Clean up logs for Negotiate Authentication and Authorization (#21927)
* Clean up logs for Negotiate Authentication and Authorization * Add missing arg in NegotiateLoggingExtensions.cs * Adjust formatting * Remaining text changes * Update src/Security/Authentication/Negotiate/src/Internal/NegotiateLoggingExtensions.cs Co-authored-by: Chris Ross <Tratcher@Outlook.com> * Update src/Security/Authentication/Negotiate/src/Internal/NegotiateLoggingExtensions.cs Co-authored-by: Chris Ross <Tratcher@Outlook.com> * Update src/Security/Authentication/Negotiate/src/NegotiateHandler.cs Co-authored-by: Chris Ross <Tratcher@Outlook.com> * Update src/Security/Authentication/Negotiate/src/Internal/NegotiateLoggingExtensions.cs Co-authored-by: Chris Ross <Tratcher@Outlook.com> * Apply changes to feedback committed * Update logger call to refactored name Co-authored-by: Chris Ross <Tratcher@Outlook.com> Co-authored-by: Giuseppe Campanelli <campanelli_g@yahoo.com>
This commit is contained in:
parent
02bf53de96
commit
78edd18524
|
|
@ -17,6 +17,7 @@ namespace Microsoft.Extensions.Logging
|
||||||
private static Action<ILogger, Exception> _challengeNegotiate;
|
private static Action<ILogger, Exception> _challengeNegotiate;
|
||||||
private static Action<ILogger, Exception> _reauthenticating;
|
private static Action<ILogger, Exception> _reauthenticating;
|
||||||
private static Action<ILogger, Exception> _deferring;
|
private static Action<ILogger, Exception> _deferring;
|
||||||
|
private static Action<ILogger, string, Exception> _negotiateError;
|
||||||
|
|
||||||
static NegotiateLoggingExtensions()
|
static NegotiateLoggingExtensions()
|
||||||
{
|
{
|
||||||
|
|
@ -43,7 +44,7 @@ namespace Microsoft.Extensions.Logging
|
||||||
_challengeNegotiate = LoggerMessage.Define(
|
_challengeNegotiate = LoggerMessage.Define(
|
||||||
eventId: new EventId(6, "ChallengeNegotiate"),
|
eventId: new EventId(6, "ChallengeNegotiate"),
|
||||||
logLevel: LogLevel.Debug,
|
logLevel: LogLevel.Debug,
|
||||||
formatString: "Challenged 401 Negotiate");
|
formatString: "Challenged 401 Negotiate.");
|
||||||
_reauthenticating = LoggerMessage.Define(
|
_reauthenticating = LoggerMessage.Define(
|
||||||
eventId: new EventId(7, "Reauthenticating"),
|
eventId: new EventId(7, "Reauthenticating"),
|
||||||
logLevel: LogLevel.Debug,
|
logLevel: LogLevel.Debug,
|
||||||
|
|
@ -60,6 +61,10 @@ namespace Microsoft.Extensions.Logging
|
||||||
eventId: new EventId(10, "ClientError"),
|
eventId: new EventId(10, "ClientError"),
|
||||||
logLevel: LogLevel.Debug,
|
logLevel: LogLevel.Debug,
|
||||||
formatString: "The users authentication request was invalid.");
|
formatString: "The users authentication request was invalid.");
|
||||||
|
_negotiateError = LoggerMessage.Define<string>(
|
||||||
|
eventId: new EventId(11, "NegotiateError"),
|
||||||
|
logLevel: LogLevel.Debug,
|
||||||
|
formatString: "Negotiate error code: {error}.");
|
||||||
}
|
}
|
||||||
|
|
||||||
public static void IncompleteNegotiateChallenge(this ILogger logger)
|
public static void IncompleteNegotiateChallenge(this ILogger logger)
|
||||||
|
|
@ -91,5 +96,8 @@ namespace Microsoft.Extensions.Logging
|
||||||
|
|
||||||
public static void ClientError(this ILogger logger, Exception ex)
|
public static void ClientError(this ILogger logger, Exception ex)
|
||||||
=> _clientError(logger, ex);
|
=> _clientError(logger, ex);
|
||||||
|
|
||||||
|
public static void NegotiateError(this ILogger logger, string error)
|
||||||
|
=> _negotiateError(logger, error, null);
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
|
||||||
|
|
@ -129,9 +129,9 @@ namespace Microsoft.AspNetCore.Authentication.Negotiate
|
||||||
_negotiateState ??= Options.StateFactory.CreateInstance();
|
_negotiateState ??= Options.StateFactory.CreateInstance();
|
||||||
|
|
||||||
var outgoing = _negotiateState.GetOutgoingBlob(token, out var errorType, out var exception);
|
var outgoing = _negotiateState.GetOutgoingBlob(token, out var errorType, out var exception);
|
||||||
Logger.LogInformation(errorType.ToString());
|
|
||||||
if (errorType != BlobErrorType.None)
|
if (errorType != BlobErrorType.None)
|
||||||
{
|
{
|
||||||
|
Logger.NegotiateError(errorType.ToString());
|
||||||
_negotiateState.Dispose();
|
_negotiateState.Dispose();
|
||||||
_negotiateState = null;
|
_negotiateState = null;
|
||||||
if (persistence?.State != null)
|
if (persistence?.State != null)
|
||||||
|
|
|
||||||
|
|
@ -32,7 +32,7 @@ namespace Microsoft.AspNetCore.Authorization.Infrastructure
|
||||||
|
|
||||||
public override string ToString()
|
public override string ToString()
|
||||||
{
|
{
|
||||||
return $"{nameof(DenyAnonymousAuthorizationRequirement)}:Requires an authenticated user.";
|
return $"{nameof(DenyAnonymousAuthorizationRequirement)}: Requires an authenticated user.";
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
|
||||||
|
|
@ -20,7 +20,7 @@ namespace Microsoft.Extensions.Logging
|
||||||
_userAuthorizationFailed = LoggerMessage.Define<string>(
|
_userAuthorizationFailed = LoggerMessage.Define<string>(
|
||||||
eventId: new EventId(2, "UserAuthorizationFailed"),
|
eventId: new EventId(2, "UserAuthorizationFailed"),
|
||||||
logLevel: LogLevel.Information,
|
logLevel: LogLevel.Information,
|
||||||
formatString: "Authorization failed for {0}");
|
formatString: "Authorization failed. {0}");
|
||||||
}
|
}
|
||||||
|
|
||||||
public static void UserAuthorizationSucceeded(this ILogger logger)
|
public static void UserAuthorizationSucceeded(this ILogger logger)
|
||||||
|
|
|
||||||
|
|
@ -1221,7 +1221,7 @@ namespace Microsoft.AspNetCore.Authorization.Test
|
||||||
Assert.Equal("UserAuthorizationFailed", eventId.Name);
|
Assert.Equal("UserAuthorizationFailed", eventId.Name);
|
||||||
var message = formatter(state, exception);
|
var message = formatter(state, exception);
|
||||||
|
|
||||||
Assert.Equal("Authorization failed for These requirements were not met:" + Environment.NewLine + "LogRequirement" + Environment.NewLine + "LogRequirement", message);
|
Assert.Equal("Authorization failed. These requirements were not met:" + Environment.NewLine + "LogRequirement" + Environment.NewLine + "LogRequirement", message);
|
||||||
}
|
}
|
||||||
|
|
||||||
var authorizationService = BuildAuthorizationService(services =>
|
var authorizationService = BuildAuthorizationService(services =>
|
||||||
|
|
@ -1254,7 +1254,7 @@ namespace Microsoft.AspNetCore.Authorization.Test
|
||||||
Assert.Equal("UserAuthorizationFailed", eventId.Name);
|
Assert.Equal("UserAuthorizationFailed", eventId.Name);
|
||||||
var message = formatter(state, exception);
|
var message = formatter(state, exception);
|
||||||
|
|
||||||
Assert.Equal("Authorization failed for Fail() was explicitly called.", message);
|
Assert.Equal("Authorization failed. Fail() was explicitly called.", message);
|
||||||
}
|
}
|
||||||
|
|
||||||
var authorizationService = BuildAuthorizationService(services =>
|
var authorizationService = BuildAuthorizationService(services =>
|
||||||
|
|
|
||||||
|
|
@ -26,7 +26,7 @@ namespace Microsoft.AspNetCore.Authorization.Test
|
||||||
var formattedValue = requirement.ToString();
|
var formattedValue = requirement.ToString();
|
||||||
|
|
||||||
// Assert
|
// Assert
|
||||||
Assert.Equal("DenyAnonymousAuthorizationRequirement:Requires an authenticated user.", formattedValue);
|
Assert.Equal("DenyAnonymousAuthorizationRequirement: Requires an authenticated user.", formattedValue);
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
|
||||||
Loading…
Reference in New Issue