Where Federation authentication token is saved [WIF STS]?

坚强是说给别人听的谎言 提交于 2019-12-11 01:49:07

问题


While i started to explore WIF, i have a doubt on the following:

In the Windows Identification Foundation[WIF],looking on to Security Token Service[STS], i wish to know where the federation authentication token is being saved?

I think its in browser cookie, if so can anyone please give me a insight about it?


回答1:


I used the 'Fiddler' Web debugger to find the answer to this question. Here's what happens: Let's suppose that the name of your application is SecureApp and the name of your STS is SecurePortal.

The first thing that happens when you point your browser at SecureApp is that it checks to see if you're authenticated. If you're not, you are immediately redirected to SecurePortal with a query string indicating that you're logging into SecureApp.

Once you log in with SecurePortal, the WIF framework produces an HttpResponse from SecurePortal which contains some 'hidden' HTML fields containing values which indicate that you successfully logged in. These values may be signed and/or encrypted based on the setup of SecurePortal. Along with these values is written some Javascript code to make the browser post the values to SecureApp. Once these values are validated by SecureApp, the framework will write an HttpResponse with cookie(s) that indicate that you are logged in. In my experience, the names of the cookies start with "FedAuth". At this point, you may now access pages within SecureApp.

Also, I would like to point out that the framework seems to have some way of preventing the cookies that it sets from being removed manually.

I suggest that you use a web debugger and observe this process happening on your own to understand better.

The short answer: The token is first given to your browser as an HttpResponse in the STS and then given to your browser again as a cookie in the application.




回答2:


WIF also supports "Session Mode" for Tokens. In that case, the token is kept in the server and only a (much smaller) handle is passed to the browser. Especially useful if you have bandwidth considerations.

See Vittorio's post on this: Session mode for WIF

Added more references:

Hervey's session at last PDC also covers this.



来源:https://stackoverflow.com/questions/2897422/where-federation-authentication-token-is-saved-wif-sts

易学教程内所有资源均来自网络或用户发布的内容,如有违反法律规定的内容欢迎反馈
该文章没有解决你所遇到的问题?点击提问,说说你的问题,让更多的人一起探讨吧!