IdentityServer4 和 Asp.Net Core Identity 管理
The administration for the IdentityServer4 and Asp.Net Core Identity
I just want to say a huge THANK YOU to everyone who has contributed to IdentityServer4.Admin over the years. Reaching almost 4,000 stars ⭐️ on GitHub has been such an incredible milestone, and it is all thanks to this amazing community. I truly could not have done it without you.
With the end of support for .NET 6 and IdentityServer4, I have made the decision to stop maintaining this repository.
I am excited to introduce my new project: Duende IdentityServer Admin.
This is the next evolution of this project and is fully supported. I would love for you to check it out and join me on this journey.
Thanks again for everything—your contributions, feedback, and support have meant so much to me. I hope to see you over on the new project!
If you need any assistance migrating to Duende IdentityServer, feel free to reach out:
Looking forward to seeing you in the new repository.
Cheers,
Jan Skoruba ❤️
dotnet new -i Skoruba.IdentityServer4.Admin.Templates::2.1.0
dotnet new skoruba.is4admin --name MyProject --title MyProject --adminemail "[email protected]" --adminpassword "Pa$$word123" --adminrole MyRole --adminclientid MyClientId --adminclientsecret MyClientSecret --dockersupport true
Project template options:
--name: [string value] for project name
--adminpassword: [string value] admin password
--adminemail: [string value] admin email
--title: [string value] for title and footer of the administration in UI
--adminrole: [string value] for name of admin role, that is used to authorize the administration
--adminclientid: [string value] for client name, that is used in the IdentityServer4 configuration for admin client
--adminclientsecret: [string value] for client secret, that is used in the IdentityServer4 configuration for admin client
--dockersupport: [boolean value] include docker support
git clone https://github.com/skoruba/IdentityServer4.Admin
We need some resolving capabilities in order for the project to work. The domain skoruba.local is used here to represent the domain this setup is hosted on. The domain-name needs to be FQDN (fully qualified domain name).
Thus first, we need the domain skoruba.local to resolve to the docker-host machine. If you want this to work on your local machine only, use the first option.
Edit your hosts file:
\etc\hostsC:\Windows\system32\drivers\etc\hostsand add the following entries:
127.0.0.1 skoruba.local sts.skoruba.local admin.skoruba.local admin-api.skoruba.local
This way your host machine resolves skoruba.local and its subdomains to itself.
We also need certificates in order to serve on HTTPS. We'll make our own self-signed certificates with mkcert.
If the domain is publicly available through DNS, you can use Let's Encypt. Nginx-proxy has support for that, which is left out in this setup.
Use mkcert to generate local self-signed certificates.
On windows mkcert -install must be executed under elevated Administrator privileges. Then copy over the CA Root certificate over to the project as we want to mount this in later into the containers without using an environment variable.
cd shared/nginx/certs
mkcert --install
copy $env:LOCALAPPDATA\mkcert\rootCA.pem ./cacerts.pem
copy $env:LOCALAPPDATA\mkcert\rootCA.pem ./cacerts.crt
Create the skoruba.local certificates
Generate a certificate for skoruba.local with wildcards for the subdomains. The name of the certificate files need to match with actual domain-names in order for the nginx-proxy to pick them up correctly. We want both the crt-key and the pfx version.
cd shared/nginx/certs
mkcert -cert-file skoruba.local.crt -key-file skoruba.local.key skoruba.local *.skoruba.local
mkcert -pkcs12 skoruba.local.pfx skoruba.local *.skoruba.local
This docker setup is come from this repository - thanks to bravecobra.
docker-compose.vs.debug.yml and docker-compose.override.yml to enable debugging with a seeded environment.docker-compose build
docker-compose up -d
It is also possible to set as startup project the project called
docker-composein Visual Studio.
build/publish-docker-images.ps1 - change the profile name according to your requirements.cd src/Skoruba.IdentityServer4.Admin
npm install
cd src/Skoruba.IdentityServer4.STS.Identity
npm install
The following Gulp commands are available:
gulp fonts - copy fonts to the dist foldergulp styles - minify CSS, compile SASS to CSSgulp scripts - bundle and minify JSgulp clean - remove the dist foldergulp build - run the styles and scripts tasksgulp watch - watch all changes in all sass filesThe solution uses these DbContexts:
AdminIdentityDbContext: for Asp.Net Core IdentityAdminLogDbContext: for loggingIdentityServerConfigurationDbContext: for IdentityServer configuration storeIdentityServerPersistedGrantDbContext: for IdentityServer operational storeAdminAuditLogDbContext: for Audit LoggingIdentityServerDataProtectionDbContext: for dataprotectionNOTE: Initial migrations are a part of the repository.
It is possible to use powershell script in folder build/add-migrations.ps1.
This script take two arguments:
For example:
.\add-migrations.ps1 -migration DbInit -migrationProviderName SqlServer
It is possible to switch the database provider via
appsettings.json:
"DatabaseProviderConfiguration": {
"ProviderType": "SqlServer"
}
PostgreSQL:
Server=localhost;Port=5432;Database=IdentityServer4Admin;User Id=sa;Password=#;
MySql:
server=localhost;database=IdentityServer4Admin;user=root;password=#
Program.cs -> Main, uncomment DbMigrationHelpers.EnsureSeedData(host) or use dotnet CLI dotnet run /seed or via SeedConfiguration in appsettings.jsonClients and Resources files in identityserverdata.json (section called: IdentityServerData) - are the initial data, based on a sample from IdentityServer4Users file in identitydata.json (section called: IdentityData) contains the default admin username and password for the first loginappsettings.jsonAuthorizationConsts.AdministrationPolicy. In the policy - AuthorizationConsts.AdministrationPolicy is defined required role stored in - appsettings.json - AdministrationRole.appsettings.json with following configuration:"AzureKeyVaultConfiguration": {
"AzureKeyVaultEndpoint": "",
"ClientId": "",
"ClientSecret": "",
"UseClientCredentials": true
}
If your application is running in Azure App Service, you can specify AzureKeyVaultEndpoint. For applications which are running outside of Azure environment it is possible to use the client credentials flow - so it is necesarry to go to Azure portal, register new application and connect this application to Azure Key Vault and setup the client secret.
"AzureKeyVaultConfiguration": {
"ReadConfigurationFromKeyVault": true
}
Enable Azure Key Vault for dataprotection with following configuration:
"DataProtectionConfiguration": {
"ProtectKeysWithAzureKeyVault": false
}
The you need specify the key identifier in configuration:
"AzureKeyVaultConfiguration": {
"DataProtectionKeyIdentifier": ""
}
"AzureKeyVaultConfiguration": {
"IdentityServerCertificateName": ""
}
We are using Serilog with pre-definded following Sinks - white are available in serilog.json:
…
token return userid
Prevent users from creating an account with invalid email
Unsafe-eval CSP - Picker Broken
Secrets are no more showed on the UI
SqlException: Cannot open database - InvalidOperationException - CryptographicException
Skoruba with oracle
Why are the cookies returned so large?
ViewEngineResult.EnsureSuccessful : An unhandled exception occurred while processing the request
.NET 8?
Login as user feature