語言

RequiredScopeAttribute 建構函式

定義

多載

名稱 Description
RequiredScopeAttribute()

預設建構函式。

RequiredScopeAttribute(String[])

驗證網頁 API 是否以正確的範圍呼叫。 若該 API 所取得的權杖代表已認證使用者,且其作用域主張中沒有這些 acceptedScopes ,該方法會更新 HTTP 回應,提供狀態碼 403(禁止),並寫入訊息給回應主體,告知該令牌預期包含哪些範圍。

RequiredScopeAttribute()

預設建構函式。

public RequiredScopeAttribute();
Public Sub New ()

範例

[RequiredScope(RequiredScopesConfigurationKey="AzureAD:Scope")]
class Controller : BaseController
{
}

適用於

RequiredScopeAttribute(String[])

驗證網頁 API 是否以正確的範圍呼叫。 若該 API 所取得的權杖代表已認證使用者,且其作用域主張中沒有這些 acceptedScopes ,該方法會更新 HTTP 回應,提供狀態碼 403(禁止),並寫入訊息給回應主體,告知該令牌預期包含哪些範圍。

public RequiredScopeAttribute(params string[] acceptedScopes);
new Microsoft.Identity.Web.Resource.RequiredScopeAttribute : string[] -> Microsoft.Identity.Web.Resource.RequiredScopeAttribute
Public Sub New (ParamArray acceptedScopes As String())

參數

acceptedScopes
String[]

此網頁 API 允許的範圍。

範例

在控制器/頁面/動作上新增以下屬性以保護:

[RequiredScope("access_as_user")]

備註

當範圍不匹配時,回應是 403(禁止),因為使用者已認證(因此不是 401),但未授權。

另請參閱

  • <xref:RequiredScopeAttribute()>

適用於