如何禁用SharePoint 2013的WSDL生成?
针对你尝试移除Documentation协议、限制wswsdl.aspx访问、设置httpGetEnabled为false后仍能生成WSDL的情况,可以尝试以下几种方案:
直接修改ASMX服务文件拦截WSDL请求
定位到C:\Program Files\Common Files\microsoft shared\Web Server Extensions\15\ISAPI下的目标ASMX文件(比如lists.asmx),在文件头部添加代码逻辑,直接拦截带?wsdl参数的请求:<%@ WebService Language="C#" Class="Microsoft.SharePoint.SoapServer.SPListSoapServer" %> <% if (Request.QueryString["wsdl"] != null) { Response.StatusCode = 403; Response.End(); } %>该方式会直接对WSDL请求返回403禁止访问状态。
通过IIS URL重写规则拦截WSDL请求
在IIS管理器中为目标SharePoint站点配置URL重写规则,阻断所有带?wsdl的Web服务请求:- 进入站点的URL重写模块,添加空白规则
- 设置匹配URL为
*_vti_bin/*.asmx,查询字符串匹配wsdl - 操作选择自定义响应,状态码设为403,描述填"WSDL Access Denied"
彻底关闭WCF服务元数据
若涉及WCF类型的SharePoint服务,在对应配置文件中修改<serviceMetadata>节点,同时移除元数据端点:<serviceMetadata httpGetEnabled="false" httpsGetEnabled="false"/> <!-- 删除或注释掉元数据端点 --> <!-- <endpoint address="mex" binding="mexHttpBinding" contract="IMetadataExchange"/> -->自定义HttpModule全局拦截WSDL请求
编写自定义HttpModule,在请求管道中识别WSDL请求并终止响应:public class BlockWsdlModule : IHttpModule { public void Init(HttpApplication context) { context.BeginRequest += Context_BeginRequest; } private void Context_BeginRequest(object sender, EventArgs e) { var app = (HttpApplication)sender; var request = app.Context.Request; if (request.Path.Contains("_vti_bin/") && !string.IsNullOrEmpty(request.QueryString["wsdl"])) { app.Context.Response.StatusCode = 403; app.Context.Response.End(); } } public void Dispose() { } }编译后将模块部署到GAC,并在web.config的
<httpModules>节点中注册该模块。
内容的提问来源于stack exchange,提问作者Baahubali
相关产品推荐
相关产品推荐

