-
Notifications
You must be signed in to change notification settings - Fork 0
/
Program.cs
80 lines (64 loc) · 3.14 KB
/
Program.cs
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
using System.Security.Cryptography;
using System.Text.Json;
namespace MossPlatform
{
public class Program
{
public static async Task Main(string[] args)
{
var builder = WebApplication.CreateBuilder(args);
// Add services to the container.
builder.Services.AddRazorPages();
builder.Services.AddScoped<GameDataService>();
builder.Services.AddScoped<ImageService>();
// Register session services before building the app
builder.Services.AddSession(options =>
{
// You can set session options here if needed
options.IdleTimeout = TimeSpan.FromMinutes(30); // for example
options.Cookie.HttpOnly = true;
options.Cookie.IsEssential = true;
});
// Build the app
var app = builder.Build();
// Use session middleware after building the app
app.UseSession();
// Initialize admin credentials if they don't exist
await EnsureAdminCredentials(app.Environment.ContentRootPath);
// Configure the HTTP request pipeline.
if (!app.Environment.IsDevelopment())
{
app.UseExceptionHandler("/Error");
// The default HSTS value is 30 days. You may want to change this for production scenarios, see https://aka.ms/aspnetcore-hsts.
app.UseHsts();
}
app.UseHttpsRedirection();
app.UseStaticFiles();
app.UseRouting();
// Authentication and Authorization middleware would be here
// Since you're not using ASP.NET Core Identity, you would handle auth in your custom code
app.MapRazorPages();
app.MapControllerRoute(
name: "default",
pattern: "{controller=Home}/{action=Index}/{id?}");
app.Run();
}
private static async Task EnsureAdminCredentials(string contentRootPath)
{
string adminCredentialsPath = Path.Combine(contentRootPath, "admin_credentials.json");
if (!File.Exists(adminCredentialsPath))
{
// You should change this to your desired default username and a secure password
string defaultUsername = "admin";
string defaultPassword = "securepassword"; // TODO: Use a more secure password!
// Hash the default password (you should use a proper hashing algorithm like BCrypt)
using var sha256 = SHA256.Create();
var hashedPasswordBytes = sha256.ComputeHash(System.Text.Encoding.UTF8.GetBytes(defaultPassword));
string hashedPassword = BitConverter.ToString(hashedPasswordBytes).Replace("-", "").ToLowerInvariant();
var adminCredentials = new { Username = defaultUsername, PasswordHash = hashedPassword };
string json = JsonSerializer.Serialize(adminCredentials, new JsonSerializerOptions { WriteIndented = true });
await File.WriteAllTextAsync(adminCredentialsPath, json);
}
}
}
}