【发布时间】:2015-05-14 14:04:13
【问题描述】:
我有一个包含 AngularJS、WebApi2 和 FormAuthentication 的项目。 因为我需要从使用 session 来存储一些用户变量的 WebForms 项目中导入一些旧代码,所以我必须在 WebApi 中实现 Session。
在 WebConfig 我有:
`
<authentication mode="Forms">
<forms loginUrl="/index.html" defaultUrl="/Areas/Modeler/modeler.html" name=".ASPXFORMSAUTH" protection="All" cookieless="UseDeviceProfile" slidingExpiration="true" path="/" domain="" requireSSL="false" timeout="600" enableCrossAppRedirects="false">
</forms>
</authentication>
<authorization>
<allow users="*" />
</authorization>
<machineKey validationKey="xxxxx" decryptionKey="xxxxxx" validation="SHA1" />
</system.web>
<location path="Scripts">
<system.web>
<authorization>
<allow users="*" />
</authorization>
</system.web>
</location>
<location path="~/Authenticate">
<system.web>
<authorization>
<allow users="*" />
</authorization>
</system.web>
</location>
`
我在 Global.asax.cs 中进行了以下更改以实现 Session:
`
public override void Init()
{
this.PostAuthenticateRequest += Application_PostAuthorizeRequest;
base.Init();
}
protected void Application_Start()
{
AreaRegistration.RegisterAllAreas();
GlobalConfiguration.Configure(WebApiConfig.Register);
GlobalConfiguration.Configuration.IncludeErrorDetailPolicy = IncludeErrorDetailPolicy.Always;
}
protected void Application_PostAuthorizeRequest(object sender, EventArgs e)
{
var url = HttpContext.Current.Request.AppRelativeCurrentExecutionFilePath;
var auth = Context.Request.IsAuthenticated;
HttpContext.Current.SetSessionStateBehavior(SessionStateBehavior.Required);
}`
用户输入姓名和密码后,我调用一个post方法~/Authenticate/Login。
在 chrome 浏览器网络选项卡中,我可以看到下两行: 登录方式:POST,状态 302 登录方法 GET,状态 405 第一次通话:
Remote Address:[::1]:52966
Request URL:http://localhost:52966/Authenticate/Login
Request Method:POST
Status Code:302 Found
Response Headers
view source
Content-Length:166
Date:Thu, 14 May 2015 13:11:24 GMT
Location:/(S(tdd41h23pms5lllzyro1hltq))/Authenticate/Login
Server:Microsoft-IIS/8.0
X-Powered-By:ASP.NET
X-SourceFiles:=?UTF-8?B?RDpcUHJvamVjdH..............=?=
Request Headers
view source
Accept:application/json, text/plain, */*
Accept-Encoding:gzip, deflate
Accept-Language:en-US,en;q=0.8,ro;q=0.6
Connection:keep-alive
Content-Length:44
Content-Type:application/json;charset=UTF-8
Cookie:PHPSESSID=d5djbkgs7ttui073jl04mg6st3; __AntiXsrfToken=97b6e321343944a89ade4acc098305bd; ASP.NET_SessionId=2ggakcj1qxtewgsrh5qvtw40; _session_id=BAh7B0kiD3Nlc3Npb25faW....; .AspNet.ApplicationCookie=GcQUqnFHbPaX...;
UserPassword=password; UserName=admin;
.ASPXFORMSAUTH=7B15EE3DE...
DNT:1
Host:localhost:52966
Origin:http://localhost:52966
Referer:http://localhost:52966/index.html
User-Agent:Mozilla/5.0 (Windows NT 6.3; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/42.0.2311.135 Safari/537.36
Request Payload
view source
{userName: "admin", userPassword: "password"}
问题是:为什么对 Login 的调用会被重定向? 在 Global.ascx.cs ai 的 Application_PostAuthorizeRequest 方法中检查 Context.Request.IsAuthenticated 是否为真。
【问题讨论】:
标签: asp.net-web-api http-status-code-302 form-authentication