KnowledgeHub
Questions
Tags
Users
Search
Alex Rivera
|
Logout
Edit Question
Title
Body
Bear with me as I provide details for the issue... I've got an MVC site, using FormsAuthentication and custom service classes for Authentication, Authorization, Roles/Membership, etc. Authentication There are three ways to sign-on: (1) Email + Alias , (2) OpenID , and (3) Username + Password . All three get the user an auth cookie and start a session. The first two are used by visitors (session only) and the third for authors/admin with db accounts. public class BaseFormsAuthenticationService : IAuthenticationService { // Disperse auth cookie and store user session info. public virtual void SignIn(UserBase user, bool persistentCookie) { var vmUser = new UserSessionInfoViewModel { Email = user.Email, Name = user.Name, Url = user.Url, Gravatar = user.Gravatar }; if(user.GetType() == typeof(User)) { // roles go into view model as string not enum, see Roles enum below. var rolesInt = ((User)user).Roles; var rolesEnum = (Roles)rolesInt; var rolesString = rolesEnum.ToString(); var rolesStringList = rolesString.Split(',').Select(role => role.Trim()).ToList(); vmUser.Roles = rolesStringList; } // i was serializing the user data and stuffing it in the auth cookie // but I'm simply going to use the Session[] items collection now, so // just ignore this variable and its inclusion in the cookie below. var userData = ""; var ticket = new FormsAuthenticationTicket(1, user.Email, DateTime.UtcNow, DateTime.UtcNow.AddMinutes(30), false, userData, FormsAuthentication.FormsCookiePath); var encryptedTicket = FormsAuthentication.Encrypt(ticket); var authCookie = new HttpCookie(FormsAuthentication.FormsCookieName, encryptedTicket) { HttpOnly = true }; HttpContext.Current.Response.Cookies.Add(authCookie); HttpContext.Curre
Tags (comma-separated)
Save Edits
Cancel