public class JwtMessageHandler : DelegatingHandler
{
protected override Task<HttpResponseMessage> SendAsync(HttpRequestMessage request, CancellationToken cancellationToken)
{
var authorizationParameter = request.Headers.Authorization.Parameter;
var handler = new JwtSecurityTokenHandler();
var x509Certificate2 = new X509Certificate2(@"c:\temp\ADFS Signing.cer");
var x509SecurityToken = new X509SecurityToken(x509Certificate2);
var tokenValidationParameters = new TokenValidationParameters
{
SigningToken = x509SecurityToken,
AllowedAudience = "[relyingparty identifier]",
ValidIssuer = "[Federation Service identifier]"
};
ClaimsPrincipal res;
res = handler.ValidateToken(authorizationParameter,
tokenValidationParameters);
HttpContext.Current.User = res;
Thread.CurrentPrincipal = res;
return base.SendAsync(request, cancellationToken);
}
}
The JwtMesssageHandler can be configured in the global.asax:
public class WebApiApplication : System.Web.HttpApplication
{
protected void Application_Start()
{
// other configuration
GlobalConfiguration.Configuration.MessageHandlers.Add(new JwtMessageHandler());
}
}
woensdag 30 juli 2014
maandag 24 februari 2014
zondag 23 februari 2014
Asynchronous Programming Model
This is a good explanation of how to make asynchronous calls with the Asynchronous Programming Model ( begin/end):
Calling Synchronous Methods Asynchronously
Calling Synchronous Methods Asynchronously
maandag 27 januari 2014
Competing consumers and returning results with in-memory-queues (BlockingCollection)
I needed a way to to put some work in a queue, consume it and return the result to the producer of the work. In C# we can use the BlockingCollection class and TaskCompletionSource for that.
The code in this blogpost is based on the code from Albahari.What I want to do is this create a Producer which creates work and places that on a queue. I'll also want to create Consumers which take work off the queue and send the result back to the Producer when they are done. See the following image for an overview:
Let's start with a simple console application:
(Don't forget to set it to the correct framework, as VS 2010 defaults to client framework 4.0)
class Program
{
static void Main()
{
// Put something on a queue
}
}
This is the class that we are going to put on the queue:
public class WorkItem
{
public readonly TaskCompletionSource<int> TaskSource;
public readonly int Context;
public readonly CancellationToken? CancelToken;
public WorkItem(
TaskCompletionSource<int> taskSource,
int context,
CancellationToken? cancelToken)
{
TaskSource = taskSource;
Context = context;
CancelToken = cancelToken;
}
}
Next we create the queue we are going to use for enqueueing the work:
public class ProducerConsumerQueue : IDisposable
{
readonly BlockingCollection<WorkItem> _workitemQueue =
new BlockingCollection<WorkItem>();
public Task<int> EnqueueTask(int context)
{
return EnqueueTask(context, null);
}
public Task<int> EnqueueTask(int context,
CancellationToken? cancelToken)
{
var tcs = new TaskCompletionSource<int>();
_workitemQueue.Add(new WorkItem(tcs, context, cancelToken));
return tcs.Task;
}
public void Dispose()
{
_workitemQueue.CompleteAdding();
}
}
As you can see our ProducerConsumerQueue uses a BlockingCollection internally. This is a great class that let's multiple consumers/workers read from it in a thread-safe manner.
Next, create the consumer:
public class Consumer
{
private readonly BlockingCollection<WorkItem> _workitemQueue;
public Consumer(BlockingCollection<WorkItem> workitemQueue)
{
_workitemQueue = workitemQueue;
}
public void Consume()
{
foreach (WorkItem workItem in _workitemQueue.GetConsumingEnumerable())
{
if (workItem.CancelToken.HasValue &&
workItem.CancelToken.Value.IsCancellationRequested)
{
workItem.TaskSource.SetCanceled();
}
else
{
try
{
Thread.Sleep(1000); // simulate work
workItem.TaskSource.SetResult(workItem.Context + 1);
}
catch (OperationCanceledException ex)
{
if (ex.CancellationToken == workItem.CancelToken)
{
workItem.TaskSource.SetCanceled();
}
else
{
workItem.TaskSource.SetException(ex);
}
}
catch (Exception ex)
{
workItem.TaskSource.SetException(ex);
}
}
}
}
}
So how do we start the consumers?
We do that in the constructor of the ProducerConsumerQueue:
public ProducerConsumerQueue(int workerCount)
{
for (int i = 0; i < workerCount; i++)
{
var consumer = new Consumer(_workitemQueue);
Task.Factory.StartNew(consumer.Consume);
}
}
Finally we can finish the console application:
class Program
{
static void Main()
{
var producerConsumerQueue = new ProducerConsumerQueue(2);
Task<int> task1 = producerConsumerQueue.EnqueueTask(1);
Task<int> task2 = producerConsumerQueue.EnqueueTask(2);
Task<int> task3 = producerConsumerQueue.EnqueueTask(3);
Console.WriteLine(task1.Result);
Console.WriteLine(task2.Result);
Console.WriteLine(task3.Result);
Console.ReadLine();
}
}
If we run this, we will start three tasks. Each task will get an input value, add one to it, and return the value to the console app. WE start with two consumers, so after one second the first two tasks finish and the following output is printed:
2
3
A second later the third task finished, and we will see this:
4
You can play around with the number of consumers and the number of enqueued WorkItems.
maandag 13 januari 2014
Design Patterns Quick Reference
Jason McDonald made a Quick Reference for Design Patterns. You can get it here:
http://www.mcdonaldland.info/2007/11/28/40/
http://www.mcdonaldland.info/2007/11/28/40/
woensdag 31 juli 2013
Call WCF service with ADFS token
How can we configure a WCF client to call an ADFS-secured WCF service? In this blog I'll show you how to do it with code only, no xml-configuration needed.
The are only two steps to take:
1. Get a securityToken from ADFS
2. Create a WCF channel to the WCF service, using the securityToken.
internal class Program
{
private static void Main()
{
var stsEndpoint =
"https://myAdfsServer/adfs/services/trust/13/certificatemixed";
var clientCertificateThumbprint = "[put the thumbprint here]";
var svcEndpoint = "https://myDomain/myService.svc";
var token = GetToken(stsEndpoint, svcEndpoint);
var channel = CreateChannel<IMyService>(token,
svcEndpoint,
clientCertificateThumbprint);
channel.Foo();
}
}
private static SecurityToken GetToken(string stsEndpoint,
string svcEndpoint,
string thumbprint)
{
var binding = new
CertificateWSTrustBinding(SecurityMode.TransportWithMessageCredential);
var factory = new WSTrustChannelFactory(binding, stsEndpoint)
{
TrustVersion = TrustVersion.WSTrust13
};
factory.Credentials.ClientCertificate.SetCertificate(
StoreLocation.LocalMachine,
StoreName.My,
X509FindType.FindByThumbprint,
thumbprint);
var rst = new RequestSecurityToken
{
RequestType = WSTrust13Constants.RequestTypes.Issue,
AppliesTo = new EndpointAddress(svcEndpoint),
KeyType = WSTrust13Constants.KeyTypes.Symmetric
};
var channel = factory.CreateChannel();
var token = channel.Issue(rst);
return token;
}
The are only two steps to take:
1. Get a securityToken from ADFS
2. Create a WCF channel to the WCF service, using the securityToken.
Create the WCF client
To get started, let's create a console application that will be the client:internal class Program
{
private static void Main()
{
var stsEndpoint =
"https://myAdfsServer/adfs/services/trust/13/certificatemixed";
var clientCertificateThumbprint = "[put the thumbprint here]";
var svcEndpoint = "https://myDomain/myService.svc";
var token = GetToken(stsEndpoint, svcEndpoint);
var channel = CreateChannel<IMyService>(token,
svcEndpoint,
clientCertificateThumbprint);
channel.Foo();
}
}
How to get a secured token from ADFS?
The GetToken() method looks like this:private static SecurityToken GetToken(string stsEndpoint,
string svcEndpoint,
string thumbprint)
{
var binding = new
CertificateWSTrustBinding(SecurityMode.TransportWithMessageCredential);
var factory = new WSTrustChannelFactory(binding, stsEndpoint)
{
TrustVersion = TrustVersion.WSTrust13
};
factory.Credentials.ClientCertificate.SetCertificate(
StoreLocation.LocalMachine,
StoreName.My,
X509FindType.FindByThumbprint,
thumbprint);
var rst = new RequestSecurityToken
{
RequestType = WSTrust13Constants.RequestTypes.Issue,
AppliesTo = new EndpointAddress(svcEndpoint),
KeyType = WSTrust13Constants.KeyTypes.Symmetric
};
var channel = factory.CreateChannel();
var token = channel.Issue(rst);
return token;
}
Please note that I'm using a client certificate, and not Username/Password to authenticate.
With the token, the secured channel can be created, like this:
private static T CreateChannel<T>(SecurityToken token, string svcEndpoint) where T : class
{
var binding = new WS2007FederationHttpBinding(
WSFederationHttpSecurityMode.TransportWithMessageCredential
);
binding.Security.Message.EstablishSecurityContext = true;
binding.Security.Message.IssuedKeyType = SecurityKeyType.SymmetricKey;
var factory = new ChannelFactory<T>(binding, svcEndpoint);
factory.ConfigureChannelFactory();
// Turn Cardspace off
factory.Credentials.SupportInteractive = false;
var channel = factory.CreateChannelWithIssuedToken(token);
return channel;
}
vrijdag 26 april 2013
IoC containers compared
There are quite a few different IoC containers for .Net. How does one decide which IoC container to use? There are performance comparisons made, but as even the slowest IoC container only takes 0.04 milliseconds to resolve a dependency, performance is not a good discriminator.
I've decided to do a feature comparisons of Autofac, Structuremap and Unity. The results can be read below.
{
x.For<ISomethingService>()
.Use<SomethingService>();
}
builder.RegisterType<SomethingService>()
.As<ISomethingService>();
container.RegisterType<ISomethingService, SomethingService>();
builder.RegisterType<ThatService>()
.As<IThatService>()
.SingleInstance();
container.RegisterType<IThatService, ThatService>(
new ContainerControlledLifetimeManager());
Personally I don't like the term ContainerControlledLifetimeManager. Structuremap and Autofac have more obvious terms (Singleton and SingleInstance).
ObjectFactory.Initialize(x =>
{
x.Scan(a =>
{
a.Assembly("[AssemblyName]");
a.WithDefaultConventions();
});
}
Structuremap can autoscan assemblies, but you can't set any lifetimeoptions. If you want to do that, you have to write some custom code.
builder.RegisterAssemblyTypes(Assembly.Load("[AssemblyName]"))
.Where(t => t.Name.EndsWith("Repository"))
.AsImplementedInterfaces()
.SingleInstance();
Autofac has the option to set lifetimeoptions. In the example above all repositories are registered as singletons (SingleInstance).
As far as I know, Unity doesn't provide a way to autoscan assemblies out of the box.
With Unity you can autoregister assemblies by using Unity Auto Registration. (Thanks to Björn Bailleul for letting me know).
{
public UnitOfWorkRegistry()
{
For<IUnitOfWork>().Singleton().Use<UnitOfWork>();
}
}
ObjectFactory.Initialize(x =>
{
x.AddRegistry<UnitOfWorkRegistry>();
}
Structuremap doesn't have a way to set any properties or pass constructor variables to the Registry.
The current version 2.5.2 was released in January 2009, with a 2.6 release scheduled for no later than the end of January 2009.
At the moment of writing this blog the current version of Structuremap is 2.6.4.1 and updated on august 13, 2012. But there are more problematic errors, like the quickstart, which says you can use the next statement to register a type:
x.ForRequestedType<IValidator>()
.TheDefaultIsConcreteType<Validator>();
And indeed you can, but the ForRequestedType and TheDefaultIsConcreteType are deprecated, so they shouldn't be on the quickstart anymore.
Another major gap in the documentation is that there's no information about ASP.Net MVC integration on the Structuremap homepage.
1. Go to the Unity homepage (http://unity.codeplex.com/)
2. Click on the Documentation tab (http://unity.codeplex.com/documentation)
3. Click on the link to MSDN (http://msdn.microsoft.com/en-us/library/ff647202)
4. Click on the link to Unity 3 (http://msdn.microsoft.com/en-us/library/dn170416.aspx)
5. I've found only a link to a guide that can be downloaded, not what I was looking for.
6. Click on the link to Unity 2.0 (http://msdn.microsoft.com/en-us/library/ff663144.aspx)
7. Found the online info about configuring Unity (http://msdn.microsoft.com/en-us/library/ff660846(v=pandp.20).aspx)
The online documentation itself is extensive and tedious. I find it diffucult to navigate. For example the text about MVC integration is nowhere to be found.
The PDF that can be downloaded looks a lot more inviting than the online documentation.
I've decided to do a feature comparisons of Autofac, Structuremap and Unity. The results can be read below.
Basic registration
Basic registration is easy in each of the frameworks.
Structuremap
ObjectFactory.Initialize(x =>{
x.For<ISomethingService>()
.Use<SomethingService>();
}
Autofac
var builder = new ContainerBuilder();builder.RegisterType<SomethingService>()
.As<ISomethingService>();
Unity
IUnityContainer container = new UnityContainer();container.RegisterType<ISomethingService, SomethingService>();
Registration of a singleton
Setting lifetimescope options like "singleton" are easy in each of the frameworks.Structuremap
ObjectFactory.Initialize(x =>
{
x.For<IThatService>()
.Singleton()
.Use<ThatService>();
}
{
x.For<IThatService>()
.Singleton()
.Use<ThatService>();
}
Autofac
var builder = new ContainerBuilder();builder.RegisterType<ThatService>()
.As<IThatService>()
.SingleInstance();
Unity
IUnityContainer container = new UnityContainer();container.RegisterType<IThatService, ThatService>(
new ContainerControlledLifetimeManager());
Personally I don't like the term ContainerControlledLifetimeManager. Structuremap and Autofac have more obvious terms (Singleton and SingleInstance).
Autoscanning assemblies
Some frameworks provide ways to automatically register all or specific classes from an assembly. This can really be helpfull if for example you want to register all repositories in your solution and you don't want to write every registration by hand.Structuremap
{
x.Scan(a =>
{
a.Assembly("[AssemblyName]");
a.WithDefaultConventions();
});
}
Structuremap can autoscan assemblies, but you can't set any lifetimeoptions. If you want to do that, you have to write some custom code.
Autofac
var builder = new ContainerBuilder();builder.RegisterAssemblyTypes(Assembly.Load("[AssemblyName]"))
.Where(t => t.Name.EndsWith("Repository"))
.AsImplementedInterfaces()
.SingleInstance();
Autofac has the option to set lifetimeoptions. In the example above all repositories are registered as singletons (SingleInstance).
Unity
With Unity you can autoregister assemblies by using Unity Auto Registration. (Thanks to Björn Bailleul for letting me know).
Organizing registrations
In real-life you want to organize the registrations and not put everything in the global.asax.
Structuremap
public class UnitOfWorkRegistry : Registry{
public UnitOfWorkRegistry()
{
For<IUnitOfWork>().Singleton().Use<UnitOfWork>();
}
}
ObjectFactory.Initialize(x =>
{
x.AddRegistry<UnitOfWorkRegistry>();
}
Structuremap doesn't have a way to set any properties or pass constructor variables to the Registry.
Autofac
public class MyModule : Autofac.Module
{
public bool RandomProperty { get; set; }
protected override void Load(ContainerBuilder builder)
{
if (RandomProperty)
builder.RegisterType<UnitOfWork>().As<IUnitOfWork>().SingleInstance();
}
}
builder.RegisterModule(new MyModule() { RandomProperty = true });
Unity
I didn't find a way to use modules or registries with Unity. If anyone knows how to do this, please let me know.Documentation
Structuremap
The documentation of Structuremap is incomplete and outdated. For example the next text can be seen on the homepage of structuremap:
x.ForRequestedType<IValidator>()
.TheDefaultIsConcreteType<Validator>();
And indeed you can, but the ForRequestedType and TheDefaultIsConcreteType are deprecated, so they shouldn't be on the quickstart anymore.
Another major gap in the documentation is that there's no information about ASP.Net MVC integration on the Structuremap homepage.
Autofac
I have no criticism on the Autofac documentation. It is frequently updated (last update was 59 minutes ago since writing this text), and it's extensive. The most important chapters are easy to be found on the wiki on the Autofac homepage.Unity
I find it difficult to find the documentation on Unity. This is the path I had to follow for the online documentation:1. Go to the Unity homepage (http://unity.codeplex.com/)
2. Click on the Documentation tab (http://unity.codeplex.com/documentation)
3. Click on the link to MSDN (http://msdn.microsoft.com/en-us/library/ff647202)
4. Click on the link to Unity 3 (http://msdn.microsoft.com/en-us/library/dn170416.aspx)
5. I've found only a link to a guide that can be downloaded, not what I was looking for.
6. Click on the link to Unity 2.0 (http://msdn.microsoft.com/en-us/library/ff663144.aspx)
7. Found the online info about configuring Unity (http://msdn.microsoft.com/en-us/library/ff660846(v=pandp.20).aspx)
The online documentation itself is extensive and tedious. I find it diffucult to navigate. For example the text about MVC integration is nowhere to be found.
The PDF that can be downloaded looks a lot more inviting than the online documentation.
Final verdict
Autofac has the most extensive featureset when it comes to registration of classes. The documentation is up to date and easy to read.
Structuremap does a pretty good job too, but lacks in autoscanning features. The documentation is outdated.
Unity doesn't provide a way to autoscan assemblies, which leads to writing a lot of code yourself if you need that. (corrected by remark of Björn Bailleul) I didn't find a way to organize the registrations like the way it can be done with Autofac or Structuremap. The documentation is hard to find and difficult to navigate.
Abonneren op:
Posts (Atom)
