Add JWT auth, token service & Neutrino endpoint

This commit is contained in:
Holden
2026-06-19 12:25:45 -05:00
parent 608def3ac8
commit 3eebfc9ba2
27 changed files with 581 additions and 51 deletions

View File

@@ -1,5 +1,5 @@
using Microsoft.AspNetCore.Mvc;
using RecNet.Application.Services.Configuration;
using Microsoft.AspNetCore.Mvc;
using RecNet.Domain.Services.Configuration;
namespace API.Controllers.Config.V1;
@@ -11,7 +11,7 @@ public class ConfigController(IConfigService configService) : ControllerBase
public async Task<ActionResult<string>> GetMotd(CancellationToken ct = default)
{
var motd = await configService.GetAsync("Config:MOTD", "Ten Whole Years!", ct);
return Ok(motd);
}
}
}

View File

@@ -0,0 +1,82 @@
using System.Security.Claims;
using System.Text.Json;
using API.Contracts.Neutrino.Enums;
using API.Contracts.Neutrino.Requests;
using API.Contracts.Neutrino.Responses;
using Microsoft.AspNetCore.Mvc;
using RecNet.Domain.Repositories;
using RecNet.Domain.Services.Tokens;
namespace API.Controllers.Neutrino;
[Route("[controller]")]
[ApiController]
public class NeutrinoController(
IProfileRepository profileRepository,
ITokenService tokenService) : ControllerBase
{
// This route will be kind of abysmal so bare with it.
[Route("authorize")]
public async Task<ActionResult<NeutrinoAuthenticateResponse>> AuthorizeNeutrinoAsync()
{
// Photon sends the request with Content-Type: text/plain instead of application/json
// This is a really janky workaround since we can't use [FromBody] to automatically parse the data.
using var reader = new StreamReader(Request.Body);
string rawText = await reader.ReadToEndAsync();
NeutrinoAuthenticateRequest? request;
try
{
request = JsonSerializer.Deserialize<NeutrinoAuthenticateRequest>(rawText, new JsonSerializerOptions
{
IncludeFields = true,
PropertyNameCaseInsensitive = true
});
}
catch
{
return Ok(
NeutrinoAuthenticateResponse.Failure(
AuthenticationResultCode.InvalidParameters));
}
// 1. Check if request parameters aren't empty
if (request is null ||
request.ProfileId == Guid.Empty ||
string.IsNullOrWhiteSpace(request.AccessToken))
return Ok(
NeutrinoAuthenticateResponse.Failure(
AuthenticationResultCode.InvalidParameters));
// 2. Verify accessToken is valid
var tokenVerifyResult = tokenService.VerifyToken(request.AccessToken);
if (tokenVerifyResult.IsError || !TryGetProfileId(tokenVerifyResult.Claims, out var tokenAccountId))
return Ok(
NeutrinoAuthenticateResponse.Failure(
AuthenticationResultCode.AuthenticationFailedWrongCredentials));
// 3. Verify that the accountId from the request matches the one from the token
if (tokenAccountId != request.ProfileId)
return Ok(
NeutrinoAuthenticateResponse.Failure(
AuthenticationResultCode.AuthenticationFailedWrongCredentials));
// 4. Get the profile to check if it exists, and for the name
var profile = await profileRepository.GetByIdAsync(request.ProfileId);
if (profile is null)
return Ok(
NeutrinoAuthenticateResponse.Failure(
AuthenticationResultCode.AuthenticationFailedWrongCredentials));
return Ok(
NeutrinoAuthenticateResponse.Success(
userId: request.ProfileId.ToString(),
nickname: profile.Name
)
);
}
private static bool TryGetProfileId(IEnumerable<Claim> claims, out Guid accountId)
=> Guid.TryParse(claims.FirstOrDefault(c => c.Type == "sub")?.Value, out accountId);
}

View File

@@ -1,8 +1,10 @@
using API.Contracts.Profiles.Responses;
using API.Contracts.Profiles.Responses;
using AutoMapper;
using Microsoft.AspNetCore.Authorization;
using Microsoft.AspNetCore.Mvc;
using RecNet.Application.Profiles;
using RecNet.Domain.Repositories;
using RecNet.Domain.Services.Tokens;
using LoginRequest = API.Contracts.Profiles.Requests.LoginRequest;
using Profile = RecNet.Domain.Entities.Profiles.Profile;
@@ -10,9 +12,11 @@ namespace API.Controllers.Profiles.V1;
[Route("api/[controller]/v1")]
[ApiController]
[Authorize]
public class ProfilesController(
IProfileRepository profileRepository,
IMapper mapper) : ControllerBase
IProfileRepository profileRepository,
IMapper mapper,
ITokenService tokenService) : ControllerBase
{
[HttpGet("{id:guid}")]
public async Task<ActionResult<ProfileDTO>> GetProfile(
@@ -22,7 +26,7 @@ public class ProfilesController(
var profile = await profileRepository.GetByIdAsync(id, ct);
if (profile == null)
return NotFound();
return mapper.Map<ProfileDTO>(profile);
}
@@ -32,33 +36,44 @@ public class ProfilesController(
CancellationToken ct)
{
var profiles = await profileRepository.GetByIdsAsync(ids, ct);
return mapper.Map<List<ProfileDTO>>(profiles);
}
// TODO: Implement
[AllowAnonymous]
[HttpPost("login")]
public async Task<ActionResult<LoginResponse>> Login(
[FromBody] LoginRequest request,
CancellationToken ct)
{
var name = GenerateRandomName();
var profile = await profileRepository.GetByPlatform(request.PlatformType, request.PlatformId, ct);
if (profile is null)
{
profile = Profile.Create(request.Username, request.PlatformType, request.PlatformId);
profile = Profile.Create(name, request.PlatformType, request.PlatformId);
await profileRepository.AddAsync(profile, ct);
}
profile.AddDeviceId(request.DeviceId);
if (request.Username != profile.Name)
profile.SetName(request.Username);
await profileRepository.SaveChangesAsync(ct);
if (profile.IsBanned)
return BadRequest();
var token = tokenService.GenerateProfileToken(profile);
return new LoginResponse
{
Profile = mapper.Map<ProfileDTO>(profile)
Profile = mapper.Map<ProfileDTO>(profile),
AccessToken = token.AccessToken,
ExpiresIn = token.ExpiresIn
};
}
}
// TODO: REPLACE WITH BETTER GENERATOR, THIS IS TEMP.
private static string GenerateRandomName()
=> string.Concat("rr", Guid.NewGuid().ToString("N").AsSpan(0, 18));
}