Beispiel #1
0
        public async Task <Content <EndUser> > AuthenticateUserAsync(
            String email,
            String password)
        {
            var resultContent = new Content <EndUser>();

            try
            {
                var emailHashed = BCrypt.Net.BCrypt.HashPassword(email, _appSettings_.Secret);
                var dbContent   = await GetUserWithSensitiveDataAsync(emailHashed, true);

                if (dbContent.HasError)
                {
                    resultContent.AppendError(dbContent);
                    _logger_.LogError(resultContent.Errors.Last()?.Exception, resultContent.Errors.Last()?.Description);
                }
                else
                {
                    var ss              = BCrypt.Net.BCrypt.GenerateSalt();
                    var passwordHashed  = BCrypt.Net.BCrypt.HashPassword(password, dbContent.Data.Salt);
                    var isAuthenticated = await _endUserRepository_.TryAuthenticateAsync(emailHashed, passwordHashed);

                    if (!isAuthenticated)
                    {
                        var message = $"{nameof(user)} with email {email} not authenticated";
                        resultContent.AppendError(new KeyNotFoundException(), message);
                        _logger_.LogError(message);
                    }
                    else
                    {
                        resultContent.SetData(dbContent.Data.ReturnWithoutSensitiveData());
                    }
                }
            }
            catch (Exception e)
            {
                var message = $"Unable to authenticate {nameof(user)} with email {email}";
                resultContent.AppendError(e, message);
                _logger_.LogError(e, message);
            }
            return(resultContent);
        }