WindowsIdentity.GetCurrent().Impersonate()做什么

DCa*_*olz 4 .net c#

我正在编写一个类来处理在asp.net,WCF服务和WinForms应用程序中使用的模拟和委托.

根据MSDN,WindowsIdentity.GetCurrent()返回表示当前Windows用户的WindowsIdentity对象.

和

根据MSDN,WindowsIdentity.Impersonate允许代码模拟不同的Windows用户.

那么,冒充当前用户有什么影响,更重要的是,在Web应用程序中,WindowsIdentity.GetCurrent()如何返回除流程入门者身份或已经模仿的最终用户之外的其他用户?

Fré*_*idi 7

Impersonate()SecurityException如果发生Win32错误则抛出一个.因此,它很可能是通过Win32函数实现的,很可能是ImpersonateLoggedOnUser().

它的文件说(强调我的):

所有模拟函数,包括ImpersonateLoggedOnUser允许所请求的模拟,如果满足以下条件之一:

  • 请求的令牌模拟级别小于SecurityImpersonation,例如SecurityIdentification或 SecurityAnonymous.
  • 呼叫者有SeImpersonatePrivilege权限.
  • 进程(或调用者登录会话中的另一个进程)使用显式凭证LogonUser或 LsaLogonUser函数创建令牌.
  • 经过身份验证的身份与呼叫者相同.

因此,我强烈倾向于认为WindowsIdentity.GetCurrent().Impersonate()将成功为同一用户建立新的模拟层.

关于你问题的第二部分,你似乎是混乱WindowsIdentity.GetCurrent()与HttpContext.User中.在Web应用程序中,WindowsIdentity.GetCurrent()始终返回线程所有者(通常Network Service),并HttpContext.User返回当前经过身份验证的用户(如果有).

  • 仍然没有人回答再次冒充_当前用户_有什么好处,这是最初的问题。是的,它创建了同一用户的新模拟上下文。但为什么要这样做呢? (2认同)