.net 实现Cookie跨域共享,单点登录SSO
實現原理:cookie是不能跨域訪問的,但是在二級域名是可以共享cookie的
概念說明:站點1=a.devin.com ? 站點2=b.devin.com
實現步驟:1. 配置兩個站點的webconfig
? ? ? ? ? ? ? 2. a.devin.com寫入cookie?
? ? ? ? ? ? ? 3. b.devin.com讀取cookie
一、配置Webconfig:
<authentication mode="Forms">
? ? ?<forms domain="devin.com" name="devin.authcookie" protection="All" />
</authentication>
<machineKey validationKey="0FA0557BB72D5E7ADD89A4B4FD40E3E232D17EFE06874FA8DD358D5484B8A4C5E1D3629B79FFD3D6D53184495CAED1164BCC1F19B47B89B7CA35875B4A687FAE" decryptionKey="A4BBD94822A8731F" validation="SHA1" />
以上machineKey自行生成配置;
如下是登陸寫入cookie代碼
1 /// <summary> 2 /// 登陸驗證成功后寫入FormsAuthenticationTicket 3 /// </summary> 4 /// <param name="userCode">登錄名</param> 5 /// <param name="userData">登陸用戶信息</param> 6 /// <param name="isAutoLogin">是否自動登陸</param> 7 public static void Login(string userCode, string userData, bool isAutoLogin = false) 8 { 9 FormsAuthentication.Initialize(); 10 DateTime expirationTime = DateTime.Now.AddMinutes(60); 11 if (isAutoLogin) expirationTime = DateTime.Now.AddDays(7); 12 var authTicket = new FormsAuthenticationTicket(1, userCode, DateTime.Now, expirationTime, false, userData, FormsAuthentication.FormsCookiePath); 13 var encryptedTicket = FormsAuthentication.Encrypt(authTicket); 14 var authCookie = new HttpCookie(FormsAuthentication.FormsCookieName, encryptedTicket) 15 { 16 Domain = FormsAuthentication.CookieDomain, 17 Path = FormsAuthentication.FormsCookiePath, 18 Expires = expirationTime, 19 HttpOnly = true 20 }; 21 HttpContext.Current.Response.Cookies.Add(authCookie); 22 }以下是讀取登陸cookie信息代碼(LoginedUserInfo為登陸用戶實體對象,自定義,與登陸中的userData的json串相對應序列化)
1 /// <summary> 2 /// 獲取當前登錄用戶信息,如未登陸則返回NULL 3 /// </summary> 4 /// <returns>返回當前登錄用戶信息</returns> 5 public static LoginedUserInfo GetLoginInfo() 6 { 7 var currentuser = HttpContext.Current.User; 8 if (!currentuser.Identity.IsAuthenticated) return null; 9 var userData = ((FormsIdentity)currentuser.Identity).Ticket.UserData; 10 if (string.IsNullOrWhiteSpace(userData)) return null; 11 LoginedUserInfo loginMember = SerializationHelper.JsonDeserialize<LoginedUserInfo>(userData); 12 return loginMember; 13 }?
轉載于:https://www.cnblogs.com/devinhua/p/5364363.html
總結
以上是生活随笔為你收集整理的.net 实现Cookie跨域共享,单点登录SSO的全部內容,希望文章能夠幫你解決所遇到的問題。
- 上一篇: 基于动态混合高斯模型的商品价格模型算法
- 下一篇: dat14-memcached