|
|
|
Securing WCF Data Services using WIF |
Si vous voulez bloquer ce service sur vos fils RSS
Si vous voulez nous contacter ou nous proposer un fil RSS
Menu > Articles de la revue de presse : - l'ensemble [ tous | francophone] - par mots clé [ tous] - par site [ tous] - le tagwall [ voir] - Top bi-hebdo de la revue de presse [ Voir]
Présentation : This questions comes up every once in a while.. Since WCF Data Services is just a normal WCF service using the web programming model , all the typical security APIs and extensibility points apply. That said, depending on your scenario you might have to be a little more creative for REST-style services. Here s a quick walkthrough Enabling WIF in the Data Service The easiest way to get WIF wired up is by writing a custom service host factory. You simply have to derive from DataServiceHostFactory, override CreateServiceHost and call FederatedServiceCredentials.ConfigureServiceHost before you return the host to the plumbing. This gives you the standard WIF integration for all standard HTTP credential types Basic, Integrated etc and the typical extensibility points like ClaimsAuthorizationManager. For accepting and converting more advanced token types like SWT or SAML, you need to plugin your own token handling. I gave it a try for SWT tokens see here for the general SWT integration story . public class ProtectedDataServiceHostFactory DataServiceHostFactory protected override ServiceHost CreateServiceHost Type serviceType, Uri baseAddresses host.Authorization.ServiceAuthorizationManager new SimpleWebTokenAuthorizationManager acsAddress, expectedAudience, acsKey host.Authorization.PrincipalPermissionMode PrincipalPermissionMode.Custom return host This uses my SWT plumbing to turn incoming SWT tokens into an IClaimsPrincipal. You could easily do the same thing for SAML but be aware that SAML tokens can become quite big and you typically want to transmit them using an HTTP header for this scenario . You could now use the resulting claims for authorization as well as WCFDS interceptors, e.g. QueryInterceptor Users public Expression OnQueryUsers var principal Thread.CurrentPrincipal as IClaimsPrincipal var customer principal.GetClaimValue http claims customerName return user user.Applications.ApplicationName customer Sending a token header to the Data Service The next step is to send a token to the Data Service. This can be achieved by handling the SendingRequest event on the DataServiceContext derived client plumbing, e.g. class ProviderEntitiesWithToken ProviderEntities string _token string _tokenHeader Authorization public ProviderEntitiesWithToken Uri address, string token base address _token token SendingRequest OnSendingRequest void OnSendingRequest object sender, SendingRequestEventArgs e e.RequestHeaders tokenHeader SimpleWebToken.GetAuthorizationHeader token Using the Data Service The usage pattern is the same as without any tokens or WIF. New up your derived class, set the token and use e.g. LINQ to query the Data Service. static void Main string args var token RequestToken var service new ProviderEntitiesWithToken new Uri dataServiceAddress , token var users from u in service.Users select u users.ToList .ForEach u Console.WriteLine u.UserName HTH
Les derniers articles du site "www.leastprivilege.com" :
- Moving to a new Blog - API for the X509 Certificate Store - Thinktecture.IdentityModel.Http and the ASP.NET Web API CodePlex bits - Identity in .NET 4.5Part 4 Claims over Kerberos - Thinktecture IdentityServer and Contrib Project now on GitHub - Identity in .NET 4.5Part 3 Breaking changes - Identity in .NET 4.5Part 2 Claims Transformation in ASP.NET Beta 1 - Identity in .NET 4.5Part 1 Status Quo Beta 1 - ASP.NET WebAPI Security 5 JavaScript Clients - ASP.NET WebAPI Security 4 Examples for various Authentication Scenarios
Menu > Articles de la revue de presse : - l'ensemble [ tous | francophone] - par mots clé [ tous] - par site [ tous] - le tagwall [ voir] - Top bi-hebdo de la revue de presse [ Voir]
Si vous voulez bloquer ce service sur vos fils RSS :
- avec iptables "iptables -A INPUT -s 88.191.75.173 --dport 80 -j DROP"
- avec ipfw et wipfw "ipfw add deny from 88.191.75.173 to any 80"
- Nous contacter par mail
| Mini-Tagwall des articles publiés sur SecuObs : | | | | sécurité, exploit, windows, attaque, outil, microsoft, réseau, audit, metasploit, vulnérabilité, système, virus, internet, usbsploit, données, source, linux, protocol, présentation, scanne, réseaux, scanner, bluetooth, conférence, reverse, shell, meterpreter, vista, rootkit, détection, mobile, security, malicieux, engineering, téléphone, paquet, trames, https, noyau, utilisant, intel, wishmaster, google, sysun, libre |
| Mini-Tagwall de l'annuaire video : | | | | curit, security, biomet, metasploit, biometric, cking, password, windows, botnet, defcon, tutorial, crypt, xploit, exploit, lockpicking, linux, attack, wireshark, vmware, rootkit, conference, network, shmoocon, backtrack, virus, conficker, elcom, etter, elcomsoft, server, meterpreter, openvpn, ettercap, openbs, iphone, shell, openbsd, iptables, securitytube, deepsec, source, office, systm, openssh, radio |
| Mini-Tagwall des articles de la revue de presse : | | | | security, microsoft, windows, hacker, attack, network, vulnerability, google, exploit, malware, internet, remote, iphone, server, inject, patch, apple, twitter, mobile, virus, ebook, facebook, vulnérabilité, crypt, source, linux, password, intel, research, virtual, phish, access, tutorial, trojan, social, privacy, firefox, adobe, overflow, office, cisco, conficker, botnet, pirate, sécurité |
| Mini-Tagwall des Tweets de la revue Twitter : | | | | security, linux, botnet, attack, metasploit, cisco, defcon, phish, exploit, google, inject, server, firewall, network, twitter, vmware, windows, microsoft, compliance, vulnerability, python, engineering, source, kernel, crypt, social, overflow, nessus, crack, hacker, virus, iphone, patch, virtual, javascript, malware, conficker, pentest, research, email, password, adobe, apache, proxy, backtrack |
|
|
|
|
|