代码之家  ›  专栏  ›  技术社区  ›  Program.X

ASP.NET成员身份提供程序身份验证无法对WCF服务进行身份验证

  •  1
  • Program.X  · 技术社区  · 15 年前

    我有一个启用了角色的SqlMembershipProvider存储。这是配置的,用户“devtest”的角色是“xxUser”和“xxAdmin”。

    我还有一个WCF服务,我想对其进行身份验证和授权。我的问题是:

    1. 授权不是 发生时,代码只是执行 尽管有政策属性
    2. 我没有任何身份或安全措施 上下文所以不知道是谁 呼叫服务

    我需要:

    1. 要知道哪个用户正在调用 方法
    2. 一定程度的拒绝 权限不匹配时的用户 (理想情况下,应执行此操作 在 RoleProvider/会员提供商/WCF 但如果必须的话我可以自己做)
    3. 传输中的SSL

    我的服务合同如下:

        [ServiceContract]
        public interface ISupportService
        {
            [OperationContract]
            [PrincipalPermission(SecurityAction.Demand, Role = "ThisRoleDoesNotExist")]
            List<BaseInterestRate> GetAllBaseInterestRates();
        }
    

    代码非常简单:

    public class SupportService : ISupportService
    {
        public List<BaseInterestRate> GetAllBaseInterestRates()
        {
            OperationContext operationContext = OperationContext.Current;
            ServiceSecurityContext serviceSecurityContext = ServiceSecurityContext.Current; // is always null
    
            using (xxxEntities entities = new xxxEntities())
            {
                return new List<BaseInterestRate>(entities.BaseInterestRates);
            }
        }}
    

    因此,我的服务配置是:

    -->

    <behaviors>
      <serviceBehaviors>
          <behavior name="SupportServiceBehavior">
              <serviceMetadata httpGetEnabled="false" httpsGetEnabled="true" />
              <serviceDebug includeExceptionDetailInFaults="false" />
              <serviceAuthorization principalPermissionMode="UseAspNetRoles" roleProviderName="AspNetSqlRoleProvider" />
              <serviceCredentials>
                  <userNameAuthentication userNamePasswordValidationMode="MembershipProvider" 
     membershipProviderName="SqlMembershipProvider" />
              </serviceCredentials>
          </behavior>
        <behavior>     
          <serviceMetadata httpGetEnabled="true"/>
          <serviceDebug includeExceptionDetailInFaults="false"/>
        </behavior>
      </serviceBehaviors>
    </behaviors>
    <serviceHostingEnvironment multipleSiteBindingsEnabled="true" />
    

    已配置成员提供程序:

      <membership defaultProvider="SqlMembershipProvider" >
          <providers>
              <clear/>
              <add name="SqlMembershipProvider"
       connectionStringName="SqlMembershipProvider"
       applicationName="xxx"
       type="System.Web.Security.SqlMembershipProvider" />
          </providers>
      </membership>
      <roleManager enabled="true">
          <providers>
              <clear />
              <add connectionStringName="SqlMembershipProvider" applicationName="xxx"
               name="AspNetSqlRoleProvider" type="System.Web.Security.SqlRoleProvider" />
              <add applicationName="xxx" name="AspNetWindowsTokenRoleProvider"
               type="System.Web.Security.WindowsTokenRoleProvider" />
          </providers>
      </roleManager>
    

    我已按照这些页上的说明写信:

    我至少希望证书/传输等的问题会失败,并出现异常,但我可以在WCF调用中调试。我没有可用的安全上下文/用户上下文,当我使用不属于上述两个角色的用户(在上面的代码示例中我这样做)时,我不会被“踢出”。

    我的客户端应用程序目前是一个Web应用程序,但最终也将提供Windows窗体应用程序和测试套件。我目前使用的是ASP.NET WebDev服务器,运行的是.NET 4.0。

    我遗漏了什么吗?

    3 回复  |  直到 15 年前
        1
  •  0
  •   efalconer    15 年前

    我对WCF Rest服务还不太熟悉,但在我自己的测试中遇到了类似的问题。我看到了这段视频,这段视频有点帮助(即使不是我想做的):

    http://channel9.msdn.com/blogs/rojacobs/endpointtv-securing-restful-services-with-aspnet-membership

    实际上,问题在于,在asp.net配置下,我必须禁用匿名访问,以便它使用MembershipProvider身份验证:

    system.web>
        <authorization>
          <deny users="?" />
        </authorization>
    ...
    
        2
  •  0
  •   John Nicholas    14 年前

    我认为你不能在接口上设置主体权限。 我敢打赌,如果你把它移到服务实现方法上,它会起作用的

    或者至少开始打破一个不同的原因(我目前卡在这一点上-我得到访问被拒绝的例外-希望你不要!)

    (我第一次尝试把它们也放到合同界面上)

        3
  •  0
  •   lupok    12 年前

    这是使用SSL自托管的wcf服务的正确配置:

    <?xml version="1.0"?>
    <configuration>
       <startup>
          <supportedRuntime version="v4.0" sku=".NETFramework,Version=v4.0"/>
       </startup>
       <connectionStrings>
          <add name="mySqlConnection" connectionString="Data Source=.\SQLEXPRESS2012;Integrated Security=SSPI;Initial Catalog=aspnetdb;"/>
       </connectionStrings>
       <system.web>
          <compilation debug="true"/>
          <!-- Configure the Sql Membership Provider -->
          <membership defaultProvider="MySqlMembershipProvider" userIsOnlineTimeWindow="15">
             <providers>
                <clear/>
                <add name="MySqlMembershipProvider" type="System.Web.Security.SqlMembershipProvider" connectionStringName="mySqlConnection" applicationName="UsersManagementNavigationApplication" enablePasswordRetrieval="false" enablePasswordReset="false" requiresQuestionAndAnswer="false" requiresUniqueEmail="true" passwordFormat="Hashed"/>
             </providers>
          </membership>
    
          <!-- Configure the Sql Role Provider -->
          <roleManager enabled="true" defaultProvider="MySqlRoleProvider">
             <providers>
                <clear/>
                <add name="MySqlRoleProvider" type="System.Web.Security.SqlRoleProvider" connectionStringName="mySqlConnection" applicationName="UsersManagementNavigationApplication"/>
             </providers>
          </roleManager>
       </system.web>
       <system.serviceModel>
          <bindings>
             <webHttpBinding>
                <binding name="webBinding">
                   <security mode="Transport">
                      <transport clientCredentialType="Basic"/>
                   </security>
                </binding>
             </webHttpBinding>
             <basicHttpBinding>
                <binding name="basicBindingConfiguration">
                   <security mode="Transport">
                      <transport clientCredentialType="Basic"/>
                   </security>
                </binding>
             </basicHttpBinding>
          </bindings>
          <behaviors>
             <endpointBehaviors>
                <behavior name="webEndpointBehavior">
                   <webHttp/>
                </behavior>
             </endpointBehaviors>
             <serviceBehaviors>
                <behavior name="webServiceBehavior">
                   <serviceMetadata httpsGetEnabled="true"/>
                   <serviceThrottling/>
                   <serviceDebug/>
                </behavior>
                <behavior name="myServiceBehavior">
                   <!-- Configure role based authorization to use the Role Provider -->
                   <serviceAuthorization principalPermissionMode="UseAspNetRoles" roleProviderName="MySqlRoleProvider">
                   </serviceAuthorization>
                   <serviceCredentials>
                      <!-- Configure user name authentication to use the Membership Provider -->
                      <userNameAuthentication userNamePasswordValidationMode="Custom" customUserNamePasswordValidatorType="WcfServiceHTTPSSelfHosted.MyCustomValidator, WcfServiceHTTPSSelfHosted"   />
                   </serviceCredentials>
                   <!-- To avoid disclosing metadata information, set the value below to false before deployment -->
                   <serviceMetadata httpsGetEnabled="true"/>
                   <!-- To receive exception details in faults for debugging purposes, set the value below to true.  Set to false before deployment to avoid disclosing exception information -->
                   <serviceDebug includeExceptionDetailInFaults="false"/>
                </behavior>
             </serviceBehaviors>
          </behaviors>
          <services>
             <service behaviorConfiguration="myServiceBehavior" name="WcfServiceHTTPSSelfHosted.WcfServiceHTTPSSelfHosted">
                <endpoint address="" binding="basicHttpBinding" bindingConfiguration="basicBindingConfiguration" contract="WcfServiceHTTPSSelfHosted.IWcfServiceHTTPSSelfHosted"/>
                <endpoint address="web" behaviorConfiguration="webEndpointBehavior" binding="webHttpBinding" bindingConfiguration="webBinding" contract="WcfServiceHTTPSSelfHosted.IWcfServiceHTTPSSelfHosted"/>
                <endpoint address="mex" binding="mexHttpsBinding" bindingConfiguration="" contract="IMetadataExchange"/>
                <host>
                   <baseAddresses>
                      <add baseAddress="https://localhost:50001/WcfServiceHTTPSSelfHosted/"/>
                   </baseAddresses>
                </host>
             </service>
          </services>
       </system.serviceModel>
    </configuration>
    

    如果您需要更多信息,请查看以下内容:

    http://www.albertoschiassi.it/Home/tabid/55/EntryId/94/Use-ASP-NET-SqlMemberShipProvider-in-WCF-self-hosted-service.aspx

    和

    http://www.albertoschiassi.it/Home/tabid/55/EntryId/95/Use-ASP-NET-SqlMemberShipProvider-in-WCF-self-hosted-service-with-SSL.aspx