首頁 >後端開發 >php教程 >如何使用 PHP 驗證 WS-Security 保護的 Web 服務的請求?

如何使用 PHP 驗證 WS-Security 保護的 Web 服務的請求?

Patricia Arquette
Patricia Arquette原創
2024-11-08 16:23:02658瀏覽

How to Authenticate Requests to a WS-Security Protected Web Service Using PHP?

使用PHP 連接到受WS-Security 保護的Web 服務

嘗試連接到需要密碼保護並使用HTTPS 的Web 服務時,您可能會遇到身份驗證問題。這是因為 PHP 腳本在定義服務後立即發起請求,可能在建立任何身份驗證之前。


要解決此問題,您需要擴充 SoapHeader類別來建立符合 Wsse 的驗證。以下程式碼示範了這一點:

class WsseAuthHeader extends SoapHeader {

    private $wss_ns = 'http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-secext-1.0.xsd';

    function __construct($user, $pass, $ns = null) {
        if ($ns) {
            $this->wss_ns = $ns;

        $auth = new stdClass();
        $auth->Username = new SoapVar($user, XSD_STRING, NULL, $this->wss_ns, NULL, $this->wss_ns);
        $auth->Password = new SoapVar($pass, XSD_STRING, NULL, $this->wss_ns, NULL, $this->wss_ns);

        $username_token = new stdClass();
        $username_token->UsernameToken = new SoapVar($auth, SOAP_ENC_OBJECT, NULL, $this->wss_ns, 'UsernameToken', $this->wss_ns);

        $security_sv = new SoapVar(
            new SoapVar($username_token, SOAP_ENC_OBJECT, NULL, $this->wss_ns, 'UsernameToken', $this->wss_ns),
            SOAP_ENC_OBJECT, NULL, $this->wss_ns, 'Security', $this->wss_ns);
        parent::__construct($this->wss_ns, 'Security', $security_sv, true);


擴展SoapHeader 後,您可以使用它來驗證請求:

$wsse_header = new WsseAuthHeader($username, $password);
$x = new SoapClient('{...}', array("trace" => 1, "exception" => 0));

使用Nonce 和Timestamp

如果您需要將WS-Security 與nonce 和時間戳一起使用,您可以使用Peter 提供的更新版本:

class WsseAuthHeader extends SoapHeader
    private $wss_ns = 'http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-secext-1.0.xsd';
    private $wsu_ns = 'http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-utility-1.0.xsd';

    function __construct($user, $pass)
        $created    = gmdate('Y-m-d\TH:i:s\Z');
        $nonce      = mt_rand();
        $passdigest = base64_encode(pack('H*', sha1(pack('H*', $nonce) . pack('a*', $created) . pack('a*', $pass))));

        $auth           = new stdClass();
        $auth->Username = new SoapVar($user, XSD_STRING, NULL, $this->wss_ns, NULL, $this->wss_ns);
        $auth->Password = new SoapVar($pass, XSD_STRING, NULL, $this->wss_ns, NULL, $this->wss_ns);
        $auth->Nonce    = new SoapVar($passdigest, XSD_STRING, NULL, $this->wss_ns, NULL, $this->wss_ns);
        $auth->Created  = new SoapVar($created, XSD_STRING, NULL, $this->wss_ns, NULL, $this->wsu_ns);

        $username_token                = new stdClass();
        $username_token->UsernameToken = new SoapVar($auth, SOAP_ENC_OBJECT, NULL, $this->wss_ns, 'UsernameToken', $this->wss_ns);

        $security_sv = new SoapVar(
            new SoapVar($username_token, SOAP_ENC_OBJECT, NULL, $this->wss_ns, 'UsernameToken', $this->wss_ns),
            SOAP_ENC_OBJECT, NULL, $this->wss_ns, 'Security', $this->wss_ns);
        parent::__construct($this->wss_ns, 'Security', $security_sv, true);

透過利用這些技術,您可以使用PHP 成功連接到受WS-Security 保護的Web 服務並對其要求進行身份驗證。

以上是如何使用 PHP 驗證 WS-Security 保護的 Web 服務的請求?的詳細內容。更多資訊請關注PHP中文網其他相關文章!
