IA.Common/AntiForgery/AntiXsrf/AntiForgeryWorker.cs

(开头部分) 7KB

这里只显示每个文件的开头 60 行。登录后可以解锁完整代码。

// Copyright (c) Microsoft Open Technologies, Inc. All rights reserved. See License.txt in the project root for license information.

using System;
using System.Collections.Generic;
using System.Diagnostics.CodeAnalysis;
using System.Diagnostics.Contracts;
using System.Net;
using System.Security.Principal;
using System.Web;
using System.Web.Mvc;

namespace IA.Common.AntiForgery.AntiXsrf
{
    public sealed class AntiForgeryWorker
    {
        private readonly IAntiForgeryConfig _config;
        private readonly IAntiForgeryTokenSerializer _serializer;
        private readonly ITokenStore _tokenStore;
        private readonly ITokenValidator _validator;

        internal AntiForgeryWorker(IAntiForgeryTokenSerializer serializer, IAntiForgeryConfig config,
                                   ITokenStore tokenStore, ITokenValidator validator)
        {
            _serializer = serializer;
            _config = config;
            _tokenStore = tokenStore;
            _validator = validator;
        }

        private void CheckSSLConfig(HttpContextBase httpContext)
        {
            if (_config.RequireSSL && !httpContext.Request.IsSecureConnection)
            {
                throw new InvalidOperationException("AntiForgeryWorker_RequireSSL");
            }
        }

        private AntiForgeryToken DeserializeToken(string serializedToken)
        {
            return (!String.IsNullOrEmpty(serializedToken))
                       ? _serializer.Deserialize(serializedToken)
                       : null;
        }

        [SuppressMessage("Microsoft.Design", "CA1031:DoNotCatchGeneralExceptionTypes",
            Justification = "Caller will just regenerate token in case of failure.")]
        private AntiForgeryToken DeserializeTokenNoThrow(string serializedToken)
        {
            try
            {
                return DeserializeToken(serializedToken);
            }
            catch
            {
                // ignore failures since we'll just generate a new token
                return null;
            }
        }

        private static IIdentity ExtractIdentity(HttpContextBase httpContext)
后面还有 135 行代码,购买后查看完整代码

24 小时内免费解锁 3 个项目,之后 1 积分/个。 规则说明

AI 解读

登录后可用,每次 10 积分,解读结果公开显示在下面。

还没有人解读过这个文件。