Asp.Net MVC验证用户登录授权

/// <summary>
/// 验证用户登录授权
/// </summary>
public sealed class IsLoginAttribute : FilterAttribute, IAuthorizationFilter
{
	/// <summary>
	/// 是否验证登录,true需要验证,false不用验证
	/// </summary>
	public bool IsCheck;
	public void OnAuthorization(AuthorizationContext filterContext)
	{
		//判断是否跳过授权过滤器
		if (filterContext.ActionDescriptor.IsDefined(typeof(AllowAnonymousAttribute), true)
			|| filterContext.ActionDescriptor.ControllerDescriptor.IsDefined(typeof(AllowAnonymousAttribute), true))
		{
			return;
		}
		if (IsCheck)
		{
			object user = filterContext.HttpContext.Session["user"];
			bool isAjax = filterContext.HttpContext.Request.IsAjaxRequest();
			if (isAjax)
			{
				if (user == null)
				{
					//ContentResult content = new ContentResult();
					//content.Content = json;
					filterContext.Result = new HttpStatusCodeResult(999, "Not logged in");//content 
				}
			}
			else
			{
				string url = filterContext.HttpContext.Request.Url.LocalPath;
				string url2 = url.ToLower();
				string[] urlList = { "/manager/menu", "/manager/index" };
				if (user == null)
				{
					if (urlList.Contains(url2))
					{
						ActionResult result = new RedirectResult("/Manager/Login");
						filterContext.Result = result;
					}
					else if (filterContext.HttpContext.Request.HttpMethod == "GET")
					{
						ActionResult result = new RedirectResult("/Manager/Login");
						filterContext.Result = result;
					}
				}
			}
		}
	}
}

 

方式二,写个类继承AuthorizeAttribute,然后过滤验证请求:


public class LoginFilter : AuthorizeAttribute
{
    public override void OnAuthorization(AuthorizationContext filterContext)
    {
	    //判断是否跳过授权过滤器
		if (filterContext.ActionDescriptor.IsDefined(typeof(AllowAnonymousAttribute), true)
			|| filterContext.ActionDescriptor.ControllerDescriptor.IsDefined(typeof(AllowAnonymousAttribute), true))
		{
			return;
		}
			
        var session = filterContext.HttpContext.Session;
        bool isAjax = filterContext.HttpContext.Request.IsAjaxRequest();
        LoginInfo loginInfo = session["LoginInfo"] as LoginInfo;
		if (loginInfo == null)
        {
            if (isAjax)
            {
                filterContext.Result = new HttpUnauthorizedResult("登录失效,请登录");
            }
            else
            {
                filterContext.Result = new RedirectResult(ConfigurationManager.AppSettings["loginpage"]);
            }
            return;
        } 
    }
}

//整个控制器所有方法都要验证登录
[LoginFilter]
public class BaseController : Controller
{

}


public class HomeController : Controller
{
         //不验证登录
        [AllowAnonymous]
        public ActionResult Index()
        {
            return View();
        }
}


public class DefaultController : Controller
{
       //验证登录
       [LoginFilter]
        public ActionResult Index()
        {
            return View();
        }
}

 

 

  • 0
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 打赏
    打赏
  • 0
    评论

“相关推荐”对你有帮助么?

  • 非常没帮助
  • 没帮助
  • 一般
  • 有帮助
  • 非常有帮助
提交
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包

打赏作者

王焜棟琦

你的鼓励将是我创作的最大动力

¥1 ¥2 ¥4 ¥6 ¥10 ¥20
扫码支付:¥1
获取中
扫码支付

您的余额不足,请更换扫码支付或充值

打赏作者

实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值