Skip to content

Instantly share code, notes, and snippets.

@Ibro
Created April 26, 2018 11:46
Show Gist options
  • Star 0 You must be signed in to star a gist
  • Fork 0 You must be signed in to fork a gist
  • Save Ibro/cb72d575086d30126259d73a08fbe35a to your computer and use it in GitHub Desktop.
Save Ibro/cb72d575086d30126259d73a08fbe35a to your computer and use it in GitHub Desktop.
public class AuthorizeResourceAttribute : TypeFilterAttribute
{
public AuthorizeResourceAttribute(Type requirementType)
: base(typeof(AuthorizeResourceFilter))
{
Arguments = new object[] { requirementType };
}
private class AuthorizeResourceFilter : IAsyncActionFilter
{
private readonly IAuthorizationService _authorizationService;
private readonly Type _requirementType;
public AuthorizeResourceFilter(ApplicationDbContext dbContext, IAuthorizationService authorizationService, Type requirementType)
{
_authorizationService = authorizationService;
_requirementType = requirementType;
}
public async Task OnActionExecutionAsync(ActionExecutingContext context, ActionExecutionDelegate next)
{
var resource = context.ActionArguments.First().Value;
var requirement = Activator.CreateInstance(_requirementType) as IAuthorizationRequirement;
var authorizationResult = await _authorizationService.AuthorizeAsync(context.HttpContext.User, resource, requirement);
if (!authorizationResult.Succeeded)
{
context.Result = new ForbidResult();
return;
}
await next();
}
}
}
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment