AuthorizationContext Clase

Definición

El resultado de evaluar todas las directivas de autorización disponibles de los tokens en el mensaje enviado y llamando al método GetAuthorizationPolicies(OperationContext).The result of evaluating all authorization policies available from the tokens in the sent message and by calling the GetAuthorizationPolicies(OperationContext) method.

public ref class AuthorizationContext abstract : System::IdentityModel::Policy::IAuthorizationComponent
public abstract class AuthorizationContext : System.IdentityModel.Policy.IAuthorizationComponent
type AuthorizationContext = class
    interface IAuthorizationComponent
Public MustInherit Class AuthorizationContext
Implements IAuthorizationComponent
Herencia
AuthorizationContext
Implementaciones

Ejemplos

protected override bool CheckAccessCore(OperationContext operationContext)
{
    // Extract the action URI from the OperationContext. Match this against the claims
    // in the AuthorizationContext.
    string action = operationContext.RequestContext.RequestMessage.Headers.Action;
    Console.WriteLine("action: {0}", action);

    // Iterate through the various claim sets in the AuthorizationContext.
    foreach(ClaimSet cs in operationContext.ServiceSecurityContext.AuthorizationContext.ClaimSets)
    {
        // Examine only those claim sets issued by System.
        if (cs.Issuer == ClaimSet.System)
        {
            // Iterate through claims of type "http://example.org/claims/allowedoperation".
            foreach (Claim c in cs.FindClaims("http://example.org/claims/allowedoperation", Rights.PossessProperty))
            {
                // Write the Claim resource to the console.
                Console.WriteLine("resource: {0}", c.Resource.ToString());

                // If the Claim resource matches the action URI then return true to allow access.
                if (action == c.Resource.ToString())
                    return true;
            }
        }
    }

    // If this point is reached, return false to deny access.
    return false;
}
Protected Overrides Function CheckAccessCore(ByVal operationContext As OperationContext) As Boolean
    ' Extract the action URI from the OperationContext. Match this against the claims
    ' in the AuthorizationContext.
    Dim action As String = operationContext.RequestContext.RequestMessage.Headers.Action
    Console.WriteLine("action: {0}", action)

    ' Iterate through the various claim sets in the AuthorizationContext.
    Dim cs As ClaimSet
    For Each cs In operationContext.ServiceSecurityContext.AuthorizationContext.ClaimSets
        ' Examine only those claim sets issued by System.
        If cs.Issuer Is ClaimSet.System Then
            ' Iterate through claims of type "http://example.org/claims/allowedoperation".
            Dim c As Claim
            For Each c In cs.FindClaims("http://example.org/claims/allowedoperation", Rights.PossessProperty)
                ' Write the Claim resource to the console.
                Console.WriteLine("resource: {0}", c.Resource.ToString())

                ' If the Claim resource matches the action URI then return true to allow access.
                If action = c.Resource.ToString() Then
                    Return True
                End If
            Next c
        End If
    Next cs
    ' If we get here, return false, denying access.
    Return False

End Function 

Comentarios

Evaluar todas las directivas de autorización en un administrador de autorización da lugar a un conjunto de objetos ClaimSet.Evaluating all of the authorization policies in an authorization manager results in a set of ClaimSet objects. Estos objetos constituyen un contexto de autorización.These objects make up an authorization context.

Un contexto de autorización contiene un conjunto de objetos fijos de demanda, una hora de expiración que especifica la duración en la que el contexto de autorización es válido y un identificador único.An authorization context contains a set of claim set objects, an expiration time that specifies the span of time during which the authorization context is valid, and a unique identifier.

Se puede tener acceso a AuthorizationContext para la operación actual a través de la propiedad AuthorizationContext.The AuthorizationContext for the current operation can be accessed via the AuthorizationContext property.

Constructores

AuthorizationContext()

Inicializa una nueva instancia de la clase AuthorizationContext.Initializes a new instance of the AuthorizationContext class.

Propiedades

ClaimSets

Obtiene el conjunto de demandas asociado a una directiva de autorización.Gets the set of claims associated with an authorization policy.

ExpirationTime

Obtiene la fecha y hora en las que AuthorizationContext ya no es válido.Gets the date and time at which this AuthorizationContext object is no longer valid.

Id

Obtiene un identificador único para este objeto AuthorizationContext.Gets a unique identifier for this AuthorizationContext object.

Properties

Obtiene una colección de propiedades de no demanda asociada a este objeto AuthorizationContext.Gets a collection of non-claim properties associated with this AuthorizationContext object.

Métodos

CreateDefaultAuthorizationContext(IList<IAuthorizationPolicy>)

Evalúe todas las directivas de autorización especificadas y cree un AuthorizationContext.Evaluate all of the specified authorization policies and create an AuthorizationContext.

Equals(Object)

Determina si el objeto especificado es igual que el objeto actual.Determines whether the specified object is equal to the current object.

(Heredado de Object)
GetHashCode()

Sirve como la función hash predeterminada.Serves as the default hash function.

(Heredado de Object)
GetType()

Obtiene el Type de la instancia actual.Gets the Type of the current instance.

(Heredado de Object)
MemberwiseClone()

Crea una copia superficial del Object actual.Creates a shallow copy of the current Object.

(Heredado de Object)
ToString()

Devuelve una cadena que representa el objeto actual.Returns a string that represents the current object.

(Heredado de Object)

Se aplica a