| | | 1 | | using Elsa.Common.Multitenancy; |
| | | 2 | | using Elsa.Extensions; |
| | | 3 | | using Elsa.Workflows.Api.RealTime.Contracts; |
| | | 4 | | using Elsa.Workflows.Management; |
| | | 5 | | using Elsa.Workflows.Management.Entities; |
| | | 6 | | using Elsa.Workflows.Management.Filters; |
| | | 7 | | using FastEndpoints.Security; |
| | | 8 | | using JetBrains.Annotations; |
| | | 9 | | using Microsoft.AspNetCore.Authorization; |
| | | 10 | | using Microsoft.AspNetCore.SignalR; |
| | | 11 | | |
| | | 12 | | namespace Elsa.Workflows.Api.RealTime.Hubs; |
| | | 13 | | |
| | | 14 | | /// <summary> |
| | | 15 | | /// Represents a SignalR hub for receiving workflow events on the client. |
| | | 16 | | /// </summary> |
| | | 17 | | [PublicAPI] |
| | | 18 | | [Authorize] |
| | | 19 | | public class WorkflowInstanceHub : Hub<IWorkflowInstanceClient> |
| | | 20 | | { |
| | | 21 | | private const string ReadWorkflowInstancesPermission = "read:workflow-instances"; |
| | | 22 | | private const string ReadAllPermission = "read:*"; |
| | 1 | 23 | | private static readonly string[] ReadPermissions = [PermissionNames.All, ReadAllPermission, ReadWorkflowInstancesPer |
| | | 24 | | private readonly IWorkflowInstanceStore _workflowInstanceStore; |
| | | 25 | | private readonly ITenantAccessor? _tenantAccessor; |
| | | 26 | | |
| | | 27 | | /// <inheritdoc /> |
| | 11 | 28 | | public WorkflowInstanceHub(IWorkflowInstanceStore workflowInstanceStore, ITenantAccessor? tenantAccessor = null) |
| | | 29 | | { |
| | 11 | 30 | | _workflowInstanceStore = workflowInstanceStore; |
| | 11 | 31 | | _tenantAccessor = tenantAccessor; |
| | 11 | 32 | | } |
| | | 33 | | |
| | | 34 | | /// <summary> |
| | | 35 | | /// Observes a workflow instance. |
| | | 36 | | /// </summary> |
| | | 37 | | /// <param name="instanceId">The ID of the workflow instance to observe.</param> |
| | | 38 | | public async Task ObserveInstanceAsync(string instanceId) |
| | | 39 | | { |
| | 10 | 40 | | if (!CanReadWorkflowInstances()) |
| | 1 | 41 | | throw new HubException("Access denied."); |
| | | 42 | | |
| | 9 | 43 | | var workflowInstance = await _workflowInstanceStore.FindAsync(new WorkflowInstanceFilter { Id = instanceId }, Co |
| | | 44 | | |
| | 9 | 45 | | if (!CanAccessTenant(workflowInstance, _tenantAccessor)) |
| | 2 | 46 | | throw new HubException("Access denied."); |
| | | 47 | | |
| | | 48 | | // Join the user to the workflow instance group. |
| | 7 | 49 | | await Groups.AddToGroupAsync(Context.ConnectionId, instanceId, Context.ConnectionAborted); |
| | 7 | 50 | | } |
| | | 51 | | |
| | | 52 | | private bool CanReadWorkflowInstances() |
| | | 53 | | { |
| | 10 | 54 | | var user = Context.User; |
| | | 55 | | |
| | 10 | 56 | | if (user?.Identity?.IsAuthenticated != true) |
| | 0 | 57 | | return false; |
| | | 58 | | |
| | 10 | 59 | | return ReadPermissions.Any(user.HasPermission); |
| | | 60 | | } |
| | | 61 | | |
| | | 62 | | private static bool CanAccessTenant(WorkflowInstance? workflowInstance, ITenantAccessor? tenantAccessor) |
| | | 63 | | { |
| | 9 | 64 | | if (workflowInstance == null) |
| | 1 | 65 | | return false; |
| | | 66 | | |
| | 8 | 67 | | if (tenantAccessor == null) |
| | 1 | 68 | | return true; |
| | | 69 | | |
| | 7 | 70 | | var workflowInstanceTenantId = workflowInstance.TenantId.NormalizeTenantId(); |
| | 7 | 71 | | var currentTenantId = tenantAccessor.TenantId.NormalizeTenantId(); |
| | | 72 | | |
| | 7 | 73 | | return workflowInstanceTenantId == Tenant.AgnosticTenantId || workflowInstanceTenantId == currentTenantId; |
| | | 74 | | } |
| | | 75 | | } |