扩展Wcf call security service, 手动添加 Soap Security Head.
有次我们有个项目需要Call 一个 Java 的 web service, Soap包中需要一个 Security Head
- <soapenv:Header>
- <wsse:Security soapenv:mustUnderstand="1" xmlns:wsse="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-secext-1.0.xsd">
- <wsse:UsernameToken xmlns:wsse="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-secext-1.0.xsd" wsu:Id="UsernameToken-1" xmlns:wsu="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-utility-1.0.xsd">
- <wsse:Username>username</wsse:Username>
- <wsse:Password Type="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-username-token-profile-1.0#PasswordText">password</wsse:Password>
- </wsse:UsernameToken>
- </wsse:Security>
- </soapenv:Header>
但是.net 默认的 Credentials 添加的 UserName 不符合这种格式
- orgClient.ClientCredentials.UserName.UserName = "userName";
- orgClient.ClientCredentials.UserName.Password = "password";
所以总是报错
System.Web.Services.Protocols.SoapHeaderException: An error was
discovered processing the <wsse: Security> header
没奈何,就只有用力气活,手动的把这段WSSE 的 head 添加到 Soap 包里面去了。
- orgClient.Endpoint.EndpointBehaviors.Add(new CustomEndpointBehavior());
下面是Behavior
- /// <summary>
- /// Represents a run-time behavior extension for a client endpoint.
- /// </summary>
- public class CustomEndpointBehavior : IEndpointBehavior
- {
- /// <summary>
- /// Implements a modification or extension of the client across an endpoint.
- /// </summary>
- /// <param name="endpoint">The endpoint that is to be customized.</param>
- /// <param name="clientRuntime">The client runtime to be customized.</param>
- public void ApplyClientBehavior(ServiceEndpoint endpoint, ClientRuntime clientRuntime)
- {
- clientRuntime.ClientMessageInspectors.Add(new ClientMessageInspector());
- }
- /// <summary>
- /// Implement to pass data at runtime to bindings to support custom behavior.
- /// </summary>
- /// <param name="endpoint">The endpoint to modify.</param>
- /// <param name="bindingParameters">The objects that binding elements require to support the behavior.</param>
- public void AddBindingParameters(ServiceEndpoint endpoint, BindingParameterCollection bindingParameters)
- {
- // Nothing special here
- }
- /// <summary>
- /// Implements a modification or extension of the service across an endpoint.
- /// </summary>
- /// <param name="endpoint">The endpoint that exposes the contract.</param>
- /// <param name="endpointDispatcher">The endpoint dispatcher to be modified or extended.</param>
- public void ApplyDispatchBehavior(ServiceEndpoint endpoint, EndpointDispatcher endpointDispatcher)
- {
- // Nothing special here
- }
- /// <summary>
- /// Implement to confirm that the endpoint meets some intended criteria.
- /// </summary>
- /// <param name="endpoint">The endpoint to validate.</param>
- public void Validate(ServiceEndpoint endpoint)
- {
- // Nothing special here
- }
- }
请注意13行红色部分的代码,相当于一层层的使用了Provider 的模式
- /// <summary>
- /// Represents a message inspector object that can be added to the <c>MessageInspectors</c> collection to view or modify messages.
- /// </summary>
- public class ClientMessageInspector : IClientMessageInspector
- {
- /// <summary>
- /// Enables inspection or modification of a message before a request message is sent to a service.
- /// </summary>
- /// <param name="request">The message to be sent to the service.</param>
- /// <param name="channel">The WCF client object channel.</param>
- /// <returns>
- /// The object that is returned as the <paramref name="correlationState " /> argument of
- /// the <see cref="M:System.ServiceModel.Dispatcher.IClientMessageInspector.AfterReceiveReply(System.ServiceModel.Channels.Message@,System.Object)" /> method.
- /// This is null if no correlation state is used.The best practice is to make this a <see cref="T:System.Guid" /> to ensure that no two
- /// <paramref name="correlationState" /> objects are the same.
- /// </returns>
- public object BeforeSendRequest(ref System.ServiceModel.Channels.Message request, IClientChannel channel)
- {
- SoapSecurityHeader header = new SoapSecurityHeader("UsernameToken-1", UserName, Password, "");
- request.Headers.Add(header);
- return header.Id;
- }
- /// <summary>
- /// Enables inspection or modification of a message after a reply message is received but prior to passing it back to the client application.
- /// </summary>
- /// <param name="reply">The message to be transformed into types and handed back to the client application.</param>
- /// <param name="correlationState">Correlation state data.</param>
- public void AfterReceiveReply(ref System.ServiceModel.Channels.Message reply, object correlationState)
- {
- var a = reply;
- // Nothing special here
- }
- }
下面是写入Head的部分
- public class SoapSecurityHeader : MessageHeader
- {
- private readonly string _password, _username, _nonce;
- private readonly DateTime _createdDate;
- public SoapSecurityHeader(string id, string username, string password, string nonce)
- {
- _password = password;
- _username = username;
- _nonce = nonce;
- _createdDate = DateTime.Now;
- this.Id = id;
- }
- public string Id { get; set; }
- public override string Name
- {
- get { return "Security"; }
- }
- public override string Namespace
- {
- get { return "http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-secext-1.0.xsd"; }
- }
- protected override void OnWriteStartHeader(XmlDictionaryWriter writer, MessageVersion messageVersion)
- {
- writer.WriteStartElement("wsse", Name, Namespace);
- writer.WriteXmlnsAttribute("wsse", Namespace);
- }
- protected override void OnWriteHeaderContents(XmlDictionaryWriter writer, MessageVersion messageVersion)
- {
- writer.WriteStartElement("wsse", "UsernameToken", Namespace);
- writer.WriteAttributeString("Id", "UsernameToken-10");
- writer.WriteAttributeString("wsu", "http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-utility-1.0.xsd");
- writer.WriteStartElement("wsse", "Username", Namespace);
- writer.WriteValue(_username);
- writer.WriteEndElement();
- writer.WriteStartElement("wsse", "Password", Namespace);
- writer.WriteAttributeString("Type", "http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-username-token-profile-1.0#PasswordText");
- writer.WriteValue(_password);
- writer.WriteEndElement();
- writer.WriteStartElement("wsse", "Nonce", Namespace);
- writer.WriteAttributeString("EncodingType", "http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-soap-message-security-1.0#Base64Binary");
- writer.WriteValue(_nonce);
- writer.WriteEndElement();
- writer.WriteStartElement("wsse", "Created", Namespace);
- writer.WriteValue(_createdDate.ToString("YYYY-MM-DDThh:mm:ss"));
- writer.WriteEndElement();
- writer.WriteEndElement();
- }
- }
至此大功告成!
扩展Wcf call security service, 手动添加 Soap Security Head.的更多相关文章
- WCF 在VS中,添加服务引用,地址输入http://ip/Service.svc,点击前往,提示错误,内容如下:
WCF的service端的webconfig如下: <?xml version="1.0"?> <configuration> <system.ser ...
- centos6.5 gsoap安装过程+ php添加soap扩展
参考博客: CentOS编译安装gSOAP Linux C实现webservice调用 安装gsoap流程 里面提到make时可能碰到的问题 还没有用到 1.从官网下载最新的版本:http://so ...
- wcf和web service的区别
1.WebService:严格来说是行业标准,不是技术,使用XML扩展标记语言来表示数据(这个是夸语言和平台的关键).微软的Web服务实现称为ASP.NET Web Service.它使用Soap简单 ...
- WCF和Web Service的 区(guan)别(xi)
参考文献:http://social.microsoft.com/Forums/zh-CN/c06420d1-69ba-4aa6-abe5-242e3213b68f/wcf-webservice 之前 ...
- WCF与 Web Service的区别是什么?各自的优点在哪里呢?
这是很多.NET开发人员容易搞错的问题.面试的时候也经常遇到,初学者也很难分快速弄明白 Web service: .net技术中其实就指ASP.NET Web Service,用的时间比较长,微软其实 ...
- 如何手动添加Windows服务和如何把一个服务删除
windows 手动添加服务方法一:修改注册表 在注册表编辑器,展开分支"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services" ...
- Windows服务的手动添加和删除方法
Windows服务的手动添加和删除方法 服务,是指执行指定系统功能的程序.例程或进程,以便支持其他程序,尤其是低层(接近硬件)程序.其实,服务就是一种特殊的应用程序,它从服务启动开始就一直处于运行状态 ...
- 解决 Cocos2d-x 中 Android.mk 手动添加源文件
转自:http://blog.csdn.net/ypfsoul/article/details/8909178 Makefile Android.mk 引发的思索 在我们编写 Android 平台 c ...
- Quartz动态添加定时任务执行sql(服务启动添加+手动添加)
系统用来每天插入视图数据... 一.数据库表设计 1.接口配置表(t_m_db_interface_config) 2.接口日志表(t_m_db_interface_log) 3.前端配置页面 查询页 ...
随机推荐
- ios 单例设计模式
单例模式的意思就是只有一个实例.单例模式确保某一个类只有一个实例,而且自行实例化并向整个系统提供这个实例.这个类称为单例类.单例可用性非常高,用于登录用户管理等可供全局调用. + (AccountMa ...
- Daily Scrum02 12.08
编译大作业的第一次检查终于过去了,已经经过这次检查的组员们可以暂时松一口气了. 也希望编译大作业有着落的成员可以多花一些时间在团队任务上,帮其他的组员多分担一些工作. 第一次没来的及检查的同学,或是没 ...
- css 设置圆角
CSS3 圆角(border-radius) -moz(例如 -moz-border-radius)用于Firefox -webkit(例如:-webkit-border-radius)用于Safar ...
- Java集合类源码学习- Iterabel<T>,Colection<E>,AbstractCollection<E>
Collection<E>接口extends Iteratable<E>接口. Iteratable<T>:实现接口使得对象能够成为“for-each loop”的 ...
- requirejs:研究笔记
模块化历史 模块化异步加载方式 后期维护 查找问题 复用代码 防止全局变量的污染 http://requirejs.cn/ http://requirejs.org/ 我的目录结构 总体步骤 < ...
- java并发容器类
本文主要介绍java并发容器相关实现类,collections节点下接口方法介绍. Queue Java提供的线程安全的Queue可以分为阻塞队列和非阻塞队列,其中阻塞队列的典型例子是Blocking ...
- Python 随机数生成总结
random.uniform(a, b),返回[a,b]之间的浮点数 random.randint(a, b),返回[a,b]之间的整数 random.randrange([start], stop[ ...
- Sony Z1 flashtool 刷机笔记
第一次硬刷,(相较于recovery的卡刷)差点变成无限重启..记录一些关键步骤: 1 unlock bootloader http://developer.sonymobile.com/unlock ...
- Xshell远程连接工具
下载地址:http://rj.baidu.com/soft/detail/15201.html?ald Xshell 是一个强大的安全终端模拟软件,它支持SSH1, SSH2, 以及Microsoft ...
- ncurses库的一些函数
为了实现一个简单的聊天程序,如果使用普通的输入输出函数,会很凌乱.so,便想着能不能用下 ncurses这个字符图形库 总结一下,就是这样. 使用ncurses时,先需要初始化窗口,程序结束时,主动调 ...