2009-07-11 Michael Barker <mike@middlesoft.co.uk>
[mono.git] / mcs / class / System.Web / System.Web.Security / UrlAuthorizationModule.cs
1 //
2 // System.Web.Security.UrlAuthorizationModule
3 //
4 // Authors:
5 //      Gonzalo Paniagua Javier (gonzalo@ximian.com)
6 //
7 // (C) 2002,2003 Ximian, Inc (http://www.ximian.com)
8 // Copyright (c) 2005 Novell, Inc (http://www.novell.com)
9 //
10 // Permission is hereby granted, free of charge, to any person obtaining
11 // a copy of this software and associated documentation files (the
12 // "Software"), to deal in the Software without restriction, including
13 // without limitation the rights to use, copy, modify, merge, publish,
14 // distribute, sublicense, and/or sell copies of the Software, and to
15 // permit persons to whom the Software is furnished to do so, subject to
16 // the following conditions:
17 // 
18 // The above copyright notice and this permission notice shall be
19 // included in all copies or substantial portions of the Software.
20 // 
21 // THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND,
22 // EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF
23 // MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND
24 // NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE
25 // LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION
26 // OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION
27 // WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.
28 //
29
30 using System.Configuration;
31 using System.Web.Configuration;
32 using System.Security.Permissions;
33 using System.Security.Principal;
34
35 namespace System.Web.Security
36 {
37         // CAS - no InheritanceDemand here as the class is sealed
38         [AspNetHostingPermission (SecurityAction.LinkDemand, Level = AspNetHostingPermissionLevel.Minimal)]
39         public sealed class UrlAuthorizationModule : IHttpModule
40         {
41                 [SecurityPermission (SecurityAction.Demand, UnmanagedCode = true)]
42                 public UrlAuthorizationModule ()
43                 {
44                 }
45
46                 public void Dispose ()
47                 {
48                 }
49
50                 public void Init (HttpApplication app)
51                 {
52                         app.AuthorizeRequest += new EventHandler (OnAuthorizeRequest);
53                 }
54
55                 void OnAuthorizeRequest (object sender, EventArgs args)
56                 {
57                         HttpApplication app = (HttpApplication) sender;
58                         HttpContext context = app.Context;
59                         if (context == null || context.SkipAuthorization)
60                                 return;
61
62                         HttpRequest req = context.Request;
63 #if NET_2_0
64                         AuthorizationSection config = (AuthorizationSection) WebConfigurationManager.GetSection ("system.web/authorization", req.Path, context);
65 #else
66                         AuthorizationConfig config = (AuthorizationConfig) context.GetConfig ("system.web/authorization");
67                         if (config == null)
68                                 return;
69 #endif
70                         if (!config.IsValidUser (context.User, req.HttpMethod)) {
71                                 HttpException e = new HttpException (401, "Unauthorized");
72                                 HttpResponse response = context.Response;
73                                 
74                                 response.StatusCode = 401;
75                                 response.Write (e.GetHtmlErrorMessage ());
76                                 app.CompleteRequest ();
77                         }
78                 }
79
80 #if NET_2_0
81                 [MonoTODO ("Not implemented")]
82                 public static bool CheckUrlAccessForPrincipal (string virtualPath, IPrincipal user, string verb)
83                 {
84                         throw new NotImplementedException ();
85                 }
86 #endif
87         }
88 }
89