【问题标题】:Allow access to WCF based on a group set in web.config允许基于 web.config 中设置的组访问 WCF
【发布时间】:2011-11-21 15:46:43
【问题描述】:

我创建了一个使用 Windows 身份验证的 WCF 服务,并希望将其设置为只有当用户在 Windows 组中时才能访问它。我目前在代码中使用以下属性来实现这一点

[PrincipalPermission(SecurityAction.Demand, Role = "Domain\MyGroup")]

问题是如果我想更改组,我必须在每个方法上执行并编译。有没有办法让我可以在配置文件和整个服务中设置具有访问权限的组?

我在我的配置文件中尝试了以下方法,但这似乎不起作用

<security>
   <authentication>
      <windowsAuthentication authPersistSingleRequest="true" enabled="true"/>
   </authentication>
   <authorization>
      <add accessType="Allow" roles="Domain\MyGroup" /> 
   </authorization>
</security>

【问题讨论】:

    标签: wcf iis authentication web-config


    【解决方案1】:

    好的,我想通了。我的配置文件设置如下

    <security>
      <authentication>
        <windowsAuthentication enabled="true" />
      </authentication>
      <authorization>
        <remove users="*" roles="" verbs="" />
        <remove users="?" roles="" verbs="" />
        <add accessType="Deny" users="?" />
        <add accessType="Allow" roles="Domain\MyGroup" />
      </authorization>
    </security>
    

    还得设置

    <serviceHostingEnvironment aspNetCompatibilityEnabled="true" />
    

    在我的实现 WCF 合同的班级上

    [AspNetCompatibilityRequirements(RequirementsMode = AspNetCompatibilityRequirementsMode.Allowed)]
    

    我猜这意味着我使用 ASP 身份验证而不是 WCF,但我为我工作

    【讨论】:

      【解决方案2】:

      PrincipalPermission 属性来自 .NET 代码访问安全功能,与 WCF 无关。如果服务托管在 IIS 中,则更灵活的方法显示在此 MSDN post. WCF 还支持不同的自定义身份验证机制 as described here.

      【讨论】:

      • 您将身份验证与授权混淆了。 PrincipalPermissionAttribute 与后者有关。虽然这个属性确实是 CAS 的一部分,但您还没有真正回答这个问题。
      猜你喜欢
      • 2021-10-26
      • 2012-04-16
      • 2018-04-02
      • 1970-01-01
      • 1970-01-01
      • 1970-01-01
      • 1970-01-01
      • 1970-01-01
      • 1970-01-01
      相关资源
      最近更新 更多