I need to perform search impersonation in SharePoint 2010 for Claims users. To put this in context, I would like to first state how I get this to work with Windows accounts and then discuss Claims / WIF.
Windows Accounts
I can do this for "classic" Windows Integrated Authenticated users using:
WindowsImpersonationContext wic = null;
try
{
WindowsIdentity impersonatedUser = new WindowsIdentity("john.doe@mydomain");
wic = impersonatedUser.Impersonate();
// do impersonated work here...
// in my case this is a SharePoint KeywordQuery
}
finally
{
if (wic != null)
{
wic.Undo();
}
}
To get the above to work the impersonated account has to be in the same domain as the current user and I have to make sure that application pool owner is:
- A domain account in a domain that has a "domain functional level" of Windows 2003 or greater
- Has "act as part of the operating system" privilege on the local box
- Has "impersonate a client after authentication" privilege on the local box
(Note: if anyone can figure out how to get around the issue where the current account must be in the same domain as the impersonated account I am all ears.)
Claims Accounts
I would like to do the same with Claims / WIF accounts. These accounts are not necessarily associated with AD accounts (I need to assume they are not).
Is there a way to tell the STS that I want to impersonate a particular account and for it to give me the appropriate token for that account? I won't have the password of the user I am impersonating.
Quoting SharePoint Brew I have to contend with my code which runs on a SharePoint web front end (WFE) that calls a Query Processor via a WCF call. I want that WCF cal