ShiftScheduler/Client/ServerAuthenticationStateProvider.cs
Copilot e8db13191e
Add Google OAuth authentication with configurable authorized emails (#29)
* Initial plan

* Add Google authentication with authorized email configuration

Co-authored-by: clayschaad <11883505+clayschaad@users.noreply.github.com>

* Complete Google authentication implementation with documentation

Co-authored-by: clayschaad <11883505+clayschaad@users.noreply.github.com>

* Fix CORS error by removing [Authorize] from auth user endpoint

Co-authored-by: clayschaad <11883505+clayschaad@users.noreply.github.com>

* Add authorization attribute to ConfigurationController for security

Co-authored-by: clayschaad <11883505+clayschaad@users.noreply.github.com>

* Fix JavaScript error in login button by correcting window.location.href usage

Co-authored-by: clayschaad <11883505+clayschaad@users.noreply.github.com>

* Fix Google OAuth redirect URI configuration to resolve authentication error

Co-authored-by: clayschaad <11883505+clayschaad@users.noreply.github.com>

* Fix OAuth state validation error by specifying authentication scheme in callback

Co-authored-by: clayschaad <11883505+clayschaad@users.noreply.github.com>

* Fix OAuth state validation error by improving authentication configuration

Co-authored-by: clayschaad <11883505+clayschaad@users.noreply.github.com>

* Fix authentication setup documentation with correct redirect URI

Co-authored-by: clayschaad <11883505+clayschaad@users.noreply.github.com>

* Fix navigation buttons overlapping with authentication header

Co-authored-by: clayschaad <11883505+clayschaad@users.noreply.github.com>

* Remove unused unsing

---------

Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: clayschaad <11883505+clayschaad@users.noreply.github.com>
Co-authored-by: Claudio Schaad <clayschaad@users.noreply.github.com>
Co-authored-by: Claudio Schaad <c.schaad@pog.ch>
2025-08-27 21:18:50 +02:00

55 lines
No EOL
1.7 KiB
C#

using Microsoft.AspNetCore.Components.Authorization;
using System.Net.Http.Json;
using System.Security.Claims;
namespace ShiftScheduler.Client
{
public class ServerAuthenticationStateProvider : AuthenticationStateProvider
{
private readonly HttpClient _httpClient;
public ServerAuthenticationStateProvider(HttpClient httpClient)
{
_httpClient = httpClient;
}
public override async Task<AuthenticationState> GetAuthenticationStateAsync()
{
try
{
var userInfo = await _httpClient.GetFromJsonAsync<UserInfo>("api/auth/user");
if (userInfo?.IsAuthenticated == true && !string.IsNullOrEmpty(userInfo.Email))
{
var claims = new List<Claim>
{
new Claim(ClaimTypes.Name, userInfo.Email),
new Claim(ClaimTypes.Email, userInfo.Email)
};
var identity = new ClaimsIdentity(claims, "Server authentication");
var user = new ClaimsPrincipal(identity);
return new AuthenticationState(user);
}
}
catch (HttpRequestException)
{
// User is not authenticated
}
return new AuthenticationState(new ClaimsPrincipal(new ClaimsIdentity()));
}
public void NotifyAuthenticationStateChanged()
{
NotifyAuthenticationStateChanged(GetAuthenticationStateAsync());
}
}
public class UserInfo
{
public string? Email { get; set; }
public bool IsAuthenticated { get; set; }
}
}