SecurityToken 類別
定義
重要
部分資訊涉及發行前產品,在發行之前可能會有大幅修改。 Microsoft 對此處提供的資訊,不做任何明確或隱含的瑕疵擔保。
代表一個用於實作所有安全權杖的基底類別。
public ref class SecurityToken abstract
public abstract class SecurityToken
type SecurityToken = class
Public MustInherit Class SecurityToken
- 繼承
-
SecurityToken
- 衍生
範例
主題中使用 SecurityToken 的程式碼範例取自範例 Custom Token 。 本範例提供自訂類別,使簡單網路令牌(SWT)能夠處理。 它包含一個類別和一個SimpleWebToken類別的實作SimpleWebTokenHandler,以及其他支援 SWT 標記的類別。 關於此範例及其他 WIF 範例的資訊,以及下載地點,請參閱 WIF 程式碼範例索引。 以下程式碼展示了該 SimpleWebToken 類別的實作。 此類別擴展 SecurityToken為 。
/// <summary>
/// Defines the set of constants for the Simple Web Token.
/// </summary>
public static class SimpleWebTokenConstants
{
public const string Audience = "Audience";
public const string ExpiresOn = "ExpiresOn";
public const string Id = "Id";
public const string Issuer = "Issuer";
public const string Signature = "HMACSHA256";
public const string ValidFrom = "ValidFrom";
public const string ValueTypeUri = "http://schemas.xmlsoap.org/ws/2009/11/swt-token-profile-1.0";
}
using System;
using System.Collections.Generic;
using System.Collections.ObjectModel;
using System.Collections.Specialized;
using System.IdentityModel.Tokens;
namespace SimpleWebToken
{
/// <summary>
/// This class represents the token format for the SimpleWebToken.
/// </summary>
public class SimpleWebToken : SecurityToken
{
public static DateTime SwtBaseTime = new DateTime( 1970, 1, 1, 0, 0, 0, 0 ); // per SWT psec
NameValueCollection _properties;
string _serializedToken;
/// <summary>
/// Initializes a new instance of the <see cref="SimpleWebToken"/> class.
/// This is an internal constructor that is only called from the <see cref="SimpleWebTokenHandler"/> when reading a token received from the wire.
/// </summary>
/// <param name="properties">The collection representing all the key value pairs in the token.</param>
/// <param name="serializedToken">The serialized form of the token.</param>
internal SimpleWebToken( NameValueCollection properties, string serializedToken )
: this(properties)
{
_serializedToken = serializedToken;
}
/// <summary>
/// Initializes a new instance of the <see cref="SimpleWebToken"/> class.
/// </summary>
/// <param name="properties">The collection representing all the key value pairs in the token.</param>
public SimpleWebToken( NameValueCollection properties )
{
if ( properties == null )
{
throw new ArgumentNullException( "properties" );
}
_properties = properties;
}
/// <summary>
/// Gets the Id of the token.
/// </summary>
/// <value>The Id of the token.</value>
public override string Id
{
get
{
return _properties[SimpleWebTokenConstants.Id];
}
}
/// <summary>
/// Gets the keys associated with this token.
/// </summary>
/// <value>The keys associated with this token.</value>
public override ReadOnlyCollection<SecurityKey> SecurityKeys
{
get
{
return new ReadOnlyCollection<SecurityKey>( new List<SecurityKey>() );
}
}
/// <summary>
/// Gets the time from when the token is valid.
/// </summary>
/// <value>The time from when the token is valid.</value>
public override DateTime ValidFrom
{
get
{
string validFrom = _properties[SimpleWebTokenConstants.ValidFrom];
return GetTimeAsDateTime( String.IsNullOrEmpty( validFrom ) ? "0" : validFrom );
}
}
/// <summary>
/// Gets the time when the token expires.
/// </summary>
/// <value>The time up to which the token is valid.</value>
public override DateTime ValidTo
{
get
{
string expiryTime = _properties[SimpleWebTokenConstants.ExpiresOn];
return GetTimeAsDateTime( String.IsNullOrEmpty( expiryTime ) ? "0" : expiryTime );
}
}
/// <summary>
/// Gets the Audience for the token.
/// </summary>
/// <value>The audience of the token.</value>
public string Audience
{
get
{
return _properties[SimpleWebTokenConstants.Audience];
}
}
/// <summary>
/// Gets the Issuer for the token.
/// </summary>
/// <value>The issuer for the token.</value>
public string Issuer
{
get
{
return _properties[SimpleWebTokenConstants.Issuer];
}
}
/// <summary>
/// Gets the signature for the token.
/// </summary>
/// <value>The signature for the token.</value>
public string Signature
{
get
{
return _properties[SimpleWebTokenConstants.Signature];
}
}
/// <summary>
/// Gets the serialized form of the token if the token was created from its serialized form by the token handler.
/// </summary>
/// <value>The serialized form of the token.</value>
public string SerializedToken
{
get
{
return _serializedToken;
}
}
/// <summary>
/// Creates a copy of all key value pairs of the token.
/// </summary>
/// <returns>A copy of all the key value pairs in the token.</returns>
public NameValueCollection GetAllProperties()
{
return new NameValueCollection( _properties );
}
/// <summary>
/// Converts the time in seconds to a <see cref="DateTime"/> object based on the base time
/// defined by the Simple Web Token.
/// </summary>
/// <param name="expiryTime">The time in seconds.</param>
/// <returns>The time as a <see cref="DateTime"/> object.</returns>
protected virtual DateTime GetTimeAsDateTime( string expiryTime )
{
long totalSeconds = 0;
if ( !long.TryParse( expiryTime, out totalSeconds ) )
{
throw new SecurityTokenException("Invalid expiry time. Expected the time to be in seconds passed from 1 January 1970.");
}
long maxSeconds = (long)( DateTime.MaxValue - SwtBaseTime ).TotalSeconds - 1;
if ( totalSeconds > maxSeconds )
{
totalSeconds = maxSeconds;
}
return SwtBaseTime.AddSeconds( totalSeconds );
}
}
}
備註
使用安全權杖來提供認證憑證或保護訊息。
安全憑證可用來提供認證憑證、密碼學金鑰資料,或在安全憑證服務(STS)發行的安全憑證的情況下,提供關於主題的一系列聲明。 所有安全權杖皆源自該 SecurityToken 類別。
從 .NET 4.5 開始,Windows 身份基礎(WIF)已完全整合進 .NET 框架,WIF 所暴露的類別成為處理程式碼中安全權杖的首選方法。 在 WIF 中,安全權杖會被序列化與反序列化,並透過從基底類別衍生 SecurityTokenHandler 的類別來驗證。 驗證令牌不僅是確保該令牌有效,還包括從 ClaimsIdentity 令牌中回傳一個實例,可用於進行認證與授權決策。 由 ClaimsIdentity 標記處理者 ValidateToken 根據標記中包含的權利要求以及憑證類型本身固有的聲明來構造該方法。
WIF 支援以下類型的安全代幣:
Saml2SecurityToken: 代表基於 SAML 2.0 斷言的安全性憑證。 這種令牌類型通常由安全令牌服務針對 WS-Trust 或 WS-Federation 安全令牌請求(RST)發出。
SamlSecurityToken:代表基於SAML 1.1斷言的安全性憑證。 這種令牌類型通常由安全令牌服務針對 WS-Trust 或 WS-Federation 安全令牌請求(RST)發出。
KerberosRequestorSecurityToken 以及 KerberosReceiverSecurityToken:代表基於 SOAP 訊息中接收或傳送的 Kerberos 工單的安全權杖
RsaSecurityToken代表基於使用 RSA 演算法建立的金鑰的安全性令牌。
SessionSecurityToken: 代表包含會話資訊的安全權杖。
UserNameSecurityToken: 代表基於使用者名稱與密碼的安全令牌。
WindowsSecurityToken:代表基於Windows網域或使用者帳號身份的安全憑證。
X509SecurityToken: 代表基於 X.509 憑證的安全憑證。
X509WindowsSecurityToken:代表基於映射到Windows域使用者或本地電腦使用者帳號的 X.509 憑證的安全憑證。
另外兩個安全令牌類別 GenericXmlSecurityTokenEncryptedSecurityToken和 ,也可用來協助處理一般情況。
大致而言,安全代幣可分為三大類:
攜帶或參考密碼密鑰材料的代幣。 例如, RsaSecurityToken 和 X509SecurityToken 類型常用於此目的。
代表已驗證用戶憑證的憑證。 例如,UserNameSecurityTokenWindowsSecurityToken, , ,以及在使用憑證認證的使用者情況下,類型X509SecurityToken。
由安全令牌服務(STS)根據安全令牌請求,使用 WS-Trust 或 WS-Federation 協議所發出的令牌。 這些通常以
wst:RequestSecurityTokenResponseXML 片段形式回傳。 Saml2SecurityToken和SamlSecurityToken類型最常用來表示這些標記。
一種特殊的標記類型 ,即 SessionSecurityToken,包含在主動或被動情境下使用會話時,重建主體所需的資訊。
要為現有的代幣類型增加功能,你可以從該特定類型及其對應的代幣處理器衍生出來,以支援你新增到代幣中的元素。 若要新增代幣類型,可以直接從 SecurityToken 該類別衍生。 在這麼做時,你還需要從該 SecurityTokenHandler 類別衍生出一個標記處理類別。 根據你的 token 用途,你可能還需要從類別衍生 IssuerTokenResolver 出一個自訂的 token 解析器,以及從類別衍生 SecurityKeyIdentifierClause 出一個或多個自訂的金鑰識別子句類型。
給實施者的注意事項
你必須覆寫 Id、 SecurityKeys、 ValidFrom和 ValidTo 屬性。 這些 CanCreateKeyIdentifierClause<T>()、 CreateKeyIdentifierClause<T>()、 MatchesKeyIdentifierClause(SecurityKeyIdentifierClause)和 ResolveKeyIdentifierClause(SecurityKeyIdentifierClause) 方法都支援型別 LocalIdKeyIdentifierClause為 的金鑰識別碼。 您必須覆寫這些方法,以支援衍生類別中的其他金鑰識別碼類型。
建構函式
| 名稱 | Description |
|---|---|
| SecurityToken() |
由衍生類別中的建構函式呼叫,以初始化 SecurityToken 類別。 |
屬性
| 名稱 | Description |
|---|---|
| Id |
取得安全憑證的唯一識別碼。 |
| SecurityKeys |
取得與安全令牌相關的密碼金鑰。 |
| ValidFrom |
取得該安全令牌有效的第一個時刻。 |
| ValidTo |
取得該安全令牌有效的最後一刻。 |
方法
| 名稱 | Description |
|---|---|
| CanCreateKeyIdentifierClause<T>() |
會獲得一個值,表示此安全權杖是否能產生指定的金鑰識別碼。 |
| CreateKeyIdentifierClause<T>() |
建立指定的金鑰識別子句。 |
| Equals(Object) |
判斷指定的物件是否等於目前的物件。 (繼承來源 Object) |
| GetHashCode() |
做為預設哈希函式。 (繼承來源 Object) |
| GetType() |
取得目前實例的 Type。 (繼承來源 Object) |
| MatchesKeyIdentifierClause(SecurityKeyIdentifierClause) |
回傳一個值,指示該實例的金鑰識別碼是否能解析為指定的金鑰識別碼。 |
| MemberwiseClone() |
建立目前 Object的淺層複本。 (繼承來源 Object) |
| ResolveKeyIdentifierClause(SecurityKeyIdentifierClause) |
取得指定的金鑰識別子句的金鑰。 |
| ToString() |
傳回表示目前 物件的字串。 (繼承來源 Object) |