Skip to content

Commit b98aa28

Browse files
authored
Enforce dedicated scopes for Visualiser (#69)
Enforces dedicated visualiser scopes. Updates the API to use dedicated scopes for the visualiser application. This change improves security by isolating the permissions required for visualiser functionality from the core data management system (DMS).
1 parent 81b4dbc commit b98aa28

4 files changed

Lines changed: 16 additions & 5 deletions

File tree

src/API/Endpoints/VisualisationEndpoints.cs

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -22,9 +22,9 @@ public static IEndpointRouteBuilder RegisterVisualisationEndpoints(this IEndpoin
2222

2323
group.MapPost("/Save", SaveNetworkAsync)
2424
.ProducesProblem(StatusCodes.Status500InternalServerError)
25-
.RequireAuthorization("write");
25+
.RequireAuthorization("visualisation-write");
2626

27-
group.RequireAuthorization("read");
27+
group.RequireAuthorization("visualisation-read");
2828

2929
return routes;
3030
}

src/API/Program.cs

Lines changed: 11 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -73,6 +73,17 @@
7373
{
7474
options.AddPolicy("read", policy => policy.RequireScope("dms.read"));
7575
options.AddPolicy("write", policy => policy.RequireScope("dms.write"));
76+
77+
options.AddPolicy("visualisation-read", policy =>
78+
policy.RequireAuthenticatedUser()
79+
.RequireScope("visualiser.read")
80+
.AddAuthenticationSchemes(JwtBearerDefaults.AuthenticationScheme));
81+
82+
options.AddPolicy("visualisation-write", policy =>
83+
policy.RequireAuthenticatedUser()
84+
.RequireScope("visualiser.write")
85+
.AddAuthenticationSchemes(JwtBearerDefaults.AuthenticationScheme));
86+
7687
options.FallbackPolicy = options.DefaultPolicy;
7788
});
7889

src/Visualiser/appsettings.Development.json

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -11,8 +11,8 @@
1111
},
1212
"API": {
1313
"Scopes": [
14-
"api://916ace49-a3db-4b11-84c5-6c4bd20260ef/dms.read",
15-
"api://916ace49-a3db-4b11-84c5-6c4bd20260ef/dms.write"
14+
"api://916ace49-a3db-4b11-84c5-6c4bd20260ef/visualiser.read",
15+
"api://916ace49-a3db-4b11-84c5-6c4bd20260ef/visualiser.write"
1616
]
1717
}
1818
}

src/Visualiser/appsettings.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -17,7 +17,7 @@ For more info see https://aka.ms/dotnet-template-ms-identity-platform
1717
"API": {
1818
"BaseUrl": "https://localhost:7013",
1919
"Scopes": [
20-
// E.g. "api://{api_client_id}/dms.read" and "api://{api_client_id}/dms.write"
20+
// E.g. "api://{api_client_id}/visualiser.read" and "api://{api_client_id}/visualiser.write"
2121
]
2222
},
2323
"Serilog": {

0 commit comments

Comments
 (0)