Skip to content
This repository was archived by the owner on Dec 13, 2018. It is now read-only.

Commit a249cbb

Browse files
author
Praburaj Thiagarajan
committed
Merge pull request #137 from brentschmaltz/release
ChallengeContext will be null with [Authorize] attribute
2 parents f9d3f6f + 3483842 commit a249cbb

File tree

3 files changed

+159
-8
lines changed

3 files changed

+159
-8
lines changed

src/Microsoft.AspNet.Security.OpenIdConnect/OpenidConnectAuthenticationHandler.cs

Lines changed: 22 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -91,15 +91,17 @@ protected override async Task ApplyResponseGrantAsync()
9191
{
9292
ProtocolMessage = openIdConnectMessage
9393
};
94+
9495
await Options.Notifications.RedirectToIdentityProvider(notification);
9596

9697
if (!notification.HandledResponse)
9798
{
9899
string redirectUri = notification.ProtocolMessage.CreateLogoutRequestUrl();
99100
if (!Uri.IsWellFormedUriString(redirectUri, UriKind.Absolute))
100101
{
101-
_logger.WriteWarning("The logout redirect URI is malformed: " + redirectUri);
102+
_logger.WriteWarning("The logout redirect URI is malformed: {0}", (redirectUri ?? "null"));
102103
}
104+
103105
Response.Redirect(redirectUri);
104106
}
105107
}
@@ -116,15 +118,30 @@ protected override void ApplyResponseChallenge()
116118
/// <returns></returns>
117119
protected override async Task ApplyResponseChallengeAsync()
118120
{
119-
if ((Response.StatusCode != 401) || (ChallengeContext == null))
121+
if (Response.StatusCode != 401)
122+
{
123+
return;
124+
}
125+
126+
// Active middleware should redirect on 401 even if there wasn't an explicit challenge.
127+
if (ChallengeContext == null && Options.AuthenticationMode == AuthenticationMode.Passive)
120128
{
121129
return;
122130
}
123131

124132
// order for redirect_uri
125133
// 1. challenge.Properties.RedirectUri
126134
// 2. CurrentUri
127-
AuthenticationProperties properties = new AuthenticationProperties(ChallengeContext.Properties);
135+
AuthenticationProperties properties;
136+
if (ChallengeContext == null)
137+
{
138+
properties = new AuthenticationProperties();
139+
}
140+
else
141+
{
142+
properties = new AuthenticationProperties(ChallengeContext.Properties);
143+
}
144+
128145
if (string.IsNullOrEmpty(properties.RedirectUri))
129146
{
130147
properties.RedirectUri = CurrentUri;
@@ -154,7 +171,6 @@ protected override async Task ApplyResponseChallengeAsync()
154171
State = OpenIdConnectAuthenticationDefaults.AuthenticationPropertiesKey + "=" + Uri.EscapeDataString(Options.StateDataFormat.Protect(properties))
155172
};
156173

157-
// TODO - brentschmaltz, if INonceCache is set should we even consider if ProtocolValidator is set?
158174
if (Options.ProtocolValidator.RequireNonce)
159175
{
160176
openIdConnectMessage.Nonce = Options.ProtocolValidator.GenerateNonce();
@@ -179,7 +195,7 @@ protected override async Task ApplyResponseChallengeAsync()
179195
string redirectUri = notification.ProtocolMessage.CreateAuthenticationRequestUrl();
180196
if (!Uri.IsWellFormedUriString(redirectUri, UriKind.Absolute))
181197
{
182-
_logger.WriteWarning("The authenticate redirect URI is malformed: " + redirectUri);
198+
_logger.WriteWarning("Uri.IsWellFormedUriString(redirectUri, UriKind.Absolute) returned 'false', redirectUri is: {0}", (redirectUri ?? "null"));
183199
}
184200

185201
Response.Redirect(redirectUri);
@@ -327,7 +343,7 @@ protected override async Task<AuthenticationTicket> AuthenticateCoreAsync()
327343
throw new InvalidOperationException("No SecurityTokenValidator found for token: " + openIdConnectMessage.IdToken);
328344
}
329345

330-
ticket = new AuthenticationTicket(principal, properties, Options.AuthenticationType);
346+
ticket = new AuthenticationTicket(principal.Identity as ClaimsIdentity, properties);
331347
if (!string.IsNullOrWhiteSpace(openIdConnectMessage.SessionState))
332348
{
333349
ticket.Properties.Dictionary[OpenIdConnectSessionProperties.SessionState] = openIdConnectMessage.SessionState;
Lines changed: 132 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,132 @@
1+
<?xml version="1.0" encoding="utf-8"?>
2+
<root>
3+
<!--
4+
Microsoft ResX Schema
5+
6+
Version 2.0
7+
8+
The primary goals of this format is to allow a simple XML format
9+
that is mostly human readable. The generation and parsing of the
10+
various data types are done through the TypeConverter classes
11+
associated with the data types.
12+
13+
Example:
14+
15+
... ado.net/XML headers & schema ...
16+
<resheader name="resmimetype">text/microsoft-resx</resheader>
17+
<resheader name="version">2.0</resheader>
18+
<resheader name="reader">System.Resources.ResXResourceReader, System.Windows.Forms, ...</resheader>
19+
<resheader name="writer">System.Resources.ResXResourceWriter, System.Windows.Forms, ...</resheader>
20+
<data name="Name1"><value>this is my long string</value><comment>this is a comment</comment></data>
21+
<data name="Color1" type="System.Drawing.Color, System.Drawing">Blue</data>
22+
<data name="Bitmap1" mimetype="application/x-microsoft.net.object.binary.base64">
23+
<value>[base64 mime encoded serialized .NET Framework object]</value>
24+
</data>
25+
<data name="Icon1" type="System.Drawing.Icon, System.Drawing" mimetype="application/x-microsoft.net.object.bytearray.base64">
26+
<value>[base64 mime encoded string representing a byte array form of the .NET Framework object]</value>
27+
<comment>This is a comment</comment>
28+
</data>
29+
30+
There are any number of "resheader" rows that contain simple
31+
name/value pairs.
32+
33+
Each data row contains a name, and value. The row also contains a
34+
type or mimetype. Type corresponds to a .NET class that support
35+
text/value conversion through the TypeConverter architecture.
36+
Classes that don't support this are serialized and stored with the
37+
mimetype set.
38+
39+
The mimetype is used for serialized objects, and tells the
40+
ResXResourceReader how to depersist the object. This is currently not
41+
extensible. For a given mimetype the value must be set accordingly:
42+
43+
Note - application/x-microsoft.net.object.binary.base64 is the format
44+
that the ResXResourceWriter will generate, however the reader can
45+
read any of the formats listed below.
46+
47+
mimetype: application/x-microsoft.net.object.binary.base64
48+
value : The object must be serialized with
49+
: System.Runtime.Serialization.Formatters.Binary.BinaryFormatter
50+
: and then encoded with base64 encoding.
51+
52+
mimetype: application/x-microsoft.net.object.soap.base64
53+
value : The object must be serialized with
54+
: System.Runtime.Serialization.Formatters.Soap.SoapFormatter
55+
: and then encoded with base64 encoding.
56+
57+
mimetype: application/x-microsoft.net.object.bytearray.base64
58+
value : The object must be serialized into a byte array
59+
: using a System.ComponentModel.TypeConverter
60+
: and then encoded with base64 encoding.
61+
-->
62+
<xsd:schema id="root" xmlns="" xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:msdata="urn:schemas-microsoft-com:xml-msdata">
63+
<xsd:import namespace="http://www.w3.org/XML/1998/namespace" />
64+
<xsd:element name="root" msdata:IsDataSet="true">
65+
<xsd:complexType>
66+
<xsd:choice maxOccurs="unbounded">
67+
<xsd:element name="metadata">
68+
<xsd:complexType>
69+
<xsd:sequence>
70+
<xsd:element name="value" type="xsd:string" minOccurs="0" />
71+
</xsd:sequence>
72+
<xsd:attribute name="name" use="required" type="xsd:string" />
73+
<xsd:attribute name="type" type="xsd:string" />
74+
<xsd:attribute name="mimetype" type="xsd:string" />
75+
<xsd:attribute ref="xml:space" />
76+
</xsd:complexType>
77+
</xsd:element>
78+
<xsd:element name="assembly">
79+
<xsd:complexType>
80+
<xsd:attribute name="alias" type="xsd:string" />
81+
<xsd:attribute name="name" type="xsd:string" />
82+
</xsd:complexType>
83+
</xsd:element>
84+
<xsd:element name="data">
85+
<xsd:complexType>
86+
<xsd:sequence>
87+
<xsd:element name="value" type="xsd:string" minOccurs="0" msdata:Ordinal="1" />
88+
<xsd:element name="comment" type="xsd:string" minOccurs="0" msdata:Ordinal="2" />
89+
</xsd:sequence>
90+
<xsd:attribute name="name" type="xsd:string" use="required" msdata:Ordinal="1" />
91+
<xsd:attribute name="type" type="xsd:string" msdata:Ordinal="3" />
92+
<xsd:attribute name="mimetype" type="xsd:string" msdata:Ordinal="4" />
93+
<xsd:attribute ref="xml:space" />
94+
</xsd:complexType>
95+
</xsd:element>
96+
<xsd:element name="resheader">
97+
<xsd:complexType>
98+
<xsd:sequence>
99+
<xsd:element name="value" type="xsd:string" minOccurs="0" msdata:Ordinal="1" />
100+
</xsd:sequence>
101+
<xsd:attribute name="name" type="xsd:string" use="required" />
102+
</xsd:complexType>
103+
</xsd:element>
104+
</xsd:choice>
105+
</xsd:complexType>
106+
</xsd:element>
107+
</xsd:schema>
108+
<resheader name="resmimetype">
109+
<value>text/microsoft-resx</value>
110+
</resheader>
111+
<resheader name="version">
112+
<value>2.0</value>
113+
</resheader>
114+
<resheader name="reader">
115+
<value>System.Resources.ResXResourceReader, System.Windows.Forms, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089</value>
116+
</resheader>
117+
<resheader name="writer">
118+
<value>System.Resources.ResXResourceWriter, System.Windows.Forms, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089</value>
119+
</resheader>
120+
<data name="ArgsException_BackchallelLessThanZero" xml:space="preserve">
121+
<value>BackchannelTimeout cannot be less or equal to TimeSpan.Zero.</value>
122+
</data>
123+
<data name="Exception_OpenIdConnectMessageError" xml:space="preserve">
124+
<value>"OpenIdConnectMessage.Error was not null, indicating an error. Error: '{0}'. Error_Description (may be empty): '{1}'. Error_Uri (may be empty): '{2}'."</value>
125+
</data>
126+
<data name="Exception_RedirectUri_LogoutQueryString_IsNotWellFormed" xml:space="preserve">
127+
<value>OIDC_20001: The query string for Logout is not a well formed URI. The runtime cannot redirect. Redirect uri: '{0}'.</value>
128+
</data>
129+
<data name="Exception_ValidatorHandlerMismatch" xml:space="preserve">
130+
<value>An ICertificateValidator cannot be specified at the same time as an HttpMessageHandler unless it is a WebRequestHandler.</value>
131+
</data>
132+
</root>

src/Microsoft.AspNet.Security/Infrastructure/AuthenticationHandler.cs

Lines changed: 5 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -77,9 +77,12 @@ protected async Task BaseInitializeAsync(AuthenticationOptions options, HttpCont
7777
if (BaseOptions.AuthenticationMode == AuthenticationMode.Active)
7878
{
7979
AuthenticationTicket ticket = await AuthenticateAsync();
80-
if (ticket != null && ticket.Identity != null)
80+
if (ticket != null)
8181
{
82-
SecurityHelper.AddUserIdentity(Context, ticket.Identity);
82+
if ( ticket.Identity != null)
83+
SecurityHelper.AddUserIdentity(Context, ticket.Identity);
84+
else if (ticket.Principal != null)
85+
SecurityHelper.AddUserIdentity(Context, ticket.Principal.Identity);
8386
}
8487
}
8588
}

0 commit comments

Comments
 (0)