Authorize:限定角色中用户访问Action;
解释:用于登录界面,Web.config页面中添加代码
<authenticationmode="Forms">
<formsloginUrl="~/Account/Login"timeout="2880" />
</authentication>
指定登录Controller和Action
[HttpPost]
[Authorize(Users="LiWei,dongzhou")]
[Authorize(Roles="Admin")]
[AllowAnonymous]//包括匿名用户都能访问