| | | 1 | | using Chronicis.Shared.Admin; |
| | | 2 | | |
| | | 3 | | namespace Chronicis.Client.Services; |
| | | 4 | | |
| | | 5 | | /// <summary> |
| | | 6 | | /// System admin authorization service. |
| | | 7 | | /// Delegates to <see cref="ISysAdminChecker"/> which reads from the "SysAdmin" |
| | | 8 | | /// configuration section, eliminating hardcoded identity sets. |
| | | 9 | | /// </summary> |
| | | 10 | | public class AdminAuthService : IAdminAuthService |
| | | 11 | | { |
| | | 12 | | private readonly IAuthService _authService; |
| | | 13 | | private readonly ISysAdminChecker _sysAdminChecker; |
| | | 14 | | private readonly ILogger<AdminAuthService> _logger; |
| | | 15 | | |
| | | 16 | | public AdminAuthService( |
| | | 17 | | IAuthService authService, |
| | | 18 | | ISysAdminChecker sysAdminChecker, |
| | | 19 | | ILogger<AdminAuthService> logger) |
| | | 20 | | { |
| | 5 | 21 | | _authService = authService; |
| | 5 | 22 | | _sysAdminChecker = sysAdminChecker; |
| | 5 | 23 | | _logger = logger; |
| | 5 | 24 | | } |
| | | 25 | | |
| | | 26 | | /// <inheritdoc/> |
| | | 27 | | public async Task<bool> IsSysAdminAsync() |
| | | 28 | | { |
| | | 29 | | var user = await _authService.GetCurrentUserAsync(); |
| | | 30 | | if (user == null) |
| | | 31 | | { |
| | | 32 | | _logger.LogDebug("IsSysAdminAsync: no current user, returning false"); |
| | | 33 | | return false; |
| | | 34 | | } |
| | | 35 | | |
| | | 36 | | return _sysAdminChecker.IsSysAdmin(user.Auth0UserId, user.Email); |
| | | 37 | | } |
| | | 38 | | } |