你可以在我的代码中激发灵感。我花了一些时间和一些调查。请记住,服务契约接口是由控制器实现的,我没有找到任何其他方式将服务请求放入 http 管道。由于这种配置,我可以在一个代码上运行 REST 和 SOAP 分支。
在 Startup.cs 中:
using SoapCore;
using ZNetCS.AspNetCore.Authentication.Basic;
using ZNetCS.AspNetCore.Authentication.Basic.Events;
public void ConfigureServices (IServiceCollection services)
{
services.AddScoped<YourNamespace.BasicAuthValidator>();
services.AddSingleton<YourNamespace.Contracts.IEnityService, YourNamespace.Controllers.ApiController>();
services.AddAuthentication(BasicAuthenticationDefaults.AuthenticationScheme)
.AddBasicAuthentication(op => {
op.Realm = "YourRealm";
op.EventsType = typeof(YourNamespace.BasicAuthValidator);
});
services.AddControllers();
}
public void Configure (IApplicationBuilder app, IWebHostEnvironment env)
{
app.UseHttpsRedirection();
app.UseRouting();
app.UseAuthentication();
app.UseAuthorization();
app.UseEndpoints(endpoints => {
endpoints.MapControllers().RequireAuthorization(); //Use DefaultAuthorizationPolicy, ie. require authenticated users on REST interface
endpoints.UseSoapEndpoint<YourNamespace.Contracts.IEnityService>("/SOAP/YourService.svc", this.CreateBindingForSOAP(), SoapSerializer.DataContractSerializer).RequireAuthorization();
}
BasicHttpBinding CreateBindingForSOAP ()
{
var binding = new BasicHttpBinding(BasicHttpSecurityMode.Transport); //security is on HTTP level
binding.Security.Transport.ClientCredentialType = HttpClientCredentialType.Basic; //http challenges filling Authorization header
return binding;
}
然后创建用于处理基本身份验证的类:
public class BasicAuthValidator:BasicAuthenticationEvents
{
public override Task ValidatePrincipalAsync (ValidatePrincipalContext context)
{
if ((context.UserName == "userName") && (context.Password == "password")) {
var claims = new List<Claim>{new Claim(ClaimTypes.Name, context.UserName, context.Options.ClaimsIssuer)};
var principal = new ClaimsPrincipal(new ClaimsIdentity(claims, context.Scheme.Name));
context.Principal = principal;
}
return Task.CompletedTask;
}
}