SecurityRequestChannel.cs 4.6 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148
  1. //
  2. // SecurityRequestChannel.cs
  3. //
  4. // Author:
  5. // Atsushi Enomoto <[email protected]>
  6. //
  7. // Copyright (C) 2006 Novell, Inc (http://www.novell.com)
  8. //
  9. // Permission is hereby granted, free of charge, to any person obtaining
  10. // a copy of this software and associated documentation files (the
  11. // "Software"), to deal in the Software without restriction, including
  12. // without limitation the rights to use, copy, modify, merge, publish,
  13. // distribute, sublicense, and/or sell copies of the Software, and to
  14. // permit persons to whom the Software is furnished to do so, subject to
  15. // the following conditions:
  16. //
  17. // The above copyright notice and this permission notice shall be
  18. // included in all copies or substantial portions of the Software.
  19. //
  20. // THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND,
  21. // EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF
  22. // MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND
  23. // NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE
  24. // LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION
  25. // OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION
  26. // WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.
  27. //
  28. using System;
  29. using System.Collections.Generic;
  30. using System.Collections.ObjectModel;
  31. using System.IdentityModel.Selectors;
  32. using System.IdentityModel.Tokens;
  33. using System.Runtime.Serialization;
  34. using System.Security.Cryptography;
  35. using System.Security.Cryptography.X509Certificates;
  36. using System.Security.Cryptography.Xml;
  37. using System.ServiceModel;
  38. using System.ServiceModel.Channels;
  39. using System.ServiceModel.Description;
  40. using System.ServiceModel.Security;
  41. using System.ServiceModel.Security.Tokens;
  42. using System.Xml;
  43. using System.Xml.XPath;
  44. using ReqType = System.ServiceModel.Security.Tokens.ServiceModelSecurityTokenRequirement;
  45. namespace System.ServiceModel.Channels.Security
  46. {
  47. interface ISecurityChannelSource
  48. {
  49. MessageSecurityBindingSupport Support { get; }
  50. }
  51. class SecurityRequestChannel : SecurityRequestChannelBase
  52. {
  53. SecurityChannelFactory<IRequestChannel> source;
  54. public SecurityRequestChannel (IRequestChannel innerChannel, SecurityChannelFactory<IRequestChannel> source)
  55. : base (innerChannel)
  56. {
  57. this.source = source;
  58. InitializeSecurityFunctionality (source.SecuritySupport);
  59. }
  60. public override ChannelFactoryBase Factory {
  61. get { return source; }
  62. }
  63. }
  64. class SecurityRequestSessionChannel : SecurityRequestChannelBase
  65. {
  66. SecurityChannelFactory<IRequestSessionChannel> source;
  67. public SecurityRequestSessionChannel (IRequestSessionChannel innerChannel, SecurityChannelFactory<IRequestSessionChannel> source)
  68. : base (innerChannel)
  69. {
  70. this.source = source;
  71. InitializeSecurityFunctionality (source.SecuritySupport);
  72. }
  73. public override ChannelFactoryBase Factory {
  74. get { return source; }
  75. }
  76. }
  77. abstract class SecurityRequestChannelBase : LayeredRequestChannel
  78. {
  79. InitiatorMessageSecurityBindingSupport security;
  80. protected SecurityRequestChannelBase (IRequestChannel innerChannel)
  81. : base (innerChannel)
  82. {
  83. Opened += new EventHandler (AcquireSecurityKey);
  84. Closing += new EventHandler (ReleaseSecurityKey);
  85. }
  86. protected void InitializeSecurityFunctionality (InitiatorMessageSecurityBindingSupport security)
  87. {
  88. this.security = security;
  89. }
  90. SecurityMessageProperty secprop;
  91. protected override IAsyncResult OnBeginRequest (Message message, TimeSpan timeout, AsyncCallback callback, object state)
  92. {
  93. // FIXME: make it really async
  94. Message secure = SecureMessage (message);
  95. secprop = secure.Properties.Security;
  96. return base.BeginRequest (secure, timeout, callback, state);
  97. }
  98. protected override Message OnEndRequest (IAsyncResult result)
  99. {
  100. // FIXME: it must be also asynchronized.
  101. Message raw = base.EndRequest (result);
  102. return ProcessReply (raw, secprop);
  103. }
  104. protected override Message OnRequest (Message message, TimeSpan timeout)
  105. {
  106. Message secure = SecureMessage (message);
  107. Message raw = base.OnRequest (secure, timeout);
  108. return ProcessReply (raw, secure.Properties.Security);
  109. }
  110. Message SecureMessage (Message msg)
  111. {
  112. return new InitiatorMessageSecurityGenerator (msg, security, RemoteAddress).SecureMessage ();
  113. }
  114. Message ProcessReply (Message message, SecurityMessageProperty secprop)
  115. {
  116. // FIXME: provide correct parameters
  117. return message.IsFault ? message : new InitiatorSecureMessageDecryptor (message, secprop, security).DecryptMessage ();
  118. }
  119. void AcquireSecurityKey (object o, EventArgs e)
  120. {
  121. security.Prepare (Factory, RemoteAddress);
  122. }
  123. void ReleaseSecurityKey (object o, EventArgs e)
  124. {
  125. security.Release ();
  126. }
  127. }
  128. }