AuthorizationConfigHandler.cs 3.1 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100
  1. //
  2. // System.Web.Configuration.AuthorizationConfigHandler
  3. //
  4. // Authors:
  5. // Gonzalo Paniagua Javier ([email protected])
  6. //
  7. // (C) 2003 Ximian, Inc (http://www.ximian.com)
  8. //
  9. //
  10. // Permission is hereby granted, free of charge, to any person obtaining
  11. // a copy of this software and associated documentation files (the
  12. // "Software"), to deal in the Software without restriction, including
  13. // without limitation the rights to use, copy, modify, merge, publish,
  14. // distribute, sublicense, and/or sell copies of the Software, and to
  15. // permit persons to whom the Software is furnished to do so, subject to
  16. // the following conditions:
  17. //
  18. // The above copyright notice and this permission notice shall be
  19. // included in all copies or substantial portions of the Software.
  20. //
  21. // THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND,
  22. // EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF
  23. // MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND
  24. // NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE
  25. // LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION
  26. // OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION
  27. // WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.
  28. //
  29. using System;
  30. using System.Collections;
  31. using System.Configuration;
  32. using System.Xml;
  33. namespace System.Web.Configuration
  34. {
  35. class AuthorizationConfigHandler : IConfigurationSectionHandler
  36. {
  37. public object Create (object parent, object context, XmlNode section)
  38. {
  39. AuthorizationConfig config = new AuthorizationConfig (parent);
  40. if (section.Attributes != null && section.Attributes.Count != 0)
  41. ThrowException ("Unrecognized attribute", section);
  42. XmlNodeList authNodes = section.ChildNodes;
  43. foreach (XmlNode child in authNodes) {
  44. XmlNodeType ntype = child.NodeType;
  45. if (ntype != XmlNodeType.Element)
  46. continue;
  47. string childName = child.Name;
  48. bool allow = (childName == "allow");
  49. bool deny = (childName == "deny");
  50. if (!allow && !deny)
  51. ThrowException ("Element name must be 'allow' or 'deny'.", child);
  52. string users = AttValue ("users", child);
  53. string roles = AttValue ("roles", child);
  54. if (users == null && roles == null)
  55. ThrowException ("At least 'users' or 'roles' must be present.", child);
  56. string verbs = AttValue ("verbs", child);
  57. if (child.Attributes != null && child.Attributes.Count != 0)
  58. ThrowException ("Unrecognized attribute.", child);
  59. bool added;
  60. if (allow)
  61. added = config.Allow (users, roles, verbs);
  62. else
  63. added = config.Deny (users, roles, verbs);
  64. if (!added)
  65. ThrowException ("User and role names cannot contain '?' or '*'.", child);
  66. }
  67. return config;
  68. }
  69. // A few methods to save some typing
  70. static string AttValue (string name, XmlNode node, bool optional)
  71. {
  72. return HandlersUtil.ExtractAttributeValue (name, node, optional);
  73. }
  74. static string AttValue (string name, XmlNode node)
  75. {
  76. return HandlersUtil.ExtractAttributeValue (name, node, true);
  77. }
  78. static void ThrowException (string message, XmlNode node)
  79. {
  80. HandlersUtil.ThrowException (message, node);
  81. }
  82. //
  83. }
  84. }