
Reputation: 83004

How to get HttpClient to pass credentials along with the request?

I have a web application (hosted in IIS) that talks to a Windows service. The Windows service is using the ASP.Net MVC Web API (self-hosted), and so can be communicated with over http using JSON. The web application is configured to do impersonation, the idea being that the user who makes the request to the web application should be the user that the web application uses to make the request to the service. The structure looks like this:

(The user highlighted in red is the user being referred to in the examples below.)

The web application makes requests to the Windows service using an HttpClient:

var httpClient = new HttpClient(new HttpClientHandler() 
                          UseDefaultCredentials = true

This makes the request to the Windows service, but does not pass the credentials over correctly (the service reports the user as IIS APPPOOL\ASP.NET 4.0). This is not what I want to happen.

If I change the above code to use a WebClient instead, the credentials of the user are passed correctly:

WebClient c = new WebClient
                       UseDefaultCredentials = true
c.DownloadStringAsync(new Uri("http://localhost/some/endpoint/"));

With the above code, the service reports the user as the user who made the request to the web application.

What am I doing wrong with the HttpClient implementation that is causing it to not pass the credentials correctly (or is it a bug with the HttpClient)?

The reason I want to use the HttpClient is that it has an async API that works well with Tasks, whereas the WebClient's asyc API needs to be handled with events.

Upvotes: 213

Views: 330228

Answers (11)

Maciej Gudanowicz
Maciej Gudanowicz

Reputation: 1

Having similar scenario I have used WinHttpHandler (replaced default SocketHttpHandler).

That works only on Windows hosting environment.


    var winHandler = new WinHttpHandler();
    winHandler.ServerCredentials = CredentialCache.DefaultNetworkCredentials;
    var client = new HttpClient(winHandler);

Upvotes: 0


Reputation: 536

Based on the solution from @Sean, I came up with this. With some mods this can also be used for GET and the returned string can be JsonSerializer.Deserialize(d) to an object or List of object.

public static string PostJsonString(string server, 
                                    string method, 
                                    HttpContent httpContent)
    string retval = string.Empty;
    string uri = server + method;

        // NOTE: the new HttpClientHandler() { UseDefaultCredentials = true } as the ctor
        //       parameter allows the existing user credentials to be used to make
        //       the HttpClient call.
        using (var httpClient = new HttpClient(new HttpClientHandler() { UseDefaultCredentials = true }))
            using (var response = httpClient.PostAsync(uri, httpContent))

                var result = response.Result;
                var readTask = result.Content.ReadAsStringAsync();

                retval = readTask.Result;



    return retval;

Upvotes: 0

Sifundo Dubazana
Sifundo Dubazana

Reputation: 1

string url = "";
System.Windows.Forms.WebBrowser webBrowser = new System.Windows.Forms.WebBrowser();

webBrowser.ScriptErrorsSuppressed = true;
webBrowser.Navigate(new Uri(url));

var webRequest = WebRequest.Create(url);
webRequest.Headers["Authorization"] = "Basic" + Convert.ToBase64String(Encoding.Default.GetBytes(Program.username + ";" + Program.password));
webRequest.Method = "POST";

Upvotes: -3


Reputation: 11

Set identity's impersonation to true and validateIntegratedModeConfiguration to false in web.config

    <authentication mode="Windows" />
      <deny users="?" />
    <identity impersonate="true"/>
    <validation validateIntegratedModeConfiguration="false" ></validation>

Upvotes: 1


Reputation: 2667

You can configure HttpClient to automatically pass credentials like this:

var myClient = new HttpClient(new HttpClientHandler() { UseDefaultCredentials = true });

Upvotes: 192


Reputation: 251

OK, so thanks to all of the contributors above. I am using .NET 4.6 and we also had the same issue. I spent time debugging System.Net.Http, specifically the HttpClientHandler, and found the following:

    if (ExecutionContext.IsFlowSuppressed())
      IWebProxy webProxy = (IWebProxy) null;
      if (this.useProxy)
        webProxy = this.proxy ?? WebRequest.DefaultWebProxy;
      if (this.UseDefaultCredentials || this.Credentials != null || webProxy != null && webProxy.Credentials != null)

So after assessing that the ExecutionContext.IsFlowSuppressed() might have been the culprit, I wrapped our Impersonation code as follows:

using (((WindowsIdentity)ExecutionContext.Current.Identity).Impersonate())
using (System.Threading.ExecutionContext.SuppressFlow())
    // HttpClient code goes here!

The code inside of SafeCaptureIdenity (not my spelling mistake), grabs WindowsIdentity.Current() which is our impersonated identity. This is being picked up because we are now suppressing flow. Because of the using/dispose this is reset after invocation.

It now seems to work for us, phew!

Upvotes: 25


Reputation: 2139

In .NET Core, I managed to get a System.Net.Http.HttpClient with UseDefaultCredentials = true to pass through the authenticated user's Windows credentials to a back end service by using WindowsIdentity.RunImpersonated.

HttpClient client = new HttpClient(new HttpClientHandler { UseDefaultCredentials = true } );
HttpResponseMessage response = null;

if (identity is WindowsIdentity windowsIdentity)
    await WindowsIdentity.RunImpersonated(windowsIdentity.AccessToken, async () =>
        var request = new HttpRequestMessage(HttpMethod.Get, url)
        response = await client.SendAsync(request);

Upvotes: 15

Paulo Augusto Batista
Paulo Augusto Batista

Reputation: 61

It worked for me after I set up a user with internet access in the Windows service.

In my code:

HttpClientHandler handler = new HttpClientHandler();
handler.Proxy = System.Net.WebRequest.DefaultWebProxy;
handler.Proxy.Credentials = System.Net.CredentialCache.DefaultNetworkCredentials;
HttpClient httpClient = new HttpClient(handler)

Upvotes: 6


Reputation: 4159

I was also having this same problem. I developed a synchronous solution thanks to the research done by @tpeczek in the following SO article: Unable to authenticate to ASP.NET Web Api service with HttpClient

My solution uses a WebClient, which as you correctly noted passes the credentials without issue. The reason HttpClient doesn't work is because of Windows security disabling the ability to create new threads under an impersonated account (see SO article above.) HttpClient creates new threads via the Task Factory thus causing the error. WebClient on the other hand, runs synchronously on the same thread thereby bypassing the rule and forwarding its credentials.

Although the code works, the downside is that it will not work async.

var wi = (System.Security.Principal.WindowsIdentity)HttpContext.Current.User.Identity;

var wic = wi.Impersonate();
    var data = JsonConvert.SerializeObject(new
        Property1 = 1,
        Property2 = "blah"

    using (var client = new WebClient { UseDefaultCredentials = true })
        client.Headers.Add(HttpRequestHeader.ContentType, "application/json; charset=utf-8");
        client.UploadData("http://url/api/controller", "POST", Encoding.UTF8.GetBytes(data));
catch (Exception exc)
    // handle exception

Note: Requires NuGet package: Newtonsoft.Json, which is the same JSON serializer WebAPI uses.

Upvotes: 76


Reputation: 3236

Ok so I took Joshoun code and made it generic. I am not sure if I should implement singleton pattern on SynchronousPost class. Maybe someone more knowledgeble can help.


//I assume you have your own concrete type. In my case I have am using code first with a class called FileCategory

FileCategory x = new FileCategory { CategoryName = "Some Bs"};
SynchronousPost<FileCategory>test= new SynchronousPost<FileCategory>();
test.PostEntity(x, "/api/ApiFileCategories"); 

Generic Class here. You can pass any type

 public class SynchronousPost<T>where T :class
        public SynchronousPost()
            Client = new WebClient { UseDefaultCredentials = true };

        public void PostEntity(T PostThis,string ApiControllerName)//The ApiController name should be "/api/MyName/"
            //this just determines the root url. 
            Client.BaseAddress = string.Format(
            System.Web.HttpContext.Current.Request.Url.Port != 80) ? "{0}://{1}:{2}" : "{0}://{1}",
            Client.Headers.Add(HttpRequestHeader.ContentType, "application/json;charset=utf-8");
                                 ApiControllerName, "Post", 
        private WebClient Client  { get; set; }

My Api classs looks like this, if you are curious

public class ApiFileCategoriesController : ApiBaseController
    public ApiFileCategoriesController(IMshIntranetUnitOfWork unitOfWork)
        UnitOfWork = unitOfWork;

    public IEnumerable<FileCategory> GetFiles()
        return UnitOfWork.FileCategories.GetAll().OrderBy(x=>x.CategoryName);
    public FileCategory GetFile(int id)
        return UnitOfWork.FileCategories.GetById(id);
    //Post api/ApileFileCategories

    public HttpResponseMessage Post(FileCategory fileCategory)
        return new HttpResponseMessage();

I am using ninject, and repo pattern with unit of work. Anyways, the generic class above really helps.

Upvotes: 3


Reputation: 5603

What you are trying to do is get NTLM to forward the identity on to the next server, which it cannot do - it can only do impersonation which only gives you access to local resources. It won't let you cross a machine boundary. Kerberos authentication supports delegation (what you need) by using tickets, and the ticket can be forwarded on when all servers and applications in the chain are correctly configured and Kerberos is set up correctly on the domain. So, in short you need to switch from using NTLM to Kerberos.

For more on Windows Authentication options available to you and how they work start at:

Upvotes: 33

Related Questions