Repository navigation
Authentication and Authorization
ma496 edited this page May 18, 2025
·
2 revisions
The system implements a dual authentication mechanism using both JWT tokens and cookies, with a role-based permission system.
- Send a POST request to
{{apiUrl}}/account/tokenwith the following payload:
{
"username": "admin",
"password": "Admin#123"
}- If the credentials are valid, the server will respond with a JWT token and a refresh token in the response body.
{
"accessToken": "<JWT Token>",
"refreshToken": "<Refresh Token>",
"userId": "<User ID>",
}-
Store the
accessTokenandrefreshTokenin your application's local storage or session storage. -
Include the
accessTokenin theAuthorizationheader of all subsequent API requests:
Authorization: Bearer <JWT Token>
- If the
accessTokenis expired, send a POST request to{{apiUrl}}/account/refresh-tokenwith the following payload:
{
"refreshToken": "<Refresh Token>",
"userId": "<User ID>"
}- If the refresh token is valid, the server will respond with a new
accessTokenand a newrefreshTokenin the response body.
{
"accessToken": "<New JWT Token>",
"refreshToken": "<New Refresh Token>",
"userId": "<User ID>"
}-
Update the
accessTokenandrefreshTokenin your application's local storage or session storage. -
Include the new
accessTokenin theAuthorizationheader of all subsequent API requests:
Authorization: Bearer <New JWT Token>
- Change the
AccessTokenValidityandRefreshTokenValidityin theappsettings.json,appsettings.Development.json, andappsettings.Testing.jsonfiles. default value is 60 minutes forAccessTokenValidityand 168 hours forRefreshTokenValidity.
"AccessTokenValidity": "60", // in minutes
"RefreshTokenValidity": "168" // in hours, 168 hours = 7 daysThe system uses a permission-based access control (PBAC) system to manage user permissions. For example, you want to add permission for product list endpoint, you need to add the following permission in Allow and PermissionDefinitionProvider classes.
- Add the following permission in the Allow class:
public static class Allow
{
public const string Product_View = "Product.View";
}- Add the following permission in the PermissionDefinitionProvider.cs file:
public class PermissionDefinitionProvider : DefaultPermissionDefinitionProvider
{
public override void Define(IPermissionDefinitionContext context)
{
var productsPermissions = context.AddPermission("Products", "Products");
productsPermissions.AddChild(Allow.Product_View, "View");
}
}- How to use the permission in the endpoint, for example, you want to add the permission for the product list endpoint, you need to add the following code in the endpoint configure method:
public override void Configure()
{
Permissions(Allow.Product_View);
}