asp.net身份验证和授权

本文介绍了一个ASP.NET应用程序的身份验证和授权实现方式,包括登录页面的HTML结构、后端验证逻辑及Web.config配置示例。

摘要生成于 C知道 ,由 DeepSeek-R1 满血版支持, 前往体验 >

今天闲着无聊.想起来了ASP.NET身份验证.感觉良好.贴出下列代码:
login.aspx HTML代码

None.gif
ContractedBlock.gif ExpandedBlockStart.gif
 1None.gif<%@ Page language="c#" Codebehind="02Login.aspx.cs" AutoEventWireup="false" Inherits="身份验证._02Login" %>
 2None.gif<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN" >
 3None.gif<HTML>
 4None.gif    <HEAD>
 5None.gif        <title>02Login</title>
 6None.gif        <meta name="GENERATOR" Content="Microsoft Visual Studio .NET 7.1">
 7None.gif        <meta name="CODE_LANGUAGE" Content="C#">
 8None.gif        <meta name="vs_defaultClientScript" content="JavaScript">
 9None.gif        <meta name="vs_targetSchema" content="http://schemas.microsoft.com/intellisense/ie5">
10None.gif    </HEAD>
11None.gif    <body MS_POSITIONING="GridLayout">
12None.gif        <form id="Form1" method="post" runat="server">
13None.gif            <FONT face="宋体">
14None.gif                <TABLE id="Table1" style="Z-INDEX: 102; LEFT: 152px; WIDTH: 446px; POSITION: absolute; TOP: 80px; HEIGHT: 72px"
15None.gif                    cellSpacing="1" cellPadding="1" width="446" border="1">
16None.gif                    <TR>
17None.gif                        <TD>
18None.gif                            <asp:label id="Label1" runat="server">用户名称:</asp:label></TD>
19None.gif                        <TD>
20None.gif                            <asp:textbox id="tbName" runat="server" Width="183px"></asp:textbox></TD>
21None.gif                        <TD>
22None.gif                            <asp:requiredfieldvalidator id="RequiredFieldValidator1" runat="server" ErrorMessage="用户名不能为空!" ControlToValidate="tbName"></asp:requiredfieldvalidator></TD>
23None.gif                    </TR>
24None.gif                    <TR>
25None.gif                        <TD>
26None.gif                            <asp:label id="Label2" runat="server">密码:</asp:label></TD>
27None.gif                        <TD>
28None.gif                            <asp:textbox id="tbPass" runat="server" Width="183px"></asp:textbox></TD>
29None.gif                        <TD>
30None.gif                            <asp:requiredfieldvalidator id="RequiredFieldValidator2" runat="server" ErrorMessage="密码不能为空!" ControlToValidate="tbPass"></asp:requiredfieldvalidator></TD>
31None.gif                    </TR>
32None.gif                    <TR>
33None.gif                        <TD><FONT face="宋体">是否保存Cookie</FONT></TD>
34None.gif                        <TD>
35None.gif                            <asp:checkbox id="PersistCookie" runat="server"></asp:checkbox></TD>
36None.gif                        <TD></TD>
37None.gif                    </TR>
38None.gif                </TABLE>
39None.gif                <asp:button id="btnLoginBetter" style="Z-INDEX: 101; LEFT: 288px; POSITION: absolute; TOP: 240px"
40None.gif                    runat="server" Width="78px" Text="登录"></asp:button>
41None.gif                <asp:HyperLink id="HyperLink1" style="Z-INDEX: 103; LEFT: 456px; POSITION: absolute; TOP: 240px"
42None.gif                    runat="server" NavigateUrl="Default.aspx">HyperLink</asp:HyperLink></FONT>
43None.gif        </form>
44None.gif    </body>
45None.gif</HTML>

login.aspx.cs代码如下

ContractedBlock.gif ExpandedBlockStart.gif
None.gifprivate void btnLoginBetter_Click(object sender, System.EventArgs e)
ExpandedBlockStart.gifContractedBlock.gif  
dot.gif{
InBlock.gif   
if (this.tbName.Text == "admin" && this.tbPass.Text == "admin")
ExpandedSubBlockStart.gifContractedSubBlock.gif   
dot.gif{
InBlock.gif    FormsAuthenticationTicket ticket 
= new FormsAuthenticationTicket(1,this.tbName.Text,DateTime.Now,DateTime.Now.AddMinutes(30),this.PersistCookie.Checked,"User");//创建一个验证票据
InBlock.gif
    string cookieStr = FormsAuthentication.Encrypt(ticket);进行加密
InBlock.gif    HttpCookie cookie 
= new HttpCookie(FormsAuthentication.FormsCookieName,cookieStr);创建一个cookie,cookie名为web.config设置的名,值为加密后的数据cookieStr,
InBlock.gif    
if (this.PersistCookie.Checked)//判断用户是否选中保存cookie
InBlock.gif
     cookie.Expires = ticket.Expiration;//获取cookie过期时间
InBlock.gif
    cookie.Path = FormsAuthentication.FormsCookiePath;//设置cookie保存路径
InBlock.gif
    Response.Cookies.Add(cookie);
InBlock.gif    
string strRedirect;
InBlock.gif    strRedirect 
= Request["ReturnUrl"];//取出返回url
InBlock.gif
    if (strRedirect == null)
InBlock.gif     strRedirect 
= "Default.aspx";
InBlock.gif    Response.Redirect(strRedirect,
true);
InBlock.gif
ExpandedSubBlockEnd.gif   }

InBlock.gif   
else
ExpandedSubBlockStart.gifContractedSubBlock.gif   
dot.gif{
InBlock.gif    Response.Write(
"<script>alert('帐号或密码错误!');self.location.href='02login.aspx'</script>");
ExpandedSubBlockEnd.gif   }

ExpandedBlockEnd.gif  }

None.gif


 

Default.aspx HTML代码

ContractedBlock.gif ExpandedBlockStart.gif
None.gif<body MS_POSITIONING="GridLayout">
None.gif        
<form id="Form1" method="post" runat="server">
None.gif            
<FONT face="宋体">
None.gif                
<asp:Label id="Label1" style="Z-INDEX: 106; LEFT: 224px; POSITION: absolute; TOP: 72px" runat="server">用户名称:</asp:Label>
None.gif                
<asp:Label id="Label2" style="Z-INDEX: 102; LEFT: 220px; POSITION: absolute; TOP: 136px" runat="server">身份:</asp:Label>
None.gif                
<asp:Label id="lbUser" style="Z-INDEX: 103; LEFT: 350px; POSITION: absolute; TOP: 79px" runat="server"></asp:Label>
None.gif                
<asp:Label id="lbSf" style="Z-INDEX: 104; LEFT: 355px; POSITION: absolute; TOP: 133px" runat="server"></asp:Label>
None.gif                
<asp:Button id="btnLogout" style="Z-INDEX: 105; LEFT: 261px; POSITION: absolute; TOP: 192px"
None.gif                    runat
="server" Text="注销" Width="101px"></asp:Button></FONT>
None.gif        
</form>
None.gif    
</body>

后置代码

ContractedBlock.gif ExpandedBlockStart.gif
None.gifprivate void Page_Load(object sender, System.EventArgs e)
ExpandedBlockStart.gifContractedBlock.gif  
dot.gif{
InBlock.gif   
this.lbUser.Text = User.Identity.Name;
InBlock.gif   
if (User.IsInRole("Admin"))
InBlock.gif    
this.lbSf.Text = "Admin";
InBlock.gif   
else
InBlock.gif    
this.lbSf.Text = "User";
ExpandedBlockEnd.gif  }

None.gif
ContractedBlock.gifExpandedBlockStart.gif  
Web 窗体设计器生成的代码#region Web 窗体设计器生成的代码
InBlock.gif  
override protected void OnInit(EventArgs e)
ExpandedSubBlockStart.gifContractedSubBlock.gif  
dot.gif{
InBlock.gif   
//
InBlock.gif   
// CODEGEN: 该调用是 ASP.NET Web 窗体设计器所必需的。
InBlock.gif   
//
InBlock.gif
   InitializeComponent();
InBlock.gif   
base.OnInit(e);
ExpandedSubBlockEnd.gif  }

InBlock.gif  
ExpandedSubBlockStart.gifContractedSubBlock.gif  
/**//// <summary>
InBlock.gif  
/// 设计器支持所需的方法 - 不要使用代码编辑器修改
InBlock.gif  
/// 此方法的内容。
ExpandedSubBlockEnd.gif  
/// </summary>

InBlock.gif  private void InitializeComponent()
ExpandedSubBlockStart.gifContractedSubBlock.gif  
dot.gif{    
InBlock.gif   
this.btnLogout.Click += new System.EventHandler(this.btnLogout_Click);
InBlock.gif   
this.Load += new System.EventHandler(this.Page_Load);
InBlock.gif
ExpandedSubBlockEnd.gif  }

ExpandedBlockEnd.gif  
#endregion

None.gif
None.gif  
private void btnLogout_Click(object sender, System.EventArgs e)
ExpandedBlockStart.gifContractedBlock.gif  
dot.gif{
InBlock.gif   FormsAuthentication.SignOut();
//注销票
InBlock.gif
   Response.Redirect("login.aspx",true);返回login.aspx页面
ExpandedBlockEnd.gif  }

None.gif
None.gif

webconfig配置如下
    <authentication mode="Forms" >
  <forms name=".SecurityDemo" loginUrl="login.aspx">//.SecurityDemo为cookie名,
  </forms>
    </authentication>

 <authorization>
            <deny users="?"/> //拒绝所有匿名用户
            <allow roles="admins"/>//允许管理级别用户访问
   </authorization>
自我感觉ASP写多了,一般是用session进行判断用户是否合法,但在一个ASP.NET项目中使用身份验证,基本上所有页面都要验证才能访问,可以在web.config页面对指定的页面设置权限,设置代码如下
  <location path="admin">
    <system.web>
      <authorization>
        <deny users="*" />
         <allow roles="paley"/>
      </authorization>
    </system.web>
  </location>
已看资料修如上.对admin文件夹设置权限,拒绝所有用户,允许paley访问

posted on 2006-10-21 23:43 我就是烟鬼 阅读( ...) 评论( ...) 编辑 收藏

转载于:https://www.cnblogs.com/paleyyang/archive/2006/10/21/536147.html

评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值