asp.net mvc forms身份认证

web.config配置

<authentication mode="Forms">
      <forms loginUrl="~/Login/Index" timeout="30" slidingExpiration="true"></forms>
</authentication>

增加一个Attribute类,继承自AuthorizeAttribute

public class CustomAuthorzieAttribute : AuthorizeAttribute
    {
        private string _controllerName = string.Empty;
        private string _actionName = string.Empty;

        /// <summary>
        /// base.OnAuthorization(filterContext)中会调用AuthorizeCore函数
        /// 
        /// 当AuthorizeCore返回false,则会继续调用HandleUnauthorizedRequest进行处理
        /// 
        /// 所以OnAuthorization是该类的总入口
        /// 
        /// </summary>
        /// <param name="filterContext"></param>
        public override void OnAuthorization(AuthorizationContext filterContext)
        {
            _controllerName = filterContext.ActionDescriptor.ControllerDescriptor.ControllerName;
            _actionName = filterContext.ActionDescriptor.ActionName;

            base.OnAuthorization(filterContext);
        }

        /// <summary>
        /// base.OnAuthorization来调用
        /// </summary>
        /// <param name="httpContext"></param>
        /// <returns></returns>
        protected override bool AuthorizeCore(HttpContextBase httpContext)
        {
            if (_controllerName.ToLower() == "login")
            {//登陆界面,不用身份认证,直接返回true
                return true;
            }

            if (!httpContext.User.Identity.IsAuthenticated)
            {
                return false;
            }

            return true;
        }

        /// <summary>
        /// 当AuthorizeCore返回false时候调用
        /// </summary>
        /// <param name="filterContext"></param>
        protected override void HandleUnauthorizedRequest(AuthorizationContext filterContext)
        {
            base.HandleUnauthorizedRequest(filterContext);
        }
    }

主要是去除登陆页面的验证判断

在App_Start文件夹中的FilterConfig中增加

public class FilterConfig
    {
        public static void RegisterGlobalFilters(GlobalFilterCollection filters)
        {
            filters.Add(new HandleErrorAttribute());
            filters.Add(new PermManagerWeb.Controllers.CustomAuthorzieAttribute());
        }
    }

登陆页面处理:

[HttpPost]
        public ActionResult DoLogin(LoginInfoViewModel loginInfo)
        {
            if (ModelState.IsValid)
            {//输入验证成功
                bool bLoginOK = Login.LoginSys(GetDataAccess(), loginInfo.UserName, loginInfo.UserPassword);
                if (bLoginOK)
                {//登陆成功
                    FormsAuthenticationTicket authTicket = new FormsAuthenticationTicket(
                        1,
                        loginInfo.UserName,
                        DateTime.Now,
                        DateTime.Now.AddMinutes(30),
                        false,
                        Request.UserHostAddress,
                        FormsAuthentication.FormsCookiePath);
                    string strCookie = FormsAuthentication.Encrypt(authTicket);
                    HttpCookie authCookie = new HttpCookie(FormsAuthentication.FormsCookieName, strCookie);
                    Response.Cookies.Add(authCookie);

                    return RedirectToAction("../Main");  
                }
                else
                {//登陆失败
                    return View("Index");
                }                              
            }
            else
            {//输入验证失败
                return View("Index");
            }
        }
  • 0
    点赞
  • 2
    收藏
    觉得还不错? 一键收藏
  • 0
    评论

“相关推荐”对你有帮助么?

  • 非常没帮助
  • 没帮助
  • 一般
  • 有帮助
  • 非常有帮助
提交
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值