Showing posts with label claims. Show all posts
Showing posts with label claims. Show all posts

Sunday, November 23, 2014

Sharepoint Custom Claims provider - Fill Resolve method implementation.


In order to have the fillresolve methods to be triggered, you need to have the property SupportsResolve to true.

We will have 2 overload methods of fillResolve in your custom claims provider. You need to implement both of these methods.

protected override void FillResolve(Uri context, string[] entityTypes, string resolveInput, List<Microsoft.SharePoint.WebControls.PickerEntity> resolved) - This method will be called when you enter name in the text box and click resolve.

and

protected override void FillResolve(Uri context, string[] entityTypes, SPClaim resolveInput, List<Microsoft.SharePoint.WebControls.PickerEntity> resolved) - This method will be called when you enter name in the people picker and click add, it will call fillresolve as it needs to resolve the name as soon as we have an entry in textbox.


You need to implement the Picker entity; Use SPClaim constructor instead of CreateClaim constructor.

private PickerEntity GetPickerEntity(string ClaimValue, string type)
{
PickerEntity pe = CreatePickerEntity();
 
/* in my case, emailaddress is the identity claim. Make sure that the last parameter TrustedProvider is correct, otherwise name resolution will not be correct. */

pe.Claim = new SPClaim("http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress", ClaimValue, ClaimValueType, SPOriginalIssuers.Format(SPOriginalIssuerType.TrustedProvider, "Trusted User"));  

pe.EntityData[PeopleEditorEntityDataKeys.AccountName] = ClaimValue;
pe.EntityData[PeopleEditorEntityDataKeys.Email] = ClaimValue;
pe.DisplayText = ClaimValue;
pe.EntityData[PeopleEditorEntityDataKeys.DisplayName] = ClaimValue;
pe.EntityType = SPClaimEntityTypes.User;
pe.IsResolved = true;
return pe;
}

More Information

http://msdn.microsoft.com/en-us/library/microsoft.sharepoint.administration.claims.spclaim.spclaim.aspx

http://blogs.technet.com/b/speschka/archive/2010/05/25/replacing-the-out-of-box-name-resolution-in-sharepoint-2010-part-2.aspx

http://msdn.microsoft.com/en-us/library/microsoft.sharepoint.administration.claims.spclaimprovider.fillsearch.aspx

Thursday, February 2, 2012

Sharepoint 2010 : How to map Claim Provider with Token issuer

The main purpose of a custom claims provide is 
1) Name resolution & 
2) Claims augmentation. 

The token issuer (for example ADFS) issues claims and the custom claims provider will provide name resolution and augment for those claims issued by the token issuer. Thus, you need to map both claims provider and token issuer. If we do not map them, then the claims we resolve in the search dialog or type-in control will not map to the account name or other claim that someone logs in with.

Object Model Code

            SPSecurityTokenServiceManager manager = SPSecurityTokenServiceManager.Local;
            SPTrustedLoginProviderCollection providers=manager.TrustedLoginProviders;
          
            foreach (SPTrustedLoginProvider i in providers) //I have looped all the trusted provider
            {
//you can check the name before applying the custom claim provider
                i.ClaimProviderName = "CustomClaimsProviderName";
                i.Update();
            }
            manager.Update();



Powershell Script

$trustedProv = Get-SPTrustedIdentityTokenIssuer -Identity "Trusted Login Provider Name"
$trustedProv.ClaimProviderName = “Custom Claims Provider Name”  
$trustedProv.Update()

Thursday, January 26, 2012

How to remove “All user” from people picker

We can disable the “All Users” from people picker via the below powershell script.

$claimMgr = Get-SPClaimProviderManager
$allUser = get-spclaimprovider –identity "AllUsers"
$allUser.IsEnabled = $false
$claimMgr.Update()

For Enabling it, use the below one
 
$claimMgr = Get-SPClaimProviderManager
$allUser = get-spclaimprovider –identity "AllUsers"
$allUser.IsEnabled = $true
$claimMgr.Update()

Friday, December 23, 2011

How to disable or hide the “All Users” from people picker

When we have multiple tenants in sharepoint 2010 and have different identity provider, in people picker you might see all the trusted provider being listed in the result of "All Users".


We can disable the “All Users” from people picker via the below powershell script.

$cpm = Get-SPClaimProviderManager
$au = get-spclaimprovider –identity "AllUsers"
$au.IsEnabled = $false
$cpm.Update()

Saturday, August 6, 2011

Sharepoint 2010 Claims site - Add FBA users to Sharepoint group programmatically

Adding FBA users to Sharepoint group programmatically is simple. The hunch is the format "i:0#.f|fbamembershipprovider|" + username

In the format, 
i  - stands for Identity provider 
f  - stands for fba authentication
fbamembershipprovider  - is my providername

Here you go, a simple sample that servers the pupose.

SPSite sitename = new SPSite("SiteURL");
        SPWeb spWeb = sitename.OpenWeb();
        
        String strusername= "i:0#.f|fbamembershipprovider|" + UsernameTextbox.Text;
        spWeb.AllUsers.Add[strusername, EmailTextbox.Text, UsernameTextbox.Text, strusername];
       
         
            if (spUser != null)
            {
                SPGroup spGroup = spWeb.Groups["GROUP_NAME"];
            if (spGroup != null)
            spGroup.AddUser(spUser);
            }


Happy Coding :)