feat(web): add Discord OAuth service and authorization endpoints
- DiscordOAuthOptions for client_id, secret, redirect_uri - DiscordAuthService exchanges code for token and fetches user profile - /auth/discord and /auth/discord/callback endpoints - CreateDiscordPrincipal for cookie auth claims - Telegram principal now includes Platform claim for forward compatibility Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
This commit is contained in:
@@ -16,6 +16,12 @@ var builder = WebApplication.CreateBuilder(args);
|
||||
// Add Aspire service defaults
|
||||
builder.AddServiceDefaults();
|
||||
|
||||
// Add HttpClient
|
||||
builder.Services.AddHttpClient();
|
||||
|
||||
// Add HttpContextAccessor for platform-agnostic identity resolution
|
||||
builder.Services.AddHttpContextAccessor();
|
||||
|
||||
// Add health checks
|
||||
builder.Services.AddHealthChecks()
|
||||
.AddCheck<NpgsqlHealthCheck>("npgsql");
|
||||
@@ -29,6 +35,8 @@ builder.AddNpgsqlDataSource("gmrelaydb");
|
||||
|
||||
// Add Services
|
||||
builder.Services.AddSingleton<TelegramAuthService>();
|
||||
builder.Services.Configure<DiscordOAuthOptions>(builder.Configuration.GetSection("Discord"));
|
||||
builder.Services.AddSingleton<DiscordAuthService>();
|
||||
builder.Services.AddSingleton<ISessionStore, SessionService>();
|
||||
builder.Services.AddScoped<AuthorizedSessionService>();
|
||||
builder.Services.AddScoped<CalendarSubscriptionService>();
|
||||
@@ -174,6 +182,38 @@ app.MapPost("/auth/logout", async (HttpContext context) =>
|
||||
return Results.Redirect("/");
|
||||
});
|
||||
|
||||
// Discord OAuth endpoints
|
||||
app.MapGet("/auth/discord", (DiscordAuthService discordAuth) =>
|
||||
{
|
||||
var state = Guid.NewGuid().ToString("N");
|
||||
var url = discordAuth.BuildAuthorizeUrl(state);
|
||||
return Results.Redirect(url);
|
||||
});
|
||||
|
||||
app.MapGet("/auth/discord/callback", async (
|
||||
HttpContext context,
|
||||
DiscordAuthService discordAuth,
|
||||
ISessionStore sessionStore) =>
|
||||
{
|
||||
var code = context.Request.Query["code"].ToString();
|
||||
if (string.IsNullOrWhiteSpace(code))
|
||||
return Results.Redirect("/login?error=auth_failed");
|
||||
|
||||
var user = await discordAuth.ExchangeCodeAsync(code);
|
||||
if (user is null)
|
||||
return Results.Redirect("/login?error=auth_failed");
|
||||
|
||||
await sessionStore.UpsertDiscordUserAsync(user.Id, user.DisplayName, user.AvatarUrl);
|
||||
|
||||
var authProperties = new AuthenticationProperties { IsPersistent = true };
|
||||
await context.SignInAsync(
|
||||
CookieAuthenticationDefaults.AuthenticationScheme,
|
||||
CreateDiscordPrincipal(user.Id, user.DisplayName, user.AvatarUrl),
|
||||
authProperties);
|
||||
|
||||
return Results.Redirect("/");
|
||||
});
|
||||
|
||||
// Public calendar subscription endpoint (no auth required)
|
||||
app.MapGet("/calendar/{token}.ics", async (
|
||||
string token,
|
||||
@@ -200,11 +240,29 @@ static ClaimsPrincipal CreateTelegramPrincipal(long telegramId, string name)
|
||||
{
|
||||
new(ClaimTypes.NameIdentifier, telegramId.ToString(System.Globalization.CultureInfo.InvariantCulture)),
|
||||
new(ClaimTypes.Name, name),
|
||||
new("TelegramId", telegramId.ToString(System.Globalization.CultureInfo.InvariantCulture))
|
||||
new("TelegramId", telegramId.ToString(System.Globalization.CultureInfo.InvariantCulture)),
|
||||
new("Platform", "Telegram")
|
||||
};
|
||||
|
||||
var claimsIdentity = new ClaimsIdentity(claims, CookieAuthenticationDefaults.AuthenticationScheme);
|
||||
return new ClaimsPrincipal(claimsIdentity);
|
||||
}
|
||||
|
||||
static ClaimsPrincipal CreateDiscordPrincipal(string discordId, string name, string? avatarUrl)
|
||||
{
|
||||
var claims = new List<Claim>
|
||||
{
|
||||
new(ClaimTypes.NameIdentifier, discordId),
|
||||
new(ClaimTypes.Name, name),
|
||||
new("DiscordId", discordId),
|
||||
new("Platform", "Discord")
|
||||
};
|
||||
|
||||
if (!string.IsNullOrWhiteSpace(avatarUrl))
|
||||
claims.Add(new Claim("AvatarUrl", avatarUrl));
|
||||
|
||||
var claimsIdentity = new ClaimsIdentity(claims, CookieAuthenticationDefaults.AuthenticationScheme);
|
||||
return new ClaimsPrincipal(claimsIdentity);
|
||||
}
|
||||
|
||||
public sealed record TelegramWebAppAuthRequest(string InitData);
|
||||
|
||||
Reference in New Issue
Block a user