WCF无法获取身份声明问题求助(WebForms等场景正常)
WCF服务无法获取身份声明的问题
我的WCF方法无法读取任何身份声明,虽然能通过ClaimsPrincipalPermission完成用户认证,但需要在指定方法中获取声明列表信息。这套逻辑在WebForms、WebAPI和ASMX中都能正常运行,唯独在WCF Web方法里失效。
我能在授权管理器中看到声明信息,但进入服务类后声明值就丢失了。相关信息如下:
预期结果
显示包含tmtName等声明信息的ClaimsPrincipal对象,可正常读取声明值。
实际结果
ClaimsPrincipal对象中无任何声明信息,无法读取tmtName等声明值。
WCF方法代码
该逻辑在WebForms、WebAPI和ASMX中正常运行:
namespace ControlPanelService { [AspNetCompatibilityRequirements(RequirementsMode = AspNetCompatibilityRequirementsMode.Allowed)] [ClaimsPrincipalPermission(SecurityAction.Demand, Resource = "ControlPanel", Operation = "Request")] [ExceptionHandling.WCF.AiLogExceptionAttribute] public partial class ControlPanelService : IControlPanelService { #region Claim private string _testMgmtUrl { get; set; } private string _tmtName { get; set; } #endregion public ControlPanelService() { var identity = (System.Security.Claims.ClaimsPrincipal)System.Threading.Thread.CurrentPrincipal; this._tmtName = identity.GetClaimValue("tmtName"); } // 其他代码... } }
授权管理器代码
此处可正常查看声明,但服务类中声明丢失:
namespace CGI_Automation_Framework.ClaimsManager { public class AuthorizationManager : ClaimsAuthorizationManager { public override bool CheckAccess(AuthorizationContext context) { var userIdentity = HttpContext.Current.User.Identity; bool checkForAuthentication = false; if (userIdentity.IsAuthenticated) return true; //throw new System.Web.Http.HttpResponseException(HttpStatusCode.Unauthorized); return checkForAuthentication; } } // 其他代码... }
Web.Config 配置片段
system.identityModel 节点
<system.identityModel> <identityConfiguration> <claimsAuthorizationManager type="CGI_Automation_Framework.ClaimsManager.AuthorizationManager, CGI_Automation_Framework" /> </identityConfiguration> </system.identityModel>
WCF Behavior 节点
<behavior name="ControlPanelServiceBehavior"> <serviceMetadata httpGetEnabled="true" httpsGetEnabled="true" /> <serviceDebug includeExceptionDetailInFaults="true" /> </behavior>
WCF Binding 节点
<webHttpBinding> <binding name="DefaultBinding" maxReceivedMessageSize="7500000" maxBufferSize="7500000" maxBufferPoolSize="7500000"> </binding> </webHttpBinding>
WCF Service 节点
<service name="ControlPanelService.ControlPanelService" behaviorConfiguration="ControlPanelServiceBehavior"> <endpoint address="" binding="webHttpBinding" contract="ControlPanelService.IControlPanelService" behaviorConfiguration="jsonBehavior" bindingConfiguration="DefaultBinding"> <identity> <dns value="localhost" /> </identity> </endpoint> </service>
SVC 文件内容
<%@ ServiceHost Language="C#" Debug="true" Service="ControlPanelService.ControlPanelService" CodeBehind="ControlPanelService.ControlPanelService.cs" %>
问题解决方法
- 配置WCF使用ASP.NET身份同步
在WCF的behavior配置中添加serviceAuthorization节点,指定使用ASP.NET的身份体系:
<behavior name="ControlPanelServiceBehavior"> <serviceMetadata httpGetEnabled="true" httpsGetEnabled="true" /> <serviceDebug includeExceptionDetailInFaults="true" /> <serviceAuthorization principalPermissionMode="UseAspNetRoles" /> </behavior>
- 改用HttpContext获取身份
服务类中从HttpContext.Current.User获取ClaimsPrincipal,而非Thread.CurrentPrincipal:
public ControlPanelService() { var identity = (System.Security.Claims.ClaimsPrincipal)HttpContext.Current.User; this._tmtName = identity.GetClaimValue("tmtName"); }
- 强制启用AspNetCompatibility模式
将服务类的AspNetCompatibilityRequirementsMode改为Required,确保WCF完全依赖ASP.NET管道:
[AspNetCompatibilityRequirements(RequirementsMode = AspNetCompatibilityRequirementsMode.Required)]
- 延迟获取身份到服务方法
避免在构造函数中获取身份(WCF实例构造时身份可能未完全初始化),将逻辑移到具体服务方法中:
public YourServiceMethod() { var identity = (System.Security.Claims.ClaimsPrincipal)HttpContext.Current.User; this._tmtName = identity.GetClaimValue("tmtName"); // 业务逻辑 }
内容的提问来源于stack exchange,提问作者spyder1329
相关产品推荐
相关产品推荐

