【发布时间】:2019-11-05 10:24:25
【问题描述】:
用户通过 ADFS 向 .net mvc Web 应用程序授权。但是一些特殊的文件夹可以在没有授权的情况下访问。
防止未经授权访问这些文件夹(例如 /bundles)的最佳方法是什么?
是否可以在 web.config 中进行配置或者是 IIS 配置?
【问题讨论】:
标签: .net iis configuration authorization adfs
用户通过 ADFS 向 .net mvc Web 应用程序授权。但是一些特殊的文件夹可以在没有授权的情况下访问。
防止未经授权访问这些文件夹(例如 /bundles)的最佳方法是什么?
是否可以在 web.config 中进行配置或者是 IIS 配置?
【问题讨论】:
标签: .net iis configuration authorization adfs
【讨论】:
如果您使用 OWIN 中间件配置 ADFS 身份验证,则可以使用以下代码保护所有匿名请求:
app.Use((context, cont) =>
{
if ((context.Authentication.User != null) && (context.Authentication.User.Identity != null) && (context.Authentication.User.Identity.IsAuthenticated))
{
return cont();
}
else
{
var provider = "ADFS Server";
context.Authentication.Challenge(new AuthenticationProperties
{
RedirectUri = "https://youapp-url/"
}, provider);
return Task.Delay(0);
}
});
app 是 IAppBuilder 类型,provider 是 AuthenticationType
【讨论】: