【问题标题】:Security for two websites talking to each other两个相互通信的网站的安全性
【发布时间】:2017-05-28 05:38:08
【问题描述】:

我有两个网站(一个是新的 MVC 应用程序,另一个是旧的 WebForms 应用程序)。我需要他们能够相互交流。

我正在考虑在两个站点上实现一个 RESTful Web API,然后让每个站点调用另一个站点的 Web API。

到目前为止,一切都很好,但是身份验证呢?我在看Authentication Filters。对于 MVC 应用程序来说,它们似乎是一种合理的方法,但看起来它们在 WebForms 上可能不受支持。

我的问题是,由于唯一会调用这些 API 的实体是另一个网站,有没有办法简化这个过程?例如,我是否可以只拥有一个秘密 GUID 并传递它,如果其他站点获得正确的 GUID,那么我认为它没问题?

请注意,我将使用 HTTPS。另外,我们不是银行。安全性只需要合理,仅此而已。

【问题讨论】:

  • 查看两个站点之间通过 https 的 JWT(Json Web Token)。应该足够简单以在两者之间实现。

标签: asp.net rest authentication asp.net-web-api


【解决方案1】:

您可以为客户端设置一个简单的用户 ID/密码,并将其与 Authorization 标头上的每个请求一起传递。然后,创建一个自定义 AuthorizationFilterAttribute 来验证凭据。

类似的东西。

public class MyAuthorizeAttribute : AuthorizationFilterAttribute
{   
        public ICustomerAuthenticator CustomerAuthenticator { get; set; }
        
        public override void OnAuthorization(HttpActionContext actionContext)
        {   
            var authInfo = $"{actionContext.Request.Headers.Authorization.Parameter}";

            var authenticationResult = CustomerAuthenticator.Authenticate(new []{ authInfo });

            if (!authenticationResult.Authenticated)
            {
                
                actionContext.Response = new HttpResponseMessage(HttpStatusCode.Unauthorized)
                {   
                    Content = new StringContent("You are not authorized.")
                };
            }
            else
            {
                actionContext.RequestContext.Principal = new GenericPrincipal(new ClaimsIdentity(new List<Claim>
                {
                    new Claim("CustomerId", authenticationResult.Customer.Id.ToString()),
                    new Claim("CustomerName", authenticationResult.Customer.Name)
                }));
            }
        }
}

希望这会有所帮助。

【讨论】:

    猜你喜欢
    • 1970-01-01
    • 2019-10-03
    • 1970-01-01
    • 1970-01-01
    • 1970-01-01
    • 1970-01-01
    • 1970-01-01
    • 2013-11-19
    • 1970-01-01
    相关资源
    最近更新 更多