【发布时间】:2011-11-21 15:46:43
【问题描述】:
我创建了一个使用 Windows 身份验证的 WCF 服务,并希望将其设置为只有当用户在 Windows 组中时才能访问它。我目前在代码中使用以下属性来实现这一点
[PrincipalPermission(SecurityAction.Demand, Role = "Domain\MyGroup")]
问题是如果我想更改组,我必须在每个方法上执行并编译。有没有办法让我可以在配置文件和整个服务中设置具有访问权限的组?
我在我的配置文件中尝试了以下方法,但这似乎不起作用
<security>
<authentication>
<windowsAuthentication authPersistSingleRequest="true" enabled="true"/>
</authentication>
<authorization>
<add accessType="Allow" roles="Domain\MyGroup" />
</authorization>
</security>
【问题讨论】:
标签: wcf iis authentication web-config