我在这样的身份中获得索赔类型。
我只想要友好的名称" adlogon "作为我的索赔类型。我知道我们可以通过操纵字符串来做到这一点,但是有什么标准的方法。?
正常索赔规则是形式,例如:
c:[type ==" http://schemas.microsoft.com/ws/ws/2008/06/istentity/claims/windowsaccountname",issuer ==" ad ad Authority"] => eases(store =" Active Directory",types =(" http://schemas.xmlsoap.org/ws/2005/2005/2005/indistity/claims/emailaddress"),query ="; mail; {0}param = c.value);
您想要的东西:
c:[type ==" http://schemas.microsoft.com/ws/ws/2008/06/istentity/claims/windowsaccountname",issuer ==" ad ad Authority"] => dession(store =" Active Directory",types =(" http://schemas.xmlsoap.org/ws/2005/2005/2005/istentity/claims/adlogon"),query ="; [some attribute; [some attribute]; {0}",param = c.value);
要获得" adlogon",请使用:
c:[type ==" http://schemas.microsoft.com/ws/ws/2008/06/istentity/claims/windowsaccountname",issuer ==" ad ad Authority"] => essot(Store =" Active Directory",type =(" adlogon"),QUERY ="; [某些属性]; {0}",param = c.value);