs +++ b/LaaProductionWeb/LaaProductionWeb/Controllers/ApprovalsController.cs @@ -1,5 +1,6 @@ namespace LaaProductionWeb.Controllers { + using LaaProductionWeb.App_Infrastructure; using LaaProductionWeb.Services.Interfaces; using LaaProductionWeb.Services.Models; @@ -7,6 +8,7 @@ using System.Web.Mvc; [Authorize] + [AllowedRoles(UserRoles.WEB_ProdApproval)] public class ApprovalsController : Controller { private readonly IApprovalsService approvals; diff --git a/LaaProductionWeb/LaaProductionWeb/Controllers/HomeController.cs b/LaaProductionWeb/LaaProductionWeb/Controllers/HomeController.cs index 27fb3462..c54d62ad 100644 --- a/LaaProductionWeb/LaaProductionWeb/Controllers/HomeController.cs +++ b/LaaProductionWeb/LaaProductionWeb/Controllers/HomeController.cs @@ -2,6 +2,7 @@ { using System.Web.Mvc; + [Authorize] public class HomeController : Controller { [HttpGet] diff --git a/LaaProductionWeb/LaaProductionWeb/Controllers/ProtocolController.cs b/LaaProductionWeb/LaaProductionWeb/Controllers/ProtocolController.cs index 2518a914..192c0a3d 100644 --- a/LaaProductionWeb/LaaProductionWeb/Controllers/ProtocolController.cs +++ b/LaaProductionWeb/LaaProductionWeb/Controllers/ProtocolController.cs @@ -1,12 +1,13 @@ namespace LaaProductionWeb.Controllers { + using LaaProductionWeb.App_Infrastructure; using LaaProductionWeb.Services.Interfaces; using LaaProductionWeb.Services.Models; using System.Web.Mvc; [Authorize] - // [AllowedRoles("Protocol")] + [AllowedRoles(UserRoles.WEB_PuneProtokoll)] public class ProtocolController : Controller { public const string FilePDF = nameof(FilePDF); diff --git a/LaaProductionWeb/LaaProductionWeb/Controllers/ReportController.cs b/LaaProductionWeb/LaaProductionWeb/Controllers/ReportController.cs index f26cfcb9..c4a9a8f1 100644 --- a/LaaProductionWeb/LaaProductionWeb/Controllers/ReportController.cs +++ b/LaaProductionWeb/LaaProductionWeb/Controllers/ReportController.cs @@ -1,12 +1,13 @@ namespace LaaProductionWeb.Controllers { + using LaaProductionWeb.App_Infrastructure; using LaaProductionWeb.Services.Interfaces; using LaaProductionWeb.Services.Models; using System.Web.Mvc; [Authorize] - // [AllowedRoles("HeReport")] + [AllowedRoles(UserRoles.WEB_HeReport)] public class ReportController : Controller { private readonly IReportService reportService; diff --git a/LaaProductionWeb/LaaProductionWeb/Controllers/ShipmentsController.cs b/LaaProductionWeb/LaaProductionWeb/Controllers/ShipmentsController.cs index 61689afe..c015b39f 100644 --- a/LaaProductionWeb/LaaProductionWeb/Controllers/ShipmentsController.cs +++ b/LaaProductionWeb/LaaProductionWeb/Controllers/ShipmentsController.cs @@ -1,5 +1,6 @@ namespace LaaProductionWeb.Controllers { + using LaaProductionWeb.App_Infrastructure; using LaaProductionWeb.Services.Interfaces; using LaaProductionWeb.Services.Models; @@ -13,7 +14,7 @@ using SystemFile = System.IO.File; [Authorize] - // [AllowedRoles("Shipment")] + [AllowedRoles(UserRoles.WEB_PalettenScan)] public class ShipmentsController : Controller { private readonly IShipmentsService shipmentsService; diff --git a/LaaProductionWeb/LaaProductionWeb/LaaProductionWeb.csproj b/LaaProductionWeb/LaaProductionWeb/LaaProductionWeb.csproj index 79b430d2..c43f69de 100644 --- a/LaaProductionWeb/LaaProductionWeb/LaaProductionWeb.csproj +++ b/LaaProductionWeb/LaaProductionWeb/LaaProductionWeb.csproj @@ -65,6 +65,7 @@ + ..\packages\Microsoft.AspNet.WebApi.Client.5.2.9\lib\net45\System.Net.Http.Formatting.dll @@ -72,6 +73,9 @@ ..\packages\System.Runtime.CompilerServices.Unsafe.6.0.0\lib\net461\System.Runtime.CompilerServices.Unsafe.dll + + ..\packages\System.Security.Principal.Windows.5.0.0\lib\net461\System.Security.Principal.Windows.dll + ..\packages\System.Threading.Tasks.Extensions.4.5.4\lib\net461\System.Threading.Tasks.Extensions.dll @@ -137,12 +141,13 @@ + - + @@ -176,9 +181,6 @@ - - - @@ -186,6 +188,7 @@ + diff --git a/LaaProductionWeb/LaaProductionWeb/Views/Account/Authorize.cshtml b/LaaProductionWeb/LaaProductionWeb/Views/Account/Authorize.cshtml deleted file mode 100644 index 62a158e7..00000000 --- a/LaaProductionWeb/LaaProductionWeb/Views/Account/Authorize.cshtml +++ /dev/null @@ -1,35 +0,0 @@ -@model PermissionsModel - -@using LaaProductionWeb.Services.Models - -
- @if (this.Model.Role.Pending is null) - { -
-
- @this.Html.AntiForgeryToken() - @this.Html.HiddenFor(x => x.UserId) - @this.Html.Partial(nameof(UserRole), this.Model.Role, new ViewDataDictionary { { "namePattern", $"{nameof(this.Model.Role)}.{{0}}" } }) -
Ihnen fehlt die Berechtigung – '@this.Model.Role.DisplayName'.
-
- @this.Html.TextBoxFor(x => x.FirstName, new { @class = "form-control", placeholder = "Vorname" }) - @this.Html.LabelFor(x => x.FirstName, new { @class = "text-secondary" }) - @this.Html.ValidationMessageFor(x => x.FirstName, string.Empty, new { @class = "small text-danger" }) -
-
- @this.Html.TextBoxFor(x => x.LastName, new { @class = "form-control", placeholder = "Vorname" }) - @this.Html.LabelFor(x => x.LastName, new { @class = "text-secondary" }) - @this.Html.ValidationMessageFor(x => x.LastName, string.Empty, new { @class = "small text-danger" }) -
- -
-
- } - else - { -
-

-
Ihre anfrage für die berechtigung – '@this.Model.Role.DisplayName' ist in bearbeitung ...
-
- } -
diff --git a/LaaProductionWeb/LaaProductionWeb/Views/Account/Permissions.cshtml b/LaaProductionWeb/LaaProductionWeb/Views/Account/Permissions.cshtml deleted file mode 100644 index 38f3b306..00000000 --- a/LaaProductionWeb/LaaProductionWeb/Views/Account/Permissions.cshtml +++ /dev/null @@ -1,60 +0,0 @@ -@model List - -@if (this.Model.Any()) -{ -
- @this.Html.AntiForgeryToken() -
    - @{ - var usersCount = this.Model.Count; - - for (int userIndex = 0; userIndex < usersCount; userIndex++) - { - var user = this.Model[userIndex]; - var hiddenUserId = $"[{userIndex}].{nameof(user.UserId)}"; - var hiddenUserName = $"[{userIndex}].{nameof(user.DisplayName)}"; - -
  • - - -
    @user.DisplayName
    -
  • -
  • - - - - - - - - - - - @{ - var rolesCount = user.Roles.Count; - - for (int roleIndex = 0; roleIndex < rolesCount; roleIndex++) - { - var role = user.Roles[roleIndex]; - var hiddenRoleId = $"[{userIndex}].{nameof(user.Roles)}[{roleIndex}].{nameof(role.RoleId)}"; - var hiddenRoleName = $"[{userIndex}].{nameof(user.Roles)}[{roleIndex}].{nameof(role.RoleName)}"; - var roleApproved = $"[{userIndex}].{nameof(user.Roles)}[{roleIndex}].{nameof(role.Approved)}"; - var roleDeleted = $"[{userIndex}].{nameof(user.Roles)}[{roleIndex}].{nameof(role.Deleted)}"; - - - - - - - - } - } - -
    Role IdRole NameIs ApprovedIs Deleted
    @role.RoleId @role.RoleName @this.Html.CheckBox(roleApproved, role.Approved, new { @class = "form-check-input" })@this.Html.CheckBox(roleDeleted, role.Deleted, new { @class = "form-check-input" })
    -
  • - } - } -
- -
-} \ No newline at end of file diff --git a/LaaProductionWeb/LaaProductionWeb/Views/Account/UserRole.cshtml b/LaaProductionWeb/LaaProductionWeb/Views/Account/UserRole.cshtml deleted file mode 100644 index bb3077f7..00000000 --- a/LaaProductionWeb/LaaProductionWeb/Views/Account/UserRole.cshtml +++ /dev/null @@ -1,14 +0,0 @@ -@model LaaProductionWeb.Services.Models.UserRole - -@{ - var namePattern = "{0}"; - - if (this.ViewData.TryGetValue(nameof(namePattern), out object value)) - { - namePattern = $"{value}"; - } -} - -@this.Html.Hidden(string.Format(namePattern, nameof(this.Model.RoleId)), this.Model.RoleId) -@this.Html.Hidden(string.Format(namePattern, nameof(this.Model.RoleName)), this.Model.RoleName) -@this.Html.Hidden(string.Format(namePattern, nameof(this.Model.DisplayName)), this.Model.DisplayName) diff --git a/LaaProductionWeb/LaaProductionWeb/Views/Admin/Index.cshtml b/LaaProductionWeb/LaaProductionWeb/Views/Admin/Index.cshtml new file mode 100644 index 00000000..f0ea3b02 --- /dev/null +++ b/LaaProductionWeb/LaaProductionWeb/Views/Admin/Index.cshtml @@ -0,0 +1,3 @@ + +

Hallo admin

+ diff --git a/LaaProductionWeb/LaaProductionWeb/Views/Shared/_Layout.cshtml b/LaaProductionWeb/LaaProductionWeb/Views/Shared/_Layout.cshtml index f8f963eb..27a9e30f 100644 --- a/LaaProductionWeb/LaaProductionWeb/Views/Shared/_Layout.cshtml +++ b/LaaProductionWeb/LaaProductionWeb/Views/Shared/_Layout.cshtml @@ -1,11 +1,4 @@ -@{ - var user = this.User - ?.Identity - ?.Name - ?.Split('\\') - ?.LastOrDefault() - ?.ToLower(); -} +@using LaaProductionWeb.App_Infrastructure @@ -29,23 +22,44 @@ diff --git a/LaaProductionWeb/LaaProductionWeb/Web.config b/LaaProductionWeb/LaaProductionWeb/Web.config index 3c45b564..99f8defa 100644 --- a/LaaProductionWeb/LaaProductionWeb/Web.config +++ b/LaaProductionWeb/LaaProductionWeb/Web.config @@ -9,7 +9,7 @@ - + diff --git a/LaaProductionWeb/LaaProductionWeb/packages.config b/LaaProductionWeb/LaaProductionWeb/packages.config index 13dcde0d..3b433207 100644 --- a/LaaProductionWeb/LaaProductionWeb/packages.config +++ b/LaaProductionWeb/LaaProductionWeb/packages.config @@ -15,7 +15,9 @@ + + \ No newline at end of file