Add application services for profiles and neutrino

This commit is contained in:
Holden
2026-06-19 12:57:31 -05:00
parent 3eebfc9ba2
commit 0b81cb046a
25 changed files with 274 additions and 125 deletions

View File

@@ -1,28 +1,23 @@
using System.Security.Claims;
using System.Text.Json;
using API.Contracts.Neutrino.Enums;
using API.Contracts.Neutrino.Requests;
using API.Contracts.Neutrino.Responses;
using Microsoft.AspNetCore.Mvc;
using RecNet.Domain.Repositories;
using RecNet.Domain.Services.Tokens;
using RecNet.Application.Neutrino;
namespace API.Controllers.Neutrino;
[Route("[controller]")]
[ApiController]
public class NeutrinoController(
IProfileRepository profileRepository,
ITokenService tokenService) : ControllerBase
public class NeutrinoController(INeutrinoAuthorizationService authorizationService) : ControllerBase
{
// This route will be kind of abysmal so bare with it.
// Photon sends the request with Content-Type: text/plain instead of application/json.
[Route("authorize")]
public async Task<ActionResult<NeutrinoAuthenticateResponse>> AuthorizeNeutrinoAsync()
public async Task<ActionResult<NeutrinoAuthenticateResponse>> AuthorizeNeutrinoAsync(
CancellationToken ct)
{
// Photon sends the request with Content-Type: text/plain instead of application/json
// This is a really janky workaround since we can't use [FromBody] to automatically parse the data.
using var reader = new StreamReader(Request.Body);
string rawText = await reader.ReadToEndAsync();
string rawText = await reader.ReadToEndAsync(ct);
NeutrinoAuthenticateRequest? request;
@@ -41,42 +36,30 @@ public class NeutrinoController(
AuthenticationResultCode.InvalidParameters));
}
// 1. Check if request parameters aren't empty
if (request is null ||
request.ProfileId == Guid.Empty ||
string.IsNullOrWhiteSpace(request.AccessToken))
if (request is null)
return Ok(
NeutrinoAuthenticateResponse.Failure(
AuthenticationResultCode.InvalidParameters));
// 2. Verify accessToken is valid
var tokenVerifyResult = tokenService.VerifyToken(request.AccessToken);
if (tokenVerifyResult.IsError || !TryGetProfileId(tokenVerifyResult.Claims, out var tokenAccountId))
return Ok(
NeutrinoAuthenticateResponse.Failure(
AuthenticationResultCode.AuthenticationFailedWrongCredentials));
var result = await authorizationService.AuthorizeAsync(
new AuthorizeNeutrinoCommand(
request.ProfileId,
request.AccessToken),
ct);
// 3. Verify that the accountId from the request matches the one from the token
if (tokenAccountId != request.ProfileId)
if (!result.Succeeded)
return Ok(
NeutrinoAuthenticateResponse.Failure(
AuthenticationResultCode.AuthenticationFailedWrongCredentials));
// 4. Get the profile to check if it exists, and for the name
var profile = await profileRepository.GetByIdAsync(request.ProfileId);
if (profile is null)
return Ok(
NeutrinoAuthenticateResponse.Failure(
AuthenticationResultCode.AuthenticationFailedWrongCredentials));
MapFailure(result.Failure)));
return Ok(
NeutrinoAuthenticateResponse.Success(
userId: request.ProfileId.ToString(),
nickname: profile.Name
)
);
result.UserId!,
result.Nickname!));
}
private static bool TryGetProfileId(IEnumerable<Claim> claims, out Guid accountId)
=> Guid.TryParse(claims.FirstOrDefault(c => c.Type == "sub")?.Value, out accountId);
}
private static AuthenticationResultCode MapFailure(NeutrinoAuthorizationFailure? failure)
=> failure == NeutrinoAuthorizationFailure.InvalidParameters
? AuthenticationResultCode.InvalidParameters
: AuthenticationResultCode.AuthenticationFailedWrongCredentials;
}