zoukankan      html  css  js  c++  java
  • jquery.uploadify不支持MVC的Authorize

    原文发布时间为:2011-10-18 —— 来源于本人的百度文章 [由搬家工具导入]

    为什么jquery.uploadify不支持MVC的Authorize呢,因为flash的cookie跟服务端的不一样。

    http://stackoverflow.com/questions/1729179/uploadify-session-and-authentication-with-asp-net-mvc

    There was not "properly" an issue with my code. The usage of the plugin was generally correct but there was an issue with the authentication mechanism.

    As everybody can find on the internet the flash plugin does not share the authentication cookie with the server-side code and this was the reason behind the usage of the "scriptData" section inside my code that contained the Authentication Cookie.

    The problem was related to the fact that the controller was decorated with the [Authorize] attribute and this was never letting the request reach its destination.

    The solution, found with the help of another user on the uploadify forum, is to write a customized version of the AuthorizeAttribute like you can see in the following code.

    /// <summary>
    /// A custom version of the <see cref="AuthorizeAttribute"/> that supports working
    /// around a cookie/session bug in Flash.  
    /// </summary>
    /// <remarks>
    /// Details of the bug and workaround can be found on this blog:
    /// http://geekswithblogs.net/apopovsky/archive/2009/05/06/working-around-flash-cookie-bug-in-asp.net-mvc.aspx
    /// </remarks>
    [AttributeUsage(AttributeTargets.Class|AttributeTargets.Method,Inherited=true,AllowMultiple=true)]
    publicclassTokenizedAuthorizeAttribute:AuthorizeAttribute
    {
        /// <summary>
        /// The key to the authentication token that should be submitted somewhere in the request.
        /// </summary>
        privateconststring TOKEN_KEY ="AuthenticationToken";

        /// <summary>
        /// This changes the behavior of AuthorizeCore so that it will only authorize
        /// users if a valid token is submitted with the request.
        /// </summary>
        /// <param name="httpContext"></param>
        /// <returns></returns>
        protectedoverrideboolAuthorizeCore(System.Web.HttpContextBase httpContext ){
            string token = httpContext.Request.Params[TOKEN_KEY];

            if( token !=null){
                FormsAuthenticationTicket ticket =FormsAuthentication.Decrypt( token );

                if( ticket !=null){
                    FormsIdentity identity =newFormsIdentity( ticket );
                    string[] roles =System.Web.Security.Roles.GetRolesForUser( identity.Name);
                    GenericPrincipal principal =newGenericPrincipal( identity, roles );
                    httpContext.User= principal;
                }
            }

            returnbase.AuthorizeCore( httpContext );
        }
    }

    http://www.uploadify.com/download/

  • 相关阅读:
    数据压缩算法---LZ77算法 的分析与实现
    数据压缩算法---霍夫曼编码的分析与实现
    数据压缩的重要组成部分---位操作
    排序算法的C语言实现(上 比较类排序:插入排序、快速排序与归并排序)
    广度优先(bfs)和深度优先搜索(dfs)的应用实例
    数据结构 图的定义和搜索方法(清晰图解)
    数据结构-堆 接口定义与实现分析(详细注释与图解)
    数据结构-堆的定义描述
    数据结构 链式哈希表(Hash Table)的接口定义与实现分析(完整代码)
    SQLServer常用快捷键汇总
  • 原文地址:https://www.cnblogs.com/handboy/p/7182569.html
Copyright © 2011-2022 走看看