Alex Rivera | Logout

Should I use the username, or the user's ID to reference authenticated users in ASP.NET

Asked 2008-08-07T16:19:40.487
34

So in my simple learning website, I use the built in ASP.NET authentication system.

I am adding now a user table to save stuff like his zip, DOB etc. My question is:

  1. In the new table, should the key be the user name (the string) or the user ID which is that GUID looking number they use in the asp_ tables.
  2. If the best practice is to use that ugly guid, does anyone know how to get it? it seems to not be accessible as easily as the name (System.Web.HttpContext.Current.User.Identity.Name)
  3. If you suggest I use neither (not the guid nor the userName fields provided by ASP.NET authentication) then how do I do it with ASP.NET authentication? One option I like is to use the email address of the user as login, but how to I make ASP.NET authentication system use an email address instead of a user name? (or there is nothing to do there, it is just me deciding I "know" userName is actually an email address?

Please note:

  • I am not asking on how get a GUID in .NET, I am just referring to the userID column in the asp_ tables as guid.
  • The user name is unique in ASP.NET authentication.
Edit
Report

2 Answers

23

You should use the UserID. It's the ProviderUserKey property of MembershipUser.

Guid UserID = new Guid(Membership.GetUser(User.Identity.Name).ProviderUserKey.ToString());
answered 2008-08-07T17:55:51.387
0

I'm agreeing with Mike Stone also. My company recently implemented a new user table for outside clients (as opposed to internal users who authenticate through LDAP). For the external users, we chose to store the GUID as the primary key, and store the username as varchar with unique constraints on the username field.

Also, if you are going to store the password field, I highly recommend storing the password as a salted, hashed binary in the database. This way, if someone were to hack your database, they would not have access to your customer's passwords.

answered 2008-08-08T01:56:00.137

Your Answer