shoc-backend/SeaHavenIndustries/Program.cs
Alexandre Brandizzi 66a49ab957 feat(auth): enforce one password policy on every password-setting path (SH-386)
Both hosts now apply the same Identity password rule: at least 6 characters
with one uppercase letter, one number and one special character. Change
password requires an authenticated caller, verifies the current password
before evaluating the new one, and reports a policy rejection separately
from a wrong current password.
2026-09-25 11:06:42 -03:00

114 lines
4.3 KiB
C#

using Amazon.Extensions.NETCore.Setup;
using Amazon.S3;
using Data.SeaHavenIndustries;
using Microsoft.AspNetCore.Builder;
using Microsoft.AspNetCore.Components.Authorization;
using Microsoft.AspNetCore.Identity;
using Microsoft.EntityFrameworkCore;
using SeaHavenIndustries;
using SeaHavenIndustries.Components;
using SeaHavenIndustries.Components.Account;
using SeaHavenIndustries.Data.IRepository;
using SeaHavenIndustries.Data.Services;
using SeaHavenIndustries.Helper;
var builder = WebApplication.CreateBuilder(args);
// Add services to the container.
builder.Services.AddRazorComponents()
.AddInteractiveServerComponents();
builder.Services.AddCascadingAuthenticationState();
builder.Services.AddScoped<IdentityUserAccessor>();
builder.Services.AddScoped<IdentityRedirectManager>();
builder.Services.AddScoped<AuthenticationStateProvider, IdentityRevalidatingAuthenticationStateProvider>();
builder.Services.AddAuthentication(options =>
{
options.DefaultScheme = IdentityConstants.ApplicationScheme;
options.DefaultSignInScheme = IdentityConstants.ExternalScheme;
})
.AddIdentityCookies();
var connectionString = builder.Configuration.GetConnectionString("DefaultConnection") ?? throw new InvalidOperationException("Connection string 'DefaultConnection' not found.");
builder.Services.AddDbContext<ApplicationDbContext>(options =>
{
options.UseSqlServer(connectionString);
}, ServiceLifetime.Transient);
builder.Services.AddDatabaseDeveloperPageExceptionFilter();
builder.Services.AddIdentityCore<ApplicationUser>(options =>
{
options.SignIn.RequireConfirmedAccount = true;
IdentityPasswordPolicy.Apply(options.Password);
}).AddRoles<IdentityRole>().AddEntityFrameworkStores<ApplicationDbContext>().AddSignInManager()
.AddDefaultTokenProviders();
builder.Services.AddRazorPages();
builder.Services.AddHttpClient();
builder.Services.AddServerSideBlazor(options =>
{
options.DetailedErrors = true;
options.DisconnectedCircuitMaxRetained = 100;
options.DisconnectedCircuitRetentionPeriod = TimeSpan.FromMinutes(3);
options.JSInteropDefaultCallTimeout = TimeSpan.FromMinutes(1);
options.MaxBufferedUnacknowledgedRenderBatches = 10;
});
builder.Services.AddDefaultAWSOptions(new AWSOptions
{
Region = Amazon.RegionEndpoint.USEast2 // This is the enum value for US East (Ohio) us-east-2
});
builder.Services.AddAWSService<IAmazonS3>();
builder.Services.AddSingleton<IEmailSender<ApplicationUser>, IdentityNoOpEmailSender>();
builder.Services.AddTransient<IAccountRepository, AccountService>();
builder.Services.AddTransient<IContactRepository, ContactService>();
builder.Services.AddTransient<ISettingsRepository, SettingsService>();
builder.Services.AddTransient<IWorkOrderRepository, WorkorderService>();
builder.Services.AddTransient<IQuotesRepository, QuotesService>();
builder.Services.AddTransient<IUserWorkorderRepository, UserWorkorderService>();
builder.Services.AddScoped<ChangeStepService>();
builder.Services.AddScoped<UploadFileHp>();
builder.Services.AddScoped<NorthwindService>();
builder.Services.AddScoped<SendMessage>();
builder.Services.AddScoped<PdfService>();
builder.Services.Configure<SeaHavenIndustries.Options.BlazorWorkOrderSunsetOptions>(
builder.Configuration.GetSection(SeaHavenIndustries.Options.BlazorWorkOrderSunsetOptions.SectionName));
builder.Services.AddSingleton<BlazorWorkOrderSunsetGuard>();
builder.Services.AddSession(options =>
{
options.IdleTimeout = TimeSpan.FromDays(1); // Session will expire if there is no activity for 1 minute
options.Cookie.HttpOnly = true;
options.Cookie.IsEssential = true;
options.IOTimeout = TimeSpan.FromMinutes(1);
});
var app = builder.Build();
// Configure the HTTP request pipeline.
if (app.Environment.IsDevelopment())
{
app.UseMigrationsEndPoint();
}
else
{
app.UseExceptionHandler("/Error", createScopeForErrors: true);
// The default HSTS value is 30 days. You may want to change this for production scenarios, see https://aka.ms/aspnetcore-hsts.
app.UseHsts();
}
app.UseHttpsRedirection();
app.UseStaticFiles();
app.UseAuthentication();
app.UseAuthorization();
app.UseAntiforgery();
app.MapRazorComponents<App>()
.AddInteractiveServerRenderMode();
// Add additional endpoints required by the Identity /Account Razor components.
app.MapAdditionalIdentityEndpoints();
app.Run();