KnowledgeHub
Questions
Tags
Users
Search
Alex Rivera
|
Logout
Edit Question
Title
Body
I am working with a permission based authorization system for my app in ASP.NET MVC. For this I have created a custom authorization attribute public class MyAuthorizationAttribute : AuthorizeAttribute { string Roles {get; set;} string Permission {get; set;} } so that I can authorize a user by both role or a specific permission key with annotation for actions like public class UserController : Controller { [MyAuthorization(Roles="ADMIN", Permissions="USER_ADD")] public ActionResult Add() [MyAuthorization(Roles="ADMIN", Permissions="USER_EDIT")] public ActionResult Edit() [MyAuthorization(Roles="ADMIN", Permissions="USER_DELETE")] public ActionResult Delete() } then I override AuthorizeCore() method in MyAuthorizationAttribute class with similar logic(pseudo code) protected override bool AuthorizeCore(HttpContextBase httpContext) { if(user not authenticated) return false; if(user has any role of Roles) return true; if(user has any permission of Permissions) return true; return false; } Up to this is working fine. Now I need some sort of extension methods so that I can dynamically generate action url in view pages that will return action url based on MyAuthorization attribute authorization logic for the given action. Like @Url.MyAuthorizedAction("Add", "User") will return url to "User/Add" if user has admin role or has permission of "USER_ADD" (as defined in attributes for the action) or return empty string otherwise. But after searching in internet for few days I could not figure it out. :( So far I have found only this "Security aware" action link? which works by executing all action filters for the action until it fails. <
Tags (comma-separated)
Save Edits
Cancel