You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Blazor Server Side如何使用用户模拟访问文件服务器受限文件夹

Blazor Server端模拟AD用户访问受限文件夹实现方案

原有方案迁移适配

你之前在.NET Framework中使用LogonUser API模拟AD用户的逻辑可以直接迁移到Blazor Server端使用,仅需做少量适配:

  • 安装NuGet包 System.Security.Principal.Windows,该包提供了.NET Core/.NET 5+环境下的Windows身份相关类
  • 配置读取从原来的ConfigurationManager.AppSettings替换为ASP.NET Core注入的IConfiguration接口
  • 模拟逻辑推荐使用更安全的WindowsIdentity.RunImpersonated方法替代原来的Impersonate接口

适配后代码示例

P/Invoke定义

using System.Runtime.InteropServices;
using Microsoft.Win32.SafeHandles;

[DllImport("advapi32.dll", SetLastError = true, CharSet = CharSet.Unicode)]
public static extern bool LogonUser(string lpszUsername, string lpszDomain, string lpszPassword, int dwLogonType, int dwLogonProvider, out SafeAccessTokenHandle phToken);

[DllImport("kernel32.dll", CharSet = CharSet.Auto)]
public extern static bool CloseHandle(IntPtr handle);

组件按钮点击逻辑

// 组件顶部注入配置服务
[Inject] private IConfiguration Config { get; set; }

private async Task HandleFileUpload()
{
    const int LOGON32_PROVIDER_DEFAULT = 0;
    const int LOGON32_LOGON_INTERACTIVE = 2;
    
    // 调用LogonUser获取服务账号令牌
    bool logonSuccess = LogonUser(
        Config["CMU"], 
        "<你的域名称>", 
        Config["CMP"], 
        LOGON32_LOGON_INTERACTIVE, 
        LOGON32_PROVIDER_DEFAULT, 
        out var safeTokenHandle);
    
    if (!logonSuccess)
    {
        // 处理登录失败逻辑,抛出异常可获取具体错误码
        throw new System.ComponentModel.Win32Exception(Marshal.GetLastWin32Error());
    }

    using (safeTokenHandle)
    {
        // 模拟服务账号执行文件操作
        WindowsIdentity.RunImpersonated(safeTokenHandle, () =>
        {
            // 此处直接放入原来的文件操作逻辑即可
            string fileExt = Path.GetExtension(uploadedFile.Name).TrimStart('.').ToUpper();
            string contentType = uploadedFile.ContentType;
            string baseFilePath = Config["ClaimsDocumentFilePath"];
            string fullFilePath = Path.Combine(baseFilePath, ddlMVA.SelectedItem.Text, txtPkgNumber.Text.Trim());
            filePath = fullFilePath;
            
            if (!Directory.Exists(fullFilePath))
            {
                Directory.CreateDirectory(fullFilePath);
            }
            // 文件保存等后续操作都放在这个作用域内即可
        });
    }
}

关于你提到的官方文档说明

你提到的Windows身份验证文档适用于需要以当前登录Blazor应用的Windows用户自身权限访问资源的场景:如果你的业务需求是跟随当前登录用户的权限访问受限文件夹,不需要固定用某个服务账号操作,就可以参考该文档开启Windows身份验证,无需手动调用LogonUser传入账号密码,直接获取当前登录用户的身份模拟即可。

安全注意事项

  • AD账号密码禁止明文存储在配置文件中,生产环境建议使用ASP.NET Core机密管理器、云密钥保管库或者Windows凭据管理器存储敏感配置,避免账号泄露
  • 模拟作用域结束后会自动释放身份上下文,不要把模拟后的身份对象传出作用域使用

内容的提问来源于stack exchange,提问作者jnelson

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.10.05 14:06:03