* Initial plan * Add Google authentication with authorized email configuration Co-authored-by: clayschaad <11883505+clayschaad@users.noreply.github.com> * Complete Google authentication implementation with documentation Co-authored-by: clayschaad <11883505+clayschaad@users.noreply.github.com> * Fix CORS error by removing [Authorize] from auth user endpoint Co-authored-by: clayschaad <11883505+clayschaad@users.noreply.github.com> * Add authorization attribute to ConfigurationController for security Co-authored-by: clayschaad <11883505+clayschaad@users.noreply.github.com> * Fix JavaScript error in login button by correcting window.location.href usage Co-authored-by: clayschaad <11883505+clayschaad@users.noreply.github.com> * Fix Google OAuth redirect URI configuration to resolve authentication error Co-authored-by: clayschaad <11883505+clayschaad@users.noreply.github.com> * Fix OAuth state validation error by specifying authentication scheme in callback Co-authored-by: clayschaad <11883505+clayschaad@users.noreply.github.com> * Fix OAuth state validation error by improving authentication configuration Co-authored-by: clayschaad <11883505+clayschaad@users.noreply.github.com> * Fix authentication setup documentation with correct redirect URI Co-authored-by: clayschaad <11883505+clayschaad@users.noreply.github.com> * Fix navigation buttons overlapping with authentication header Co-authored-by: clayschaad <11883505+clayschaad@users.noreply.github.com> * Remove unused unsing --------- Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com> Co-authored-by: clayschaad <11883505+clayschaad@users.noreply.github.com> Co-authored-by: Claudio Schaad <clayschaad@users.noreply.github.com> Co-authored-by: Claudio Schaad <c.schaad@pog.ch>
55 lines
No EOL
1.6 KiB
C#
55 lines
No EOL
1.6 KiB
C#
using Microsoft.AspNetCore.Authentication;
|
|
using Microsoft.AspNetCore.Authentication.Google;
|
|
using Microsoft.AspNetCore.Authorization;
|
|
using Microsoft.AspNetCore.Mvc;
|
|
using System.Security.Claims;
|
|
|
|
namespace ShiftScheduler.Server.Controllers
|
|
{
|
|
[ApiController]
|
|
[Route("api/[controller]")]
|
|
public class AuthController : ControllerBase
|
|
{
|
|
private readonly List<string> _authorizedEmails;
|
|
|
|
public AuthController(List<string> authorizedEmails)
|
|
{
|
|
_authorizedEmails = authorizedEmails;
|
|
}
|
|
|
|
[HttpGet("login")]
|
|
public IActionResult Login()
|
|
{
|
|
return Challenge(new AuthenticationProperties
|
|
{
|
|
RedirectUri = "/"
|
|
}, GoogleDefaults.AuthenticationScheme);
|
|
}
|
|
|
|
[HttpPost("logout")]
|
|
[Authorize]
|
|
public async Task<IActionResult> Logout()
|
|
{
|
|
await HttpContext.SignOutAsync();
|
|
return Ok();
|
|
}
|
|
|
|
[HttpGet("user")]
|
|
public IActionResult GetUser()
|
|
{
|
|
if (User.Identity?.IsAuthenticated == true)
|
|
{
|
|
var emailClaim = User.FindFirst(ClaimTypes.Email) ??
|
|
User.FindFirst("email");
|
|
|
|
// Verify the user is in the authorized emails list
|
|
if (emailClaim?.Value != null && _authorizedEmails.Contains(emailClaim.Value))
|
|
{
|
|
return Ok(new { Email = emailClaim.Value, IsAuthenticated = true });
|
|
}
|
|
}
|
|
|
|
return Ok(new { Email = (string?)null, IsAuthenticated = false });
|
|
}
|
|
}
|
|
} |