asp.net Forms身份驗(yàn)證和基于角色的權(quán)限訪問
更新時(shí)間:2009年09月25日 15:14:33 作者:
Forms身份驗(yàn)證用來判斷是否合法用戶,當(dāng)用戶合法后,再通過用戶的角色決定能訪問的頁面。
主要思想:Forms身份驗(yàn)證用來判斷是否合法用戶,當(dāng)用戶合法后,再通過用戶的角色決定能訪問的頁面。
具體步驟:
1、創(chuàng)建一個(gè)網(wǎng)站,結(jié)構(gòu)如下:
網(wǎng)站根目錄
Admin目錄 ----> 管理員目錄
Manager.aspx ----> 管理員可以訪問的頁面
Users目錄 ----> 注冊用戶目錄
Welcome.aspx ----> 注冊用戶可以訪問的頁面
Error目錄 ----> 錯(cuò)誤提示目錄
AccessError.htm ----> 訪問錯(cuò)誤的提示頁面
default.aspx ----> 網(wǎng)站默認(rèn)頁面
login.aspx ----> 網(wǎng)站登錄頁面
web.config ----> 網(wǎng)站配置文件
2、配置web.config如下:
<configuration>
<system.web>
<!--設(shè)置Forms身份驗(yàn)證-->
<authentication mode="Forms">
<forms loginUrl="Login.aspx" name="MyWebApp.APSXAUTH" path="/" protection="All" timeout="30"/>
</authentication>
<authorization>
<allow users="*"/>
</authorization>
</system.web>
</configuration>
<!--設(shè)置Admin目錄的訪問權(quán)限-->
<location path="Admin">
<system.web>
<authorization>
<allow roles="Admin"/>
<deny users="?"/>
</authorization>
</system.web>
</location>
<!--設(shè)置Users目錄的訪問權(quán)限-->
<location path="Users">
<system.web>
<authorization>
<allow roles="User"/>
<deny users="?"/>
</authorization>
</system.web>
</location>
3、在login.aspx頁面的登錄部分代碼如下:
protected void btnLogin_Click(object sender, EventArgs e)
{
//Forms身份驗(yàn)證初始化
FormsAuthentication.Initialize();
//驗(yàn)證用戶輸入并得到登錄用戶,txtName是用戶名稱,txtPassword是登錄密碼
UserModel um = ValidUser(txtName.Text.Trim(),txtPassword.Text.Trim());
if (um != null)
{
//創(chuàng)建身份驗(yàn)證票據(jù)
FormsAuthenticationTicket ticket = new FormsAuthenticationTicket(1,
um.Name,
DateTime.Now,
DateTime.Now.AddMinutes(30),
true,
um.Roles,//用戶所屬的角色字符串
FormsAuthentication.FormsCookiePath);
//加密身份驗(yàn)證票據(jù)
string hash = FormsAuthentication.Encrypt(ticket);
//創(chuàng)建要發(fā)送到客戶端的cookie
HttpCookie cookie = new HttpCookie(FormsAuthentication.FormsCookieName, hash);
if (ticket.IsPersistent)
{
cookie.Expires = ticket.Expiration;
}
//把準(zhǔn)備好的cookie加入到響應(yīng)流中
Response.Cookies.Add(cookie);
//轉(zhuǎn)發(fā)到請求的頁面
Response.Redirect(FormsAuthentication.GetRedirectUrl(um.Name,false));
}
else
{
ClientScriptManager csm = this.Page.ClientScript;
csm.RegisterStartupScript(this.GetType(), "error_tip", "alert('用戶名或密碼錯(cuò)誤!身份驗(yàn)證失?。?);", true);
}
}
//驗(yàn)證用戶
private UserModel ValidUser(string name, string password)
{
return new UserService().Validate(name, password);
}
4、給網(wǎng)站添加處理程序Global.asax,其中通用身份驗(yàn)證代碼如下:
//改造原來的User,給其添加一個(gè)用戶所屬的角色數(shù)據(jù)
protected void Application_AuthenticateRequest(object sender, EventArgs e)
{
if (HttpContext.Current.User != null )
{
if (HttpContext.Current.User.Identity.IsAuthenticated)
{
if (HttpContext.Current.User.Identity is FormsIdentity)
{
FormsIdentity id = (FormsIdentity)HttpContext.Current.User.Identity;
FormsAuthenticationTicket ticket = id.Ticket;
string userData = ticket.UserData;
string[] roles = userData.Split(',');
//重建HttpContext.Current.User,加入用戶擁有的角色數(shù)組
HttpContext.Current.User = new GenericPrincipal(id, roles);
}
}
}
}
5、在Admin目錄中Manager.aspx頁面加載代碼如下:
protected void Page_Load(object sender, EventArgs e)
{
//判斷通過身份驗(yàn)證的用戶是否有權(quán)限訪問本頁面
FormsIdentity id = (FormsIdentity)HttpContext.Current.User.Identity;
//判斷通過身份驗(yàn)證的用戶是否是Admin角色
if (!id.Ticket.UserData.Contains("Admin"))
{
//跳轉(zhuǎn)到訪問權(quán)限不夠的錯(cuò)誤提示頁面
Response.Redirect("~/Error/AccessError.htm", true);
}
}
//安全退出按鈕的代碼
protected void btnExit_Click(object sender, EventArgs e)
{
//注銷票據(jù)
FormsAuthentication.SignOut();
ClientScriptManager csm = this.Page.ClientScript;
csm.RegisterStartupScript(this.GetType(), "exit_tip", "alert('您已經(jīng)安全退出了!');", true);
}
6、在Users目錄中Welcome.aspx頁面加載代碼如下:
protected void Page_Load(object sender, EventArgs e)
{
//判斷通過身份驗(yàn)證的用戶是否有權(quán)限訪問本頁面
FormsIdentity id = (FormsIdentity)HttpContext.Current.User.Identity;
//判斷通過身份驗(yàn)證的用戶是否是User角色
if (!id.Ticket.UserData.Contains("User"))
{
//跳轉(zhuǎn)到訪問權(quán)限不夠的錯(cuò)誤提示頁面
Response.Redirect("~/Error/AccessError.htm", true);
}
}
//安全退出按鈕的代碼
protected void btnExit_Click(object sender, EventArgs e)
{
//注銷票據(jù)
FormsAuthentication.SignOut();
ClientScriptManager csm = this.Page.ClientScript;
csm.RegisterStartupScript(this.GetType(), "exit_tip", "alert('您已經(jīng)安全退出了!');", true);
}
測試結(jié)果:
數(shù)據(jù):
假設(shè)有3個(gè)用戶,如下:
------------------------------------------
用戶名 密碼 角色字符串
------------------------------------------
sa sa Admin,User
admin admin Admin
user user User
------------------------------------------
測試:
如果使用admin登錄,只能訪問Admin目錄的Manager.aspx頁面;
如果使用user登錄,只能訪問Users目錄的Welcome.aspx頁面;
使用sa登錄,既能訪問Admin目錄的Manager.aspx頁面,又能訪問Users目錄的Welcome.aspx頁面。
注意:測試時(shí)注意及時(shí)點(diǎn)擊安全退出按鈕,否則影響測試結(jié)果。
具體步驟:
1、創(chuàng)建一個(gè)網(wǎng)站,結(jié)構(gòu)如下:
網(wǎng)站根目錄
Admin目錄 ----> 管理員目錄
Manager.aspx ----> 管理員可以訪問的頁面
Users目錄 ----> 注冊用戶目錄
Welcome.aspx ----> 注冊用戶可以訪問的頁面
Error目錄 ----> 錯(cuò)誤提示目錄
AccessError.htm ----> 訪問錯(cuò)誤的提示頁面
default.aspx ----> 網(wǎng)站默認(rèn)頁面
login.aspx ----> 網(wǎng)站登錄頁面
web.config ----> 網(wǎng)站配置文件
2、配置web.config如下:
復(fù)制代碼 代碼如下:
<configuration>
<system.web>
<!--設(shè)置Forms身份驗(yàn)證-->
<authentication mode="Forms">
<forms loginUrl="Login.aspx" name="MyWebApp.APSXAUTH" path="/" protection="All" timeout="30"/>
</authentication>
<authorization>
<allow users="*"/>
</authorization>
</system.web>
</configuration>
<!--設(shè)置Admin目錄的訪問權(quán)限-->
<location path="Admin">
<system.web>
<authorization>
<allow roles="Admin"/>
<deny users="?"/>
</authorization>
</system.web>
</location>
<!--設(shè)置Users目錄的訪問權(quán)限-->
<location path="Users">
<system.web>
<authorization>
<allow roles="User"/>
<deny users="?"/>
</authorization>
</system.web>
</location>
3、在login.aspx頁面的登錄部分代碼如下:
復(fù)制代碼 代碼如下:
protected void btnLogin_Click(object sender, EventArgs e)
{
//Forms身份驗(yàn)證初始化
FormsAuthentication.Initialize();
//驗(yàn)證用戶輸入并得到登錄用戶,txtName是用戶名稱,txtPassword是登錄密碼
UserModel um = ValidUser(txtName.Text.Trim(),txtPassword.Text.Trim());
if (um != null)
{
//創(chuàng)建身份驗(yàn)證票據(jù)
FormsAuthenticationTicket ticket = new FormsAuthenticationTicket(1,
um.Name,
DateTime.Now,
DateTime.Now.AddMinutes(30),
true,
um.Roles,//用戶所屬的角色字符串
FormsAuthentication.FormsCookiePath);
//加密身份驗(yàn)證票據(jù)
string hash = FormsAuthentication.Encrypt(ticket);
//創(chuàng)建要發(fā)送到客戶端的cookie
HttpCookie cookie = new HttpCookie(FormsAuthentication.FormsCookieName, hash);
if (ticket.IsPersistent)
{
cookie.Expires = ticket.Expiration;
}
//把準(zhǔn)備好的cookie加入到響應(yīng)流中
Response.Cookies.Add(cookie);
//轉(zhuǎn)發(fā)到請求的頁面
Response.Redirect(FormsAuthentication.GetRedirectUrl(um.Name,false));
}
else
{
ClientScriptManager csm = this.Page.ClientScript;
csm.RegisterStartupScript(this.GetType(), "error_tip", "alert('用戶名或密碼錯(cuò)誤!身份驗(yàn)證失?。?);", true);
}
}
//驗(yàn)證用戶
private UserModel ValidUser(string name, string password)
{
return new UserService().Validate(name, password);
}
4、給網(wǎng)站添加處理程序Global.asax,其中通用身份驗(yàn)證代碼如下:
復(fù)制代碼 代碼如下:
//改造原來的User,給其添加一個(gè)用戶所屬的角色數(shù)據(jù)
protected void Application_AuthenticateRequest(object sender, EventArgs e)
{
if (HttpContext.Current.User != null )
{
if (HttpContext.Current.User.Identity.IsAuthenticated)
{
if (HttpContext.Current.User.Identity is FormsIdentity)
{
FormsIdentity id = (FormsIdentity)HttpContext.Current.User.Identity;
FormsAuthenticationTicket ticket = id.Ticket;
string userData = ticket.UserData;
string[] roles = userData.Split(',');
//重建HttpContext.Current.User,加入用戶擁有的角色數(shù)組
HttpContext.Current.User = new GenericPrincipal(id, roles);
}
}
}
}
5、在Admin目錄中Manager.aspx頁面加載代碼如下:
復(fù)制代碼 代碼如下:
protected void Page_Load(object sender, EventArgs e)
{
//判斷通過身份驗(yàn)證的用戶是否有權(quán)限訪問本頁面
FormsIdentity id = (FormsIdentity)HttpContext.Current.User.Identity;
//判斷通過身份驗(yàn)證的用戶是否是Admin角色
if (!id.Ticket.UserData.Contains("Admin"))
{
//跳轉(zhuǎn)到訪問權(quán)限不夠的錯(cuò)誤提示頁面
Response.Redirect("~/Error/AccessError.htm", true);
}
}
//安全退出按鈕的代碼
protected void btnExit_Click(object sender, EventArgs e)
{
//注銷票據(jù)
FormsAuthentication.SignOut();
ClientScriptManager csm = this.Page.ClientScript;
csm.RegisterStartupScript(this.GetType(), "exit_tip", "alert('您已經(jīng)安全退出了!');", true);
}
6、在Users目錄中Welcome.aspx頁面加載代碼如下:
復(fù)制代碼 代碼如下:
protected void Page_Load(object sender, EventArgs e)
{
//判斷通過身份驗(yàn)證的用戶是否有權(quán)限訪問本頁面
FormsIdentity id = (FormsIdentity)HttpContext.Current.User.Identity;
//判斷通過身份驗(yàn)證的用戶是否是User角色
if (!id.Ticket.UserData.Contains("User"))
{
//跳轉(zhuǎn)到訪問權(quán)限不夠的錯(cuò)誤提示頁面
Response.Redirect("~/Error/AccessError.htm", true);
}
}
//安全退出按鈕的代碼
protected void btnExit_Click(object sender, EventArgs e)
{
//注銷票據(jù)
FormsAuthentication.SignOut();
ClientScriptManager csm = this.Page.ClientScript;
csm.RegisterStartupScript(this.GetType(), "exit_tip", "alert('您已經(jīng)安全退出了!');", true);
}
測試結(jié)果:
數(shù)據(jù):
假設(shè)有3個(gè)用戶,如下:
------------------------------------------
用戶名 密碼 角色字符串
------------------------------------------
sa sa Admin,User
admin admin Admin
user user User
------------------------------------------
測試:
如果使用admin登錄,只能訪問Admin目錄的Manager.aspx頁面;
如果使用user登錄,只能訪問Users目錄的Welcome.aspx頁面;
使用sa登錄,既能訪問Admin目錄的Manager.aspx頁面,又能訪問Users目錄的Welcome.aspx頁面。
注意:測試時(shí)注意及時(shí)點(diǎn)擊安全退出按鈕,否則影響測試結(jié)果。
您可能感興趣的文章:
- 淺談asp.net Forms身份驗(yàn)證詳解
- 詳解ASP.NET MVC Form表單驗(yàn)證
- 關(guān)于C#.net winform程序驗(yàn)證moss的集成身份認(rèn)證實(shí)例
- Asp.Net二級(jí)域名共享Forms身份驗(yàn)證、下載站/圖片站的授權(quán)訪問控制
- ASP.NET Internet安全Forms身份驗(yàn)證方法
- asp.net forms身份驗(yàn)證,避免重復(fù)造輪子
- asp.net 基于forms驗(yàn)證的目錄角色權(quán)限的實(shí)現(xiàn)
- asp.net 特定目錄form驗(yàn)證
- ASP.net Forms驗(yàn)證Demo
- .net MVC使用IPrincipal進(jìn)行Form登錄即權(quán)限驗(yàn)證(3)
相關(guān)文章
asp.net SqlDataReader綁定Repeater
asp.net SqlDataReader綁定Repeater2009-04-04
ASP.NET網(wǎng)站聊天室的設(shè)計(jì)與實(shí)現(xiàn)(第3節(jié))
這篇文章主要介紹了ASP.NET網(wǎng)站聊天室的設(shè)計(jì)與實(shí)現(xiàn),了解Session、Application對(duì)象的屬性和事件,并且掌握利用它們在頁面間保存和傳遞數(shù)據(jù)的方法,需要的朋友可以參考下2015-08-08
詳解ASP.NET MVC 常用擴(kuò)展點(diǎn):過濾器、模型綁定
本篇文章主要介紹了詳解ASP.NET MVC 常用擴(kuò)展點(diǎn):過濾器、模型綁定,非常具有實(shí)用價(jià)值,需要的朋友可以參考下2017-05-05
利用ASP.NET MVC和Bootstrap快速搭建響應(yīng)式個(gè)人博客站(一)
這篇文章主要介紹了利用ASP.NET MVC和Bootstrap快速搭建響應(yīng)式個(gè)人博客站(一)的相關(guān)資料,需要的朋友可以參考下2016-06-06
asp.net實(shí)現(xiàn)的計(jì)算網(wǎng)頁下載速度的代碼
剛看到有人給出asp.net實(shí)現(xiàn)的計(jì)算網(wǎng)頁下載速度的方法,本方法未經(jīng)本人測試,不知道能否可靠性如何。準(zhǔn)確來說,這只是個(gè)思路吧2013-03-03
asp.net實(shí)現(xiàn)存儲(chǔ)和讀取數(shù)據(jù)庫圖片
這篇文章主要為大家詳細(xì)介紹了asp.net實(shí)現(xiàn)存儲(chǔ)和讀取數(shù)據(jù)庫圖片,文中示例代碼介紹的非常詳細(xì),具有一定的參考價(jià)值,感興趣的小伙伴們可以參考一下2019-11-11

