这是为了将 windows 和以后的表单身份验证转换为 MVC5 和 MVC6 的表单身份验证,因此希望您可以更改足够的代码以使其适合您...我计划在重新编写登录脚本时更改一些部分。(这是 Alpha 版,所以会做出一些改变!)
我将以下代码放在我们的 MVC5 Intranet 站点中以获取 Windows 身份验证的角色
protected void Application_PostAuthenticateRequest(Object sender, EventArgs e)
// Get current windows Identity to get the roles out of it
WindowsIdentity ident = WindowsIdentity.GetCurrent();
string[] roles = new string[ident.Groups.Count];
int i = 0;
// get the groups from the current Identity
foreach (var g in ident.Groups)
roles[i] = g.Translate(typeof(System.Security.Principal.NTAccount)).Value.ToString();
// join into a single string the roles that the user is a member of
string roleData = String.Join(";", roles) ;
// create the forms ticket that all MVC5 sites with the same machine key will pick up.
FormsAuthenticationTicket ticket = new FormsAuthenticationTicket(1, ident.Name, DateTime.Now, DateTime.Now.AddMinutes(30), false, roleData, "/");
string encTicket = FormsAuthentication.Encrypt(ticket);
// add the user name first from the Principle and add Windows as this will come from Windows Auth
roleData = ident.Name + ";" + "Windows;" + roleData;
//use machine key to encrypt the data
var encTicket2 = MachineKey.Protect(System.Text.Encoding.UTF8.GetBytes(roleData),
"ApplicationCookie", "v1");
//create a new cookie with a base64string of the encrypted bytes
HttpCookie hc2 = new HttpCookie("cookie1", Convert.ToBase64String(encTicket2));
hc2.Domain = ".domain.com";
hc2.Expires = DateTime.Now.AddHours(8);
// NOTE: The name of the HttpCookie must match what the FormsAuth site expects.
HttpCookie hc = new HttpCookie("cookie2", encTicket);
hc.Domain = ".domain.com";
hc.Expires = DateTime.Now.AddHours(8);
// Ticket and cookie issued, now go to the FormsAuth site and all should be well.
这将以表单和 MVC6 方法创建到 Windows 身份验证票证。
MVC6 的字符串看起来像“John.Doe;Windows;Admin”
然后在 MVC6 启动文件中,我将以下代码放入配置部分...
app.Use(async (context, next) =>
Logger _logger = new Logger("C:\\\\Logs\\Log.txt");
var request = context.Request;
var cookie = request.Cookies.Get("cookie1");
var ticket = cookie.ToString();
ticket = ticket.Replace(" ", "+");
var padding = 3 - ((ticket.Length + 3)%4);
if (padding != 0)
ticket = ticket + new string('=', padding);
var bytes = Convert.FromBase64String(ticket);
bytes = System.Web.Security.MachineKey.Unprotect(bytes,
"ApplicationCookie", "v1");
string ticketstring = System.Text.Encoding.UTF8.GetString(bytes);
var ticketSplit = ticketstring.Split(';');
var claims = new Claim[ticketSplit.Length];
var OriginalIssuer = "";
for (int index = 0; index != ticketSplit.Length; ++index)
if (index == 0)
claims[index] = new Claim(ClaimTypes.Name, ticketSplit[index], "Windows");
else if (index == 1)
OriginalIssuer = ticketSplit[1];
claims[index] = new Claim(ClaimTypes.Role,ticketSplit[0], OriginalIssuer);
var identity = new ClaimsIdentity(claims, OriginalIssuer, ClaimTypes.Name,ClaimTypes.Role);
var principal = new ClaimsPrincipal(identity);
context.User = principal;
_logger.Write("Cookie End");
await next();
} catch (Exception ex)
然后,这将获取 cookie 并从中创建一个新的声明身份。我刚刚完成了让它工作的逻辑,所以我相信它可以被整理...只是想我会把它给你,这样你就可以看看你是否能得到一些想法。