【问题标题】:Azure AD OpenId Auth not working when inhereted Authorize Attribute继承授权属性时 Azure AD OpenId 身份验证不起作用
【发布时间】:2019-04-17 09:49:59
【问题描述】:

我尝试为使用 C# 4.7.2 完整框架编写的 azure 应用服务验证用户。

身份验证在 Azure AD 上成为真正的 OpenId。

在控制器上使用 [Authorize] 属性时效果很好。

当我尝试使用从 AuthorizeAttribute 继承的属性来装饰控制器时,身份验证不再基于 Azure Ad(在云中或通过 iisexpress/localhost)

我需要重写 OnAuthorize 方法,因为应用根据上下文显示不同的数据,并且该上下文必须与某些用户安全组匹配。

即: url /context1 和 /context2 播放相同的代码,但 dbs 请求将因“where context = @context”条件而有所不同。所有 url 都会以 /context1 或 /context2 为前缀。

这里是相关代码:

        public void ConfigureAuth(IAppBuilder app)
        {

            //https://azure.microsoft.com/fr-fr/resources/samples/active-directory-dotnet-webapp-groupclaims/
            app.SetDefaultSignInAsAuthenticationType(CookieAuthenticationDefaults.AuthenticationType);

            app.UseCookieAuthentication(new CookieAuthenticationOptions());
            string authority = $"https://login.microsoftonline.com/{ConfigurationManager.AppSettings["ida:Tenant"]}";
            string client = ConfigurationManager.AppSettings["ida:ClientId"];
            app.UseOpenIdConnectAuthentication(
                new OpenIdConnectAuthenticationOptions
                {
                    ClientId = client,
                    Authority = authority,
                    TokenValidationParameters = new TokenValidationParameters
                    {
                        ValidateIssuer = false,
                        RoleClaimType = "groups",
                    },
                    Notifications = new OpenIdConnectAuthenticationNotifications
                    {
                        RedirectToIdentityProvider = OnRedirectToIdentityProvider,
                        //MessageReceived = OnMessageReceived,
                        //SecurityTokenValidated = OnSecurityTokenValidated,
                        //AuthenticationFailed = OnAuthenticationFailed,
                        AuthorizationCodeReceived = OnAuthorizationCodeReceived,
                        //SecurityTokenReceived = OnSecurityTokenReceived
                    }
                });
        }

“OnRedirectToIdentityProvider”帮助我检查是否调用了 azure AD 身份验证。

public class CustomAuthorizeAttribute : AuthorizeAttribute
    {

        public override void OnAuthorization(AuthorizationContext context)
        {
            //OnRedirectToIdentityProvider has not been called
            //Checking that the authenticated user is in the right
            //security group to grant access to /context1 or /context2
        }
}

我希望在 OnAuthorize 覆盖后调用 Startup.cs 配置。

感谢您的帮助。

【问题讨论】:

    标签: c# azure inheritance azure-active-directory onauthorization


    【解决方案1】:

    在等待回复并尝试简化授权时,我遇到了另一个问题,并在搜索时找到了答案。

    要继续对 Azure AD 进行身份验证,您可以覆盖 AuthorizationCore 方法。

    这是新代码:

     public class CustomAuthorizeAttribute : AuthorizeAttribute
        {
            protected override bool AuthorizeCore(HttpContextBase context)
            {
                if (!base.AuthorizeCore(context))
                    return false;
                //Custom actions
            }
        }
    
    

    问候。

    【讨论】:

      猜你喜欢
      • 1970-01-01
      • 1970-01-01
      • 1970-01-01
      • 1970-01-01
      • 2021-12-03
      • 2019-11-16
      • 2018-05-19
      • 1970-01-01
      • 1970-01-01
      相关资源
      最近更新 更多