AuthenticationBehavior.cs 6.0 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141
  1. //-----------------------------------------------------------------------------
  2. // Copyright (c) Microsoft Corporation. All rights reserved.
  3. //-----------------------------------------------------------------------------
  4. namespace System.ServiceModel.Dispatcher
  5. {
  6. using System;
  7. using System.Collections.Generic;
  8. using System.Linq;
  9. using System.Text;
  10. using System.Runtime.CompilerServices;
  11. using System.Messaging;
  12. using System.ServiceModel.Security;
  13. using System.Collections.ObjectModel;
  14. using System.IdentityModel.Policy;
  15. using System.Runtime;
  16. using System.ServiceModel.Diagnostics;
  17. using System.Diagnostics;
  18. using System.Globalization;
  19. sealed class AuthenticationBehavior
  20. {
  21. ServiceAuthenticationManager serviceAuthenticationManager;
  22. AuditLogLocation auditLogLocation;
  23. bool suppressAuditFailure;
  24. AuditLevel messageAuthenticationAuditLevel;
  25. AuthenticationBehavior(ServiceAuthenticationManager authenticationManager)
  26. {
  27. this.serviceAuthenticationManager = authenticationManager;
  28. }
  29. public void Authenticate(ref MessageRpc rpc)
  30. {
  31. SecurityMessageProperty security = SecurityMessageProperty.GetOrCreate(rpc.Request);
  32. ReadOnlyCollection<IAuthorizationPolicy> authPolicy = security.ServiceSecurityContext.AuthorizationPolicies;
  33. try
  34. {
  35. authPolicy = this.serviceAuthenticationManager.Authenticate(security.ServiceSecurityContext.AuthorizationPolicies, rpc.Channel.ListenUri, ref rpc.Request);
  36. if (authPolicy == null)
  37. {
  38. throw DiagnosticUtility.ExceptionUtility.ThrowHelperError(new InvalidOperationException(SR.GetString(SR.AuthenticationManagerShouldNotReturnNull)));
  39. }
  40. }
  41. catch (Exception ex)
  42. {
  43. if (Fx.IsFatal(ex))
  44. {
  45. throw;
  46. }
  47. if (PerformanceCounters.PerformanceCountersEnabled)
  48. {
  49. PerformanceCounters.AuthenticationFailed(rpc.Request, rpc.Channel.ListenUri);
  50. }
  51. if (AuditLevel.Failure == (this.messageAuthenticationAuditLevel & AuditLevel.Failure))
  52. {
  53. try
  54. {
  55. string primaryIdentity;
  56. AuthorizationContext authContext = security.ServiceSecurityContext.AuthorizationContext;
  57. if (authContext != null)
  58. {
  59. primaryIdentity = SecurityUtils.GetIdentityNamesFromContext(authContext);
  60. }
  61. else
  62. {
  63. primaryIdentity = SecurityUtils.AnonymousIdentity.Name;
  64. }
  65. SecurityAuditHelper.WriteMessageAuthenticationFailureEvent(this.auditLogLocation,
  66. this.suppressAuditFailure, rpc.Request, rpc.Channel.ListenUri, rpc.Request.Headers.Action,
  67. primaryIdentity, ex);
  68. }
  69. #pragma warning suppress 56500
  70. catch (Exception auditException)
  71. {
  72. if (Fx.IsFatal(auditException))
  73. throw;
  74. DiagnosticUtility.TraceHandledException(auditException, TraceEventType.Error);
  75. }
  76. }
  77. throw DiagnosticUtility.ExceptionUtility.ThrowHelperError(CreateFailedAuthenticationFaultException());
  78. }
  79. rpc.Request.Properties.Security.ServiceSecurityContext.AuthorizationPolicies = authPolicy;
  80. if (AuditLevel.Success == (this.messageAuthenticationAuditLevel & AuditLevel.Success))
  81. {
  82. string primaryIdentity;
  83. AuthorizationContext authContext = security.ServiceSecurityContext.AuthorizationContext;
  84. if (authContext != null)
  85. {
  86. primaryIdentity = SecurityUtils.GetIdentityNamesFromContext(authContext);
  87. }
  88. else
  89. {
  90. primaryIdentity = SecurityUtils.AnonymousIdentity.Name;
  91. }
  92. SecurityAuditHelper.WriteMessageAuthenticationSuccessEvent(this.auditLogLocation,
  93. this.suppressAuditFailure, rpc.Request, rpc.Channel.ListenUri, rpc.Request.Headers.Action,
  94. primaryIdentity);
  95. }
  96. }
  97. [MethodImpl(MethodImplOptions.NoInlining)]
  98. static AuthenticationBehavior CreateAuthenticationBehavior(DispatchRuntime dispatch)
  99. {
  100. AuthenticationBehavior authenticationBehavior = new AuthenticationBehavior(dispatch.ServiceAuthenticationManager);
  101. authenticationBehavior.auditLogLocation = dispatch.SecurityAuditLogLocation;
  102. authenticationBehavior.suppressAuditFailure = dispatch.SuppressAuditFailure;
  103. authenticationBehavior.messageAuthenticationAuditLevel = dispatch.MessageAuthenticationAuditLevel;
  104. return authenticationBehavior;
  105. }
  106. public static AuthenticationBehavior TryCreate(DispatchRuntime dispatch)
  107. {
  108. if (dispatch == null)
  109. throw DiagnosticUtility.ExceptionUtility.ThrowHelperArgumentNull("dispatch");
  110. if (!dispatch.RequiresAuthentication)
  111. return null;
  112. return CreateAuthenticationBehavior(dispatch);
  113. }
  114. internal static Exception CreateFailedAuthenticationFaultException()
  115. {
  116. // always use default version?
  117. SecurityVersion wss = SecurityVersion.Default;
  118. FaultCode faultCode = FaultCode.CreateSenderFaultCode(wss.InvalidSecurityFaultCode.Value, wss.HeaderNamespace.Value);
  119. FaultReason faultReason = new FaultReason(SR.GetString(SR.AuthenticationOfClientFailed), CultureInfo.CurrentCulture);
  120. return new FaultException(faultReason, faultCode);
  121. }
  122. }
  123. }