WebService authentication

http://blog.csdn.net/largestone_187/article/details/5734632

通过SoapHeader对用户口令进行验证,只有授权的用户才可以使用接口。确保了访问接口用户的安全性。

 

public MySoapHeader myHeader = new MySoapHeader();

    public SoapHeaderService()
    {

        //Uncomment the following line if using designed components
        //InitializeComponent();
    }
    //普通方法,不需要SoapHeader验证 
    [WebMethod(Description = "普通方法不需要验证")]
    public string HelloWorld(string msg) {
        if (msg == "")
            msg = "default message:" + "Hello World";
        else
            msg = "The message you have input is " + msg;   
        return msg;
    }
    //需要SoapHeader验证 
    [SoapHeader("myHeader")]
    [WebMethod(Description="需要SoapHeader验证  ", EnableSession = true)]
    public string GetSecurityService(string inmsg)     
    {         
        string msg = "";         
        //验证是否有权访问         
        if (!myHeader.IsValid(out  msg))         
        {             
            return msg;//返回错误信息         
        }
        inmsg = "Security Message: " + inmsg;
        return inmsg;     
    } 

SoapHeader验证,本文未连接数据库,仅仅将验证写死了,需要的可以自己改。

 

public class MySoapHeader:System.Web.Services.Protocols.SoapHeader
{
    private string _UserID = string.Empty;
    private string _PassWord = string.Empty; 
 
    public MySoapHeader()
 {
  //
  // TODO: Add constructor logic here
  //
 }
    //<param name="nUserID">用户ID</param>     
    //<param name="nPassWord">加密后的密码</param>     
    public MySoapHeader(string nUserID, string nPassWord)     
    {         
        Initial(nUserID, nPassWord);     
    } 
    #region 属性     
    //<summary>      //用户名      //</summary>     
    public string UserID     
    {         
        get { return _UserID; }         
        set { _UserID = value; }     
    }     
    //<summary>     
    //加密后的密码     
    //</summary>     
    public string PassWord     
    {         
        get { return _PassWord; }         
        set { _PassWord = value; }     
    }             
    #endregion     
    #region 方法     
    //<summary>     
    //初始化     
    //</summary>     
    //<param name="nUserID">用户ID</param>     
    //<param name="nPassWord">加密后的密码</param>     
    private void Initial(string nUserID, string nPassWord)     
    {         
        UserID = nUserID;         
        PassWord = nPassWord;     
    }     
    //<summary>     
    //验证用户名密码是否正确     
    //</summary>     
    //<param name="nUserID">用户ID</param>     
    //<param name="nPassWord">加密后的密码</param>     
    //<param name="nMsg">返回的错误信息</param>     
    //<returns>用户名密码是否正确</returns>     
    private bool IsValid(string nUserID, string nPassWord, out string nMsg)     
    {         
        nMsg = "";         
        try        
        {             
            //判断用户名密码是否正确              
            if (nUserID == "admin" && nPassWord == "admin")             
            {                 
                return true;
            }             
            else            
            {                 
                nMsg = "对不起,你无权调用此Web服务。";                 
                return false;             
            }         
        }          catch        
        {             
            nMsg = "对不起,你无权调用此Web服务。";             
            return false;          }     
        }     
    //<summary>     
    //验证用户名密码是否正确     
    //</summary>      //<returns>用户名密码是否正确</returns>     
    public bool IsValid(out string nMsg)     
    {         
        return IsValid(_UserID, _PassWord, out nMsg);     
    }     
    #endregion 

}

SoapHeaderWS.SoapHeaderService shService = new SoapHeaderWS.SoapHeaderService();
SoapHeaderWS.MySoapHeader header = new SoapHeaderWS.MySoapHeader();
header.UserID = "admin";
header.PassWord = "admin";
shService.MySoapHeaderValue = header;
string outmsg = shService.GetSecurityService("测试安全控制Web Service成功!");
Label1.Text = outmsg;

转载于:https://www.cnblogs.com/CodingArt/p/6072742.html

  • 0
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 0
    评论

“相关推荐”对你有帮助么?

  • 非常没帮助
  • 没帮助
  • 一般
  • 有帮助
  • 非常有帮助
提交
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值