【问题标题】:WCF Custom AuthorizationWCF 自定义授权
【发布时间】:2015-01-30 11:05:07
【问题描述】:

基本上,我正在创建我的第一个 WCF Web 服务,并希望实现自定义身份验证和授权。身份验证似乎运行良好,但我也希望能够使用自定义授权来存储角色和权限。

我的身份验证是通过覆盖UserNamePasswordValidator 并使用Validate 方法完成的。

Validate(string UserName, string password)

现在我尝试使用IAuthorizationPolicy 接口实现授权

public class AuthorizationPolicy : IAuthorizationPolicy
{
    private string _id;

    public string Id
    {
        get { return this._id; }
    }

    public ClaimSet Issuer
    {
        get { return ClaimSet.System; }
    }

    public AuthorizationPolicy()
    {
        _id = Guid.NewGuid().ToString();
    }

    public bool Evaluate(EvaluationContext context, ref object state)
    {
        IIdentity client = GetClientIdentity(context);
        context.Properties["Principal"] = new CustomPrincipal(client);

        return true;
    }

    private IIdentity GetClientIdentity(EvaluationContext evaluationContext)
    {
        object obj;
        if (!evaluationContext.Properties.TryGetValue("Identities", out obj))
            throw new Exception("No Identity found");

        IList<IIdentity> identities = obj as IList<IIdentity>;
        if (identities == null || identities.Count <= 0)
            throw new Exception("No Identity found");

        return identities[0];
    }
}

我还使用IPrincipal 接口实现了CustomPrincipal。

public class CustomPrincipal : IPrincipal
{
    IIdentity _identity;
    string[] _roles;

    public CustomPrincipal(IIdentity identity)
    {
        _identity = identity;
    }

    public static CustomPrincipal Current
    {
        get
        {
            return Thread.CurrentPrincipal as CustomPrincipal;
        }
    }

    public IIdentity Identity
    {
        get { return _identity; }
    }

    public string[] Roles
    {
        get
        {
            if (_roles == null)
            {
                EnsureRoles();
            }

            return _roles;
        }
    }

    public bool IsInRole(string role)
    {
        EnsureRoles();

        return _roles.Contains(role);
    }

    protected virtual void EnsureRoles()
    {
        UserManager userManager = new UserManager();
        int userPermissions = userManager.UserPermissions(_identity.Name);

        if (userPermissions == 1)
            _roles = new string[1] { "ADMIN" };
        else
            _roles = new string[1] { "USER" };
    }
}

我的 App.Config 已按要求更新,AuthorizationPolicy 中的 Evaluate 方法按预期调用。

但是,这就是我卡住的地方。如何从这里开始实施角色和权限?

【问题讨论】:

    标签: c# wcf authorization


    【解决方案1】:

    您可以参考Authentication and Authorization with ASP.NET Identity 2.0 for WCF Services

    根据本文,您基本上需要考虑 3 个级别:

    1. System.IdentityModel 和 System.Security.Principal

    2. 如果您想使用与 MVC 应用程序共享的开箱即用上下文,请使用 Asp.net Identity 2.0;或者您使用自定义数据库。

    3. 如果您想要对安全策略进行细粒度控制的策略

    【讨论】:

      【解决方案2】:

      我建议您选择Message Inspector。

      逻辑如下:

      1. 客户端将有一个消息检查器,它将为每个请求设置所需的标头。
      2. 服务器端消息检查器将拦截请求,然后读取标头并进行身份验证和授权。
      3. 您可以拥有一些服务,例如用户和角色服务,可以在服务器中调用这些服务来验证标头中的凭据并为该请求设置身份。
      4. 这些服务将通过 DAL 访问商店,并将处于 inproc 模式。

      【讨论】:

        猜你喜欢
        • 2013-03-17
        • 2011-09-18
        • 1970-01-01
        • 1970-01-01
        • 1970-01-01
        • 1970-01-01
        • 1970-01-01
        • 1970-01-01
        • 2013-10-31
        相关资源
        最近更新 更多