【发布时间】:2015-12-10 21:56:57
【问题描述】:
我有一个位于 MVC 项目的“api”位置的 ServiceStack API。除了这个 API,还有标准的 MVC 控制器和视图,它们使用 HostContext.ResolveService<MyService>(HttpContext) 调用 ServiceStack 服务。
我使用 ServiceStack AuthenticateService 设置了身份验证,调用 Authenticate(new Authenticate {...}) 方法然后设置 FormsAuthentication cookie。我没有在 web.config 中启用 FormsAuthentication 本身。这是 AppHost.cs 中的身份验证设置:
public void ConfigureAuth(Container container)
{
var authFeature = new AuthFeature(() => new CustomUserSession(), new IAuthProvider[]
{
new BasicAuthProvider(),
new CredentialsAuthProvider()
})
{
HtmlRedirect = "/Login",
MaxLoginAttempts = 5,
IncludeAssignRoleServices = false
};
Plugins.Add(authFeature);
Register<IUserAuthRepository>(new OrmLiteAuthRepository(Resolve<IDbConnectionFactory>())
{
UseDistinctRoleTables = true
});
Resolve<IUserAuthRepository>().InitSchema();
}
在应用程序的初始运行中一切正常。未经身份验证的用户获得登录页面,它会登录,我可以提取会话数据,如名称和时区。我访问视图中的会话以使用以下代码填充菜单:
@{
var key = SessionFeature.GetSessionKey() ?? "";
var sess = HostContext.Resolve<ICacheClient>().Get<AuthUserSession>(key).ConvertTo<CustomUserSession>();
}
Welcome @sess.FirstName @sess.LastName
但是,一段时间后,会话似乎过期了,尽管我在上面提取的 ServiceStack 会话显示 true 对应于 IsAuthenticated,但其他会话数据(如名字/姓氏和时区)均无法访问。
因为我所说的时间段大约是 12 小时,所以我怀疑会话确实没有仍然经过身份验证。我尝试在 web.config 中启用 FormsAuthentication,但这搞砸了 api 端点,即使我在 location 部分下的 web.config 中排除了它。
有什么想法可能是错的吗?
【问题讨论】:
标签: c# asp.net-mvc authentication servicestack