Estoy usando el proxy .NET<\/A> para el inicio de sesión de la aplicación en una aplicación web. El proxy.config funciona si especifico URLs individuales. Por ejemplo: <\/P><serverUrl url="https:\/\/<\/A>myserver<\/EM>\/arcgis\/rest\/services\/myname<\/EM>\/MapServer<\/STRONG>"<\/SPAN><\/P> clientId="aaa"<\/SPAN><\/P> clientSecret="bbb"<\/SPAN><\/P> oauth2Endpoint="<\/SPAN>https:\/\/<\/A>myserver<\/EM>\/portal\/sharing\/rest\/oauth2"<\/SPAN><\/P> matchAll="true"\/><\/SPAN><\/P><\/P>Me gustaría usar el proxy para múltiples servicios en nuestro servidor, pero usar algo como esto resulta en tokens inválidos generados:<\/SPAN><\/P><serverUrl url="https:\/\/<\/A>myserver<\/EM>\/arcgis\/rest\/services\/<\/STRONG>"<\/SPAN><\/P> clientId="aaa"<\/SPAN><\/P> clientSecret="bbb"<\/SPAN><\/P> oauth2Endpoint="<\/SPAN>https:\/\/<\/A>myserver<\/EM>\/portal\/sharing\/rest\/oauth2"<\/SPAN><\/P> matchAll="true"\/><\/SPAN><\/P><\/P>¿Es posible especificar este tipo de coincidencia "parcial" en la URL usando el proxy?<\/STRONG><\/SPAN><\/P><\/P>De la documentación:<\/SPAN><\/P>Agregue una nueva <\/SPAN><serverUrl><\/CODE> entrada para cada servicio que usará el proxy. El proxy.config permite usar la etiqueta serverUrl para especificar uno o más servicios ArcGIS Server a los que el proxy reenviará solicitudes. La etiqueta serverUrl tiene los siguientes atributos:<\/SPAN><\/EM><\/P>url<\/STRONG>: Ubicación del servicio ArcGIS Server (u otra URL) para hacer proxy. Especifique ya sea la URL específica o la raíz (en cuyo caso debe establecer matchAll=\"false\").<\/EM><\/LI><\/UL><\/BODY><\/HTML>
<serverUrl url="
<serverUrl><\/CODE> entrada para cada servicio que usará el proxy. El proxy.config permite usar la etiqueta serverUrl para especificar uno o más servicios ArcGIS Server a los que el proxy reenviará solicitudes. La etiqueta serverUrl tiene los siguientes atributos:<\/SPAN><\/EM><\/P>url<\/STRONG>: Ubicación del servicio ArcGIS Server (u otra URL) para hacer proxy. Especifique ya sea la URL específica o la raíz (en cuyo caso debe establecer matchAll=\"false\").<\/EM><\/LI><\/UL><\/BODY><\/HTML>
Pam,
FYI:
IMPORTANT – as of today, 5/21/215, the release version of the proxy.ashx file for .NET and the most recent version of ArcServer do not play well together when token authentication is required. This is because 10.3 requires that token requests are done with a POST. the version above will attempt a GET resulting in a difficult to debug error. The issue can be found here: https://github.com/Esri/resource-proxy/issues/177A fix can be found here: https://github.com/esoekianto/resource-proxy-1/blob/45d9a49b58e3405c08a4f9e7157c491067b66760/DotNet/proxy.ashx - See more at: http://blogs.esri.com/esri/supportcenter/2015/04/07/setting-up-a-proxy/
IMPORTANT – as of today, 5/21/215, the release version of the proxy.ashx file for .NET and the most recent version of ArcServer do not play well together when token authentication is required. This is because 10.3 requires that token requests are done with a POST. the version above will attempt a GET resulting in a difficult to debug error.
The issue can be found here: https://github.com/Esri/resource-proxy/issues/177
A fix can be found here: https://github.com/esoekianto/resource-proxy-1/blob/45d9a49b58e3405c08a4f9e7157c491067b66760/DotNet/proxy.ashx
- See more at: http://blogs.esri.com/esri/supportcenter/2015/04/07/setting-up-a-proxy/
Not sure if the above applies to you but using the latest proxy may help.
Also I use a username and password with tokenServiceUri in your secured serviceUrls:
Robert, thank you for the response. I am using the latest proxy. The original post was a red herring. I don't think it's the way the serverUrl is specified as much as it is that the clientId and clientSecret don't work. Using the username and password works. Problem is, we generally avoid storing clear text login information in source code, even if the client can't see it. The clientId and clientSecret are more limited in access than a regular account. It seems my issue is related to using an application.
Are you registering your production website application url to get your client Id and secret?
Yes, but since it's not working, I'm wondering if it's misconfigured. I'm using Portal for ArcGIS Server 10.3, so I login to Portal > Add Item > An Application > Web Mapping with URL to the root of my site, Ready to Use, JavaScript API. I then view the item details in Portal and register it. I've tried a number of Redirect URI's thinking that might be the problem. I've tried the proxy, the page that calls the map, the home page. I've tried sharing with Everyone to eliminate that as an issue. The result is always an invalid token.
Have you looked at your web browsers web console to see what url it is using to request the token?
Robert, it's requesting something like:
https://<mywebserver>/<mysitefolder>/proxy/proxy.ashx?https://<myportalserver>/arcgis/rest/services/<myservice>/MapServer?f=json&dpi=96&transparent=true&format=png24&callback=dojo.io.script.jsonp_dojoIoScript1._jsonpCallback
It does generate a token, but the token is invalid, and I am prompted to login. The account used to create the app is the same account that created the service, so ownership shouldn't be an issue.
What I am wondering is if the url that the proxy is using for the actual token request is right. Do you see the actual token request?
Robert, here are the detailed logs:
2015-12-07 08:53:14 https://<myportalserver>/arcgis/rest/services/<myservice>/MapServer?f=json&dpi=96&transparent=true&format=png24&callback=dojo.io.script.jsonp_dojoIoScript1._jsonpCallback
2015-12-07 08:53:15 Matching credentials found in configuration file. OAuth 2.0 mode: True
2015-12-07 08:53:15 Service is secured by https://<myportalserver>/portal/sharing/rest/oauth2/: getting new token...
2015-12-07 08:53:15 Sending request!
2015-12-07 08:53:16 Token obtained: <mytoken1>
2015-12-07 08:53:16 Exchanging Portal token for Server-specific token for https://<myportalserver>/arcgis/rest/services/<myservice>/MapServer...
2015-12-07 08:53:16 Sending request!
2015-12-07 08:53:16 Token obtained: <mytoken2>
2015-12-07 08:53:16 Renewing token and trying again.
2015-12-07 08:53:16 Matching credentials found in configuration file. OAuth 2.0 mode: True
2015-12-07 08:53:16 Service is secured by https://<myportalserver>/portal/sharing/rest/oauth2/: getting new token...
2015-12-07 08:53:17 Token obtained: <mytoken3>
2015-12-07 08:53:17 Exchanging Portal token for Server-specific token for https://<myportalserver>/arcgis/rest/services/<myservice>/MapServer...
2015-12-07 08:53:17 Sending request!
2015-12-07 08:53:17 Token obtained: <mytoken4>
Los miembros registrados pueden publicar, seguir actualizaciones y más. ¿Nuevo aquí? Regístrate gratis.
Find useful guides, FAQs, and documents to help you navigate and make the most of Esri Community.