-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathProgram.cs
More file actions
99 lines (87 loc) · 3.14 KB
/
Copy pathProgram.cs
File metadata and controls
99 lines (87 loc) · 3.14 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
using System.Text;
using Bastion.Data;
using Bastion.Interfaces;
using Bastion.Models;
using Bastion.Services;
using MaxMind.GeoIP2;
using Microsoft.AspNetCore.Authentication.JwtBearer;
using Microsoft.EntityFrameworkCore;
using Microsoft.IdentityModel.Tokens;
using Serilog;
Log.Logger = new LoggerConfiguration()
.WriteTo.Console()
.WriteTo.File("logs/bastion_.log", rollingInterval: RollingInterval.Day)
.CreateLogger();
try
{
var builder = WebApplication.CreateBuilder(args);
builder.Host.UseSerilog();
var jwtKey = builder.Configuration["Jwt:Key"] ?? "SuperSecretKeyForBastion2024!DefaultKey";
builder.Services.AddAuthentication(JwtBearerDefaults.AuthenticationScheme)
.AddJwtBearer(options =>
{
options.TokenValidationParameters = new TokenValidationParameters
{
ValidateIssuer = true,
ValidateAudience = true,
ValidateLifetime = true,
ValidateIssuerSigningKey = true,
ValidIssuer = "Bastion",
ValidAudience = "Bastion",
IssuerSigningKey = new SymmetricSecurityKey(Encoding.UTF8.GetBytes(jwtKey))
};
});
builder.Services.AddAuthorization();
// SQL Server DbContext
builder.Services.AddDbContext<AppDbContext>(options =>
options.UseSqlServer(builder.Configuration.GetConnectionString("DefaultConnection")));
// Repositories using SQL
builder.Services.AddScoped<IRepository<User>, SqlRepository<User>>();
builder.Services.AddScoped<IRepository<LoginAttempt>, SqlRepository<LoginAttempt>>();
builder.Services.AddScoped<IAuthService, AuthService>();
// Register MaxMind GeoIP2 reader
var mmdbPath = Path.Combine(builder.Environment.ContentRootPath, "Data", "GeoLite2-City.mmdb");
if (File.Exists(mmdbPath))
{
builder.Services.AddSingleton(new DatabaseReader(mmdbPath));
Log.Information("GeoIP2 database loaded from {Path}", mmdbPath);
}
else
{
Log.Warning("GeoLite2-City.mmdb not found at {Path}. GeoIP lookups disabled.", mmdbPath);
}
builder.Services.AddControllers();
var app = builder.Build();
// Phase 7: Seed canary administrator account
using (var scope = app.Services.CreateScope())
{
var userRepo = scope.ServiceProvider.GetRequiredService<IRepository<User>>();
var admin = await userRepo.GetByUsername("administrator");
if (admin == null)
{
var canary = new User
{
Username = "administrator",
PasswordHash = BCrypt.Net.BCrypt.HashPassword(Guid.NewGuid().ToString()),
Role = "Admin",
CreatedAt = DateTime.UtcNow
};
await userRepo.Add(canary);
Log.Information("Canary administrator account seeded.");
}
}
app.UseStaticFiles();
app.UseAuthentication();
app.UseAuthorization();
app.MapControllers();
app.MapGet("/", () => "Bastion Security API is running.");
app.Run();
}
catch (Exception ex)
{
Log.Fatal(ex, "Application terminated unexpectedly");
}
finally
{
Log.CloseAndFlush();
}