AuthorizeFilter should always set default identity
This commit is contained in:
parent
8ec28463fc
commit
1ea1cc4338
|
|
@ -44,6 +44,11 @@ namespace Microsoft.AspNet.Mvc
|
||||||
newPrincipal.AddIdentities(result.Identities);
|
newPrincipal.AddIdentities(result.Identities);
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
// If all schemes failed authentication, provide a default identity anyways
|
||||||
|
if (newPrincipal.Identity == null)
|
||||||
|
{
|
||||||
|
newPrincipal.AddIdentity(new ClaimsIdentity());
|
||||||
|
}
|
||||||
context.HttpContext.User = newPrincipal;
|
context.HttpContext.User = newPrincipal;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
|
||||||
|
|
@ -9,7 +9,6 @@ using Microsoft.AspNet.Authorization;
|
||||||
using Microsoft.AspNet.Http;
|
using Microsoft.AspNet.Http;
|
||||||
using Microsoft.AspNet.Http.Authentication;
|
using Microsoft.AspNet.Http.Authentication;
|
||||||
using Microsoft.AspNet.Routing;
|
using Microsoft.AspNet.Routing;
|
||||||
using Microsoft.AspNet.WebUtilities;
|
|
||||||
using Microsoft.Framework.DependencyInjection;
|
using Microsoft.Framework.DependencyInjection;
|
||||||
using Moq;
|
using Moq;
|
||||||
using Xunit;
|
using Xunit;
|
||||||
|
|
@ -87,6 +86,22 @@ namespace Microsoft.AspNet.Mvc.Test
|
||||||
Assert.Null(authorizationContext.Result);
|
Assert.Null(authorizationContext.Result);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
[Fact]
|
||||||
|
public async Task Invoke_AuthSchemesFailShouldSetEmptyPrincipalOnContext()
|
||||||
|
{
|
||||||
|
// Arrange
|
||||||
|
var authorizeFilter = new AuthorizeFilter(new AuthorizationPolicyBuilder("Fails")
|
||||||
|
.RequireAuthenticatedUser()
|
||||||
|
.Build());
|
||||||
|
var authorizationContext = GetAuthorizationContext(services => services.AddAuthorization());
|
||||||
|
|
||||||
|
// Act
|
||||||
|
await authorizeFilter.OnAuthorizationAsync(authorizationContext);
|
||||||
|
|
||||||
|
// Assert
|
||||||
|
Assert.NotNull(authorizationContext.HttpContext.User?.Identity);
|
||||||
|
}
|
||||||
|
|
||||||
[Fact]
|
[Fact]
|
||||||
public async Task Invoke_SingleValidClaimShouldSucceed()
|
public async Task Invoke_SingleValidClaimShouldSucceed()
|
||||||
{
|
{
|
||||||
|
|
@ -303,6 +318,7 @@ namespace Microsoft.AspNet.Mvc.Test
|
||||||
httpContext.SetupGet(c => c.RequestServices).Returns(serviceProvider);
|
httpContext.SetupGet(c => c.RequestServices).Returns(serviceProvider);
|
||||||
auth.Setup(c => c.AuthenticateAsync("Bearer")).ReturnsAsync(new AuthenticationResult(bearerPrincipal, new AuthenticationProperties(), new AuthenticationDescription()));
|
auth.Setup(c => c.AuthenticateAsync("Bearer")).ReturnsAsync(new AuthenticationResult(bearerPrincipal, new AuthenticationProperties(), new AuthenticationDescription()));
|
||||||
auth.Setup(c => c.AuthenticateAsync("Basic")).ReturnsAsync(new AuthenticationResult(basicPrincipal, new AuthenticationProperties(), new AuthenticationDescription()));
|
auth.Setup(c => c.AuthenticateAsync("Basic")).ReturnsAsync(new AuthenticationResult(basicPrincipal, new AuthenticationProperties(), new AuthenticationDescription()));
|
||||||
|
auth.Setup(c => c.AuthenticateAsync("Fails")).ReturnsAsync(null);
|
||||||
|
|
||||||
// AuthorizationContext
|
// AuthorizationContext
|
||||||
var actionContext = new ActionContext(
|
var actionContext = new ActionContext(
|
||||||
|
|
|
||||||
Loading…
Reference in New Issue