1. 程式人生 > >WEBAPI使用過濾器對API接口進行驗證

WEBAPI使用過濾器對API接口進行驗證

anon log req code oid 是否 func parameter html

用戶登錄控制器:[ActionFilter]自定義過濾器

用戶信息:var userData = new JObject();
userData.Add("account", account);
userData.Add("password", password);
userData.Add("accountType",2);

生成用戶登錄的憑據:FormsAuthenticationTicket ticket = new FormsAuthenticationTicket(1, account, DateTime.Now, DateTime.Now.AddMinutes(10),
true, JsonConvert.SerializeObject(userData), FormsAuthentication.FormsCookiePath);

string ticString = FormsAuthentication.Encrypt(ticket);

設置AJAX請求的請求頭:內容為登錄時生成的憑證

$.ajax("/api/Supervisor/GetSupervisorList", {
method: "GET",
data: {
account: obj.account || "",
loginSession: obj.loginSession || "",
pageNo: obj.pageNo || 1,
keyword: obj.keyword || ""
},//heads: {Authorization: "Basic " + obj.loginSession},
beforeSend: function (xhr) {
//發送ajax請求之前向http的head裏面加入驗證信息
xhr.setRequestHeader(‘Authorization‘, ‘Basic ‘ + (obj.loginSession || ""));
}})

[ActionFilter]自定義過濾器:必須繼承ActionFilterAttribute

public class ActionFilter : ActionFilterAttribute
{
private string _requestId;

public override void OnActionExecuted(HttpActionExecutedContext actionExecutedContext)
{
base.OnActionExecuted(actionExecutedContext);
//獲取返回消息數據
var response =

actionExecutedContext.Response.Content.ReadAsAsync(
actionExecutedContext.ActionContext.ActionDescriptor.ReturnType);
}
public override void OnActionExecuting(HttpActionContext actionContext)
{
base.OnActionExecuting(actionContext);
var auther = actionContext.Request.Headers.Authorization;
if (actionContext.ActionDescriptor.GetCustomAttributes<AllowAnonymousAttribute>().Any())
{
return;
}
if (auther == null)
{
//actionContext.Response.ReasonPhrase = "登錄已過期,請重新登錄";
actionContext.Response = actionContext.Request.CreateResponse(HttpStatusCode.Unauthorized,
new {messages = "登錄已過期,請重新登錄", resultCode = 1});
//HttpContext.Current.Response.Redirect("~/Views/Home/Index.cshtml"); //跳到登陸頁面
}
else
{
if (auther.Scheme == "Basic" && !string.IsNullOrEmpty(auther.Parameter))
{
var userData = Functions.JudgeSession(auther.Parameter.Trim());
if (userData == null)
{
//actionContext.Response.ReasonPhrase = "登錄已過期,請重新登錄";
actionContext.Response = actionContext.Request.CreateResponse(HttpStatusCode.Unauthorized,
new { messages = "登錄已過期,請重新登錄", resultCode = 1 });
// HttpContext.Current.Response.Redirect("~/Views/Home/Index.cshtml"); //跳到登陸頁面
}
else
{

//修改API接口參數
actionContext.ActionArguments["account"] = userData.GetValue("account").ToString();
if (actionContext.ActionArguments.ContainsKey("accounType"))
{

actionContext.ActionArguments["account"] = userData.GetValue("accounType").ToString();
}

}
}
}}
}

解密登錄憑據,獲取用戶數據:

public static JObject JudgeSession(string sessionid) //判斷session是否過期
{
try
{

var formsAuthenticationTicket = FormsAuthentication.Decrypt(sessionid);
if (formsAuthenticationTicket == null)
{
return null;
}
if (formsAuthenticationTicket.Expired)
{
return null;
}
return JsonConvert.DeserializeObject<JObject>(formsAuthenticationTicket.UserData);
}
catch (Exception e)
{
return null;
}
}

WEBAPI使用過濾器對API接口進行驗證