Basic question here (I think), I was hoping someone could point me in the right direction. I don’t know much about WCF but I’d like to create a web service to be called from an ASP.Net MVC application. The goal is to make sure only authorized ASP.Net users (we’re using forms authentication) can call the web service, not just anyone. Are there tutorials out there I can look at on how to approach this? Many thanks.
Share
I assume from the question that you don’t care what the end (MVC) user ID is that is hitting the WCF service (in other words you don’t need a specific authenticated user to hit the WCF so you can get the ID of that specific user (i.e. so you know that joeBobUser hit the WCF)). you just want to make sure that user is authenticated and authorized to use the site. You don’t need every potential user of your MVC app to be authenticated/authorized.
As long as that is true, then my approach would be as follows: