如何在urlsession中验证代理?

时间:2017-03-31 07:36:31

标签: authentication proxy swift3 nsurlcredential urlsession

您好我正在尝试使用凭据添加代理到我的应用程序,但每当我尝试时, 我得到了以下(在Xcode中)控制台警告:

*** WARNING: CFMachPortSetInvalidationCallBack() called on a CFMachPort with a Mach port (0x900b) which does not have any send rights.  This is not going to work.  Callback function: 0x181bcf524

还提醒以下说明

Authentication for HTTP proxy
MyProxyHost
MyProxyPort

当我取消弹出窗口时,它正在调用以下方法

func urlSession(_ session: URLSession, task: URLSessionTask, didReceive challenge: URLAuthenticationChallenge, completionHandler: @escaping (URLSession.AuthChallengeDisposition, URLCredential?) -> Void)

我在 Xcode控制台中调试了挑战,并获得了以下debugDescription:

po challenge.protectionSpace.debugDescription
"<NSURLProtectionSpace: 0x12f685ad0>: Host: MyProxyHost, Server:http, Auth-Scheme:NSURLAuthenticationMethodHTTPBasic, Realm:(null), Port: MyProxyPort, Proxy:YES, Proxy-Type:http"

我的问题是如何处理代理身份验证?

我的代码:

func getURLCredential() -> URLCredential {

        let credential = URLCredential(user: user, password: password, persistence: URLCredential.Persistence.forSession)
        return credential
    }

从字典下面,我可以点击代理,但无法验证代理。

// Create an NSURLSessionConfiguration that uses the proxy
    let proxyDict: [AnyHashable: Any]? = [(kCFNetworkProxiesHTTPEnable as AnyHashable): Int(1), (kCFNetworkProxiesHTTPProxy as AnyHashable): proxyServerString, (kCFNetworkProxiesHTTPPort as AnyHashable): proxyPortNumber, (kCFProxyUsernameKey as AnyHashable): userNameKey, (kCFProxyPasswordKey as AnyHashable): password]
    let configuration = URLSessionConfiguration.default
    configuration.connectionProxyDictionary = proxyDict

我尝试了以下几种方法,但失败了:

let loginString = String(format: "%@:%@", user, password)
        let loginData = loginString.data(using: String.Encoding.utf8)!
        let base64LoginString = loginData.base64EncodedString()// base64EncodedData(options: [])
configuration.httpAdditionalHeaders = ["Authorization" : base64LoginString]

另一种方式:

let protectionSpace:URLProtectionSpace = URLProtectionSpace(host: proxyHost, port: proxyPort, protocol: "http", realm: nil, authenticationMethod: NSURLAuthenticationMethodHTTPBasic)
        let credentialStorage = URLCredentialStorage.shared//.allCredentials

        credentialStorage.set(getURLCredential(), for: protectionSpace)
        configuration.urlCredentialStorage = credentialStorage

另一种方式:

func urlSession(_ session: URLSession, didReceive challenge: URLAuthenticationChallenge, completionHandler: @escaping (URLSession.AuthChallengeDisposition, URLCredential?) -> Void) {
        print("Challenge:")

        guard challenge.previousFailureCount == 0 else {
            print("Previous Failure Count = \(challenge.previousFailureCount)")
            print("Cancelling Challenge\n")
            challenge.sender?.cancel(challenge)

            // Inform the user that the user name and password are incorrect
            completionHandler(.cancelAuthenticationChallenge, nil)
            return
        }
        print("Use Credential ....\n")

        completionHandler(.useCredential, self.getURLCredential())
    }

    func urlSession(_ session: URLSession, task: URLSessionTask, didReceive challenge: URLAuthenticationChallenge, completionHandler: @escaping (URLSession.AuthChallengeDisposition, URLCredential?) -> Void) {
        if challenge.previousFailureCount > 0
        {
            print("Alert Please check the credential")
            debugPrint("Alert Please check the credential")
            completionHandler(.cancelAuthenticationChallenge, nil)
        }

        challenge.sender?.use(self.getURLCredential(), for: challenge)
        completionHandler(.useCredential, self.getURLCredential())
    }

无法进行身份验证。

请建议我如何在swift 3中验证代理?

2 个答案:

答案 0 :(得分:1)

URLSessionConfiguration

需要其他标题。

let configuration.httpAdditionalHeaders = ["Proxy-Authorization":  Request.authorizationHeader(user: "user", password: "password") ]

答案 1 :(得分:0)

每种方法都有一个不同的错误:

  • Authorization标头用于向远程服务器(而非代理)进行身份验证。您可能想要设置Proxy-Authorization标头。

  • 您使用的kCFProxy *密钥在代理字典中无效(这就是为什么将字典用作数据结构从根本上来说是糟糕的设计,对那些设计未来API的人来说是BTW)。这些键仅在配置CF(Read|Write)Stream时使用。您需要kCFStreamPropertyHTTPProxyHost和朋友。有关有效的代理字典示例,请参见this closely related question

  • 您实现了用于处理身份验证挑战的会话级委托方法。不幸的是,该方法未调用代理身份验证。仅任务级委托方法(URLSession:task:...)被调用进行代理身份验证。