Пример #1
0
        protected override async Task <AuthenticateResult> HandleAuthenticateAsync()
        {
            if (!Request.Headers.ContainsKey("Authorization"))
            {
                return(AuthenticateResult.Fail("Missing Authorization Header"));
            }

            OnlineGym_Model.Korisnik user = null;
            OnlineGym_Model.Clan     clan = null;
            var context = "";

            try
            {
                context = Request.Headers["Context"];
                var authHeader      = AuthenticationHeaderValue.Parse(Request.Headers["Authorization"]);
                var credentialBytes = Convert.FromBase64String(authHeader.Parameter);
                var credentials     = Encoding.UTF8.GetString(credentialBytes).Split(':');
                var username        = credentials[0];
                var password        = credentials[1];
                if ("Clan".Equals(context))
                {
                    clan = _clanService.Authenticiraj(username, password);
                }
                else
                {
                    user = _userService.Authenticiraj(username, password);
                }
            }
            catch (Exception e)
            {
                return(AuthenticateResult.Fail("Invalid Authorization Header"));
            }
            var claims = new List <Claim>();

            if ("Clan".Equals(context))
            {
                if (clan == null)
                {
                    return(AuthenticateResult.Fail("Invalid Username or Password"));
                }
            }
            else
            {
                if (user == null)
                {
                    return(AuthenticateResult.Fail("Invalid Username or Password"));
                }

                claims = new List <Claim> {
                    new Claim(ClaimTypes.NameIdentifier, user.KorisnickoIme),
                    new Claim(ClaimTypes.Name, user.Ime),
                };

                foreach (var role in user.KorisniciUloge)
                {
                    claims.Add(new Claim(ClaimTypes.Role, role.Uloga.Naziv));
                }
            }

            var identity  = new ClaimsIdentity(claims, Scheme.Name);
            var principal = new ClaimsPrincipal(identity);
            var ticket    = new AuthenticationTicket(principal, Scheme.Name);

            return(AuthenticateResult.Success(ticket));
        }