IA.Common/AntiForgery/AntiForgeryHelper.cs

(开头部分) 2KB

这里只显示每个文件的开头 60 行。登录后可以解锁完整代码。

// Copyright (c) Microsoft Open Technologies, Inc. All rights reserved. See License.txt in the project root for license information.

using System;
using System.Collections.Generic;
using System.ComponentModel;
using System.Diagnostics.CodeAnalysis;
using System.Net;
using System.Web;
using System.Web.Mvc;
using IA.Common.AntiForgery.AntiXsrf;
using IA.Common.AntiForgery.Claims;

namespace IA.Common.AntiForgery
{
    /// <summary>
    ///     Provides access to the anti-forgery system, which provides protection against
    ///     Cross-site Request Forgery (XSRF, also called CSRF) attacks.
    /// </summary>
    public static class AntiForgeryHelper
    {
        private static readonly AntiForgeryWorker _worker = CreateSingletonAntiForgeryWorker();

        private static AntiForgeryWorker CreateSingletonAntiForgeryWorker()
        {
            // initialize the dependency chain

            // The 'Instance' property can return null, in which case we should fall back to using
            // the 4.0 crypto code paths. We need to use an 'if' block rather than the null coalescing
            // operator due to a CLR bug (DevDiv #424203).
            ICryptoSystem cryptoSystem = MachineKey45CryptoSystem.Instance;
            if (cryptoSystem == null)
            {
                cryptoSystem = new MachineKey40CryptoSystem();
            }

            IAntiForgeryConfig config = new AntiForgeryConfigWrapper();
            IAntiForgeryTokenSerializer serializer = new AntiForgeryTokenSerializer(cryptoSystem);
            ITokenStore tokenStore = new AntiForgeryTokenStore(config, serializer);
            IClaimUidExtractor claimUidExtractor = new ClaimUidExtractor(config, ClaimsIdentityConverter.Default);
            ITokenValidator tokenValidator = new TokenValidator(config, claimUidExtractor);

            return new AntiForgeryWorker(serializer, config, tokenStore, tokenValidator);
        }

        /// <summary>
        ///     Generates an anti-forgery token for this request. This token can
        ///     be validated by calling the Validate() method.
        /// </summary>
        /// <returns>
        ///     An HTML string corresponding to an &lt;input type="hidden"&gt;
        ///     element. This element should be put inside a &lt;form&gt;.
        /// </returns>
        /// <remarks>
        ///     This method has a side effect: it may set a response cookie.
        /// </remarks>
        public static HtmlString GetHtml()
        {
            if (HttpContext.Current == null)
            {
                throw new ArgumentException("AntiForgery,GetHtml异常");

24 小时内免费解锁 3 个项目,之后 1 积分/个。 规则说明

AI 解读

登录后可用,每次 10 积分,解读结果公开显示在下面。

还没有人解读过这个文件。