* Rename Umbraco.Core namespace to Umbraco.Cms.Core * Move extension methods in core project to Umbraco.Extensions * Move extension methods in core project to Umbraco.Extensions * Rename Umbraco.Examine namespace to Umbraco.Cms.Examine * Move examine extensions to Umbraco.Extensions namespace * Reflect changed namespaces in Builder and fix unit tests * Adjust namespace in Umbraco.ModelsBuilder.Embedded * Adjust namespace in Umbraco.Persistence.SqlCe * Adjust namespace in Umbraco.PublishedCache.NuCache * Align namespaces in Umbraco.Web.BackOffice * Align namespaces in Umbraco.Web.Common * Ensure that SqlCeSupport is still enabled after changing the namespace * Align namespaces in Umbraco.Web.Website * Align namespaces in Umbraco.Web.UI.NetCore * Align namespaces in Umbraco.Tests.Common * Align namespaces in Umbraco.Tests.UnitTests * Align namespaces in Umbraco.Tests.Integration * Fix errors caused by changed namespaces * Fix integration tests * Undo the Umbraco.Examine.Lucene namespace change This breaks integration tests on linux, since the namespace wont exists there because it's only used on windows. * Fix merge * Fix Merge
39 lines
1.5 KiB
C#
39 lines
1.5 KiB
C#
// Copyright (c) Umbraco.
|
|
// See LICENSE for more details.
|
|
|
|
using System.Linq;
|
|
using System.Threading.Tasks;
|
|
using Microsoft.AspNetCore.Authorization;
|
|
using Umbraco.Cms.Core.Security;
|
|
|
|
namespace Umbraco.Cms.Web.BackOffice.Authorization
|
|
{
|
|
/// <summary>
|
|
/// Ensures that the current user has access to the section
|
|
/// </summary>
|
|
/// <remarks>
|
|
/// The user only needs access to one of the sections specified, not all of the sections.
|
|
/// </remarks>
|
|
public class SectionHandler : MustSatisfyRequirementAuthorizationHandler<SectionRequirement>
|
|
{
|
|
private readonly IBackOfficeSecurityAccessor _backOfficeSecurityAccessor;
|
|
|
|
/// <summary>
|
|
/// Initializes a new instance of the <see cref="SectionHandler"/> class.
|
|
/// </summary>
|
|
/// <param name="backOfficeSecurityAccessor">Accessor for back-office security.</param>
|
|
public SectionHandler(IBackOfficeSecurityAccessor backOfficeSecurityAccessor) => _backOfficeSecurityAccessor = backOfficeSecurityAccessor;
|
|
|
|
/// <inheritdoc/>
|
|
protected override Task<bool> IsAuthorized(AuthorizationHandlerContext context, SectionRequirement requirement)
|
|
{
|
|
var authorized = _backOfficeSecurityAccessor.BackOfficeSecurity.CurrentUser != null &&
|
|
requirement.SectionAliases
|
|
.Any(app => _backOfficeSecurityAccessor.BackOfficeSecurity.UserHasSectionAccess(
|
|
app, _backOfficeSecurityAccessor.BackOfficeSecurity.CurrentUser));
|
|
|
|
return Task.FromResult(authorized);
|
|
}
|
|
}
|
|
}
|