链接到 Tableau 的How Trusted Authentication Works
关于我如何实施可信身份验证的高级视图
1) Tableau Server 必须有一个 wgserver.trusted_hosts 文件的条目,其中包含您的 Web 应用程序的主机名,才能使上述任何一项工作。
2) 传递三个重要参数:
username 212456449
server http://[server]
target_site YourTargetSiteName
3) 如果 HTTP POST 请求有效且用户拥有正确的 Tableau 许可证,Tableau 会创建一个 48 个唯一字符的票证,该票证仅在 3 分钟内有效。
4) 在 Tableau 兑换之前,我以编程方式将 48 个唯一字符票证添加到嵌入式 JavaScript 中。
代码在我的网络应用程序中的工作原理
我创建了一个包含两个方法的 TrustedAuth 类:requestTicket() 和 addTicket()。 requestTicket() 是一种异步方法,它采用三个必需参数(sso、服务器、站点)。 HTTP POST 被触发并等待响应。如果 Tableau 响应为 -1 ,则 HTTP 握手失败或用户无效。如果有效,响应将是一个 48 个字符的加密字符串。
addTicket() 是一种同步方法,它采用两个参数(ticket、reportLink)。此方法采用 48 个字符的加密票据并将其附加到嵌入式 JavaScript (reportLink)。
Web 应用程序向 Tableau 发送一个 HTTP GET 请求,其中包括带有加密票证的嵌入式 JavaScript (reportLink)。 Tableau Server 兑换票证,创建会话,将用户登录,未显示登录提示
TrustedAuth 类
public class TrustedAuth
{
public async Task<string> requestTicket(int sso, string server, string site)
{
try
{
//Assign parameters and values
var values = new List<KeyValuePair<string, string>>();
values.Add(new KeyValuePair<string, string>("username", sso.ToString()));
values.Add(new KeyValuePair<string, string>("target_site", site));
//Web Application is HTTP and Tableau is HTTPS, there are certification issues. I need to fake the certs out and return them as true.
System.Net.ServicePointManager.ServerCertificateValidationCallback = (senderX, certificate, chain, sslPolicyErrors) => { return true; };
//Instantiate HttpClient class
var client = new HttpClient();
//Encode Content
var req = new HttpRequestMessage(HttpMethod.Post, server) { Content = new FormUrlEncodedContent(values) };
//POST request
var res = await client.SendAsync(req);
//Get response value
var responseString = await res.Content.ReadAsStringAsync();
return responseString;
}
catch (Exception e)
{
System.IO.File.AppendAllText(@"c:\inetpub\wwwroot\WebApplication\TrustedAuthError.txt", ":::ERROR::: " + System.DateTime.Today.ToString() + ":::" + e.ToString() + Environment.NewLine);
//Add Log4Net logging
}
return "-1";
}
public string addTicket(string ticket, string reportLink)
{
//Add ticket parameter with ticket value. I'm using </object> as my keyword to find and replace
string addedTicket = reportLink.Replace("</object>", "<param name='ticket' value='" + ticket + "' /></object>");
return addedTicket;
}
}
仪表板控制器
public async Task<ActionResult> Dashboard(int Report_Num)
{
//db will be your database model where your Report_Link is stored
Report_Completion_Status_NEW report_Completion_Status = db.Report_Completion_Status_NEW.Find(Report_Num);
if (report_Completion_Status == null)
{
return HttpNotFound();
}
var ticket = "";
//Get Trusted Tableau Authentication Ticket
try
{
//For example purposes, I'm hard-coding the Tableau Server Name and Site Name for the example _trustedAuth.requestTicket method. In my actual code, I'm storing these in my web.config.
ticket = await _trustedAuth.requestTicket(b.getSSO(User.Identity.Name), "https://ProdTableauUrlGoesHere.com/trusted", "YourTargetSiteNameHere");
}
catch
{
ticket = "-1";
}
//Only add trusted Tableau Authentication ticket if it's valid, else kick user to default Report_Link which will make them login manually.
//You get a nasty error message if you pass in a '-1'
if (!ticket.Equals("-1"))
{
ViewBag.Link = _trustedAuth.addTicket(ticket.ToString(), report_Completion_Status.Report_Link);
}
else
{
ViewBag.Link = report_Completion_Status.Report_Link;
}
var model = await this.GetFullAndPartialViewModel(Report_Num);
return this.View(model);
}
插入了工单参数的新嵌入式 JavaScript (reportLink)
仪表板视图
@model WebReportingToolDAL.Models.ViewModels.ReportCategoryListModel
@{
ViewBag.Title = "Dashboard";
Layout = "~/Views/Shared/_Layout.cshtml";
}
<body>
@Html.Raw(ViewBag.Link)
</body>
如果一切正常,您应该不会再看到 Tableau 登录页面。