【发布时间】:2016-08-26 16:21:37
【问题描述】:
当用户访问我的 webapi 应用程序时,我需要捕获用户的域\用户名。在我的开发机器上,我的 webapi 位于 localhost:10570 和我的 angularjs 网站,它在 localhost:34575 调用 web 服务。
如果我直接调用我的 webapi 应用程序,一切正常。我可以看到用户域和用户名,服务将请求的数据作为 JSON 返回。但是,如果我访问我的 angularjs 站点并且 angular 调用了 webapi,那么每次针对该服务的调用都会得到 401 未授权。
在我的 WebApi 应用程序的 web.config 中,我有:
<system.web>
<compilation debug="true" targetFramework="4.5.2" />
<httpRuntime targetFramework="4.5.2" />
<authentication mode="Windows" />
</system.web>
<system.webServer>
<httpProtocol>
<customHeaders>
<add name="Access-Control-Allow-Origin" value="http://localhost:34575" />
<add name="Access-Control-Allow-Methods" value="POST, PUT, DELETE, GET, OPTIONS" />
<add name="Access-Control-Allow-Headers" value="content-Type, accept, origin, X-Requested-With, Authorization, name" />
<add name="Access-Control-Allow-Credentials" value="true" />
</customHeaders>
</system.webServer>
我在 IIS Express for Visual Studio 2015 的 applicationhost.config 文件中有这个:
<location path="MyNamespace.WebAPI">
<system.webServer>
<security>
<authentication>
<windowsAuthentication enabled="true" />
<anonymousAuthentication enabled="false" />
</authentication>
</security>
</system.webServer>
</location>
我的 angularjs 网站属于“MyNamespace.Client”的同一解决方案。
为什么直接访问web服务正常,但是通过angular应用访问却失败了?
【问题讨论】:
-
您需要使用 Bearer Token。请参阅bitoftech.net/2014/06/09/…、dotnetcurry.com/aspnet/1223/… 和 c-sharpcorner.com/UploadFile/ff2f08/…
-
@gpaoli 幸运的是,在这种情况下不需要承载令牌。看起来工作量很大。
标签: angularjs iis asp.net-web-api