Sign Up

Sign Up to our social questions and Answers Engine to ask questions, answer people’s questions, and connect with other people.

Have an account? Sign In

Have an account? Sign In Now

Sign In

Login to our social questions & Answers Engine to ask questions answer people’s questions & connect with other people.

Sign Up Here

Forgot Password?

Don't have account, Sign Up Here

Forgot Password

Lost your password? Please enter your email address. You will receive a link and will create a new password via email.

Have an account? Sign In Now

You must login to ask a question.

Forgot Password?

Need An Account, Sign Up Here

Please briefly explain why you feel this question should be reported.

Please briefly explain why you feel this answer should be reported.

Please briefly explain why you feel this user should be reported.

Sign InSign Up

The Archive Base

The Archive Base Logo The Archive Base Logo

The Archive Base Navigation

  • SEARCH
  • Home
  • About Us
  • Blog
  • Contact Us
Search
Ask A Question

Mobile menu

Close
Ask a Question
  • Home
  • Add group
  • Groups page
  • Feed
  • User Profile
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Buy Points
  • Users
  • Help
  • Buy Theme
  • SEARCH
Home/ Questions/Q 88273
In Process

The Archive Base Latest Questions

Editorial Team
  • 0
Editorial Team
Asked: May 10, 20262026-05-10T22:32:02+00:00 2026-05-10T22:32:02+00:00

Encouraged by SO, I’m trying to write an ASP.NET site that uses OpenID for

  • 0

Encouraged by SO, I’m trying to write an ASP.NET site that uses OpenID for user authentication. It’s a regular WinForms site (not MVC.NET), using the DotNetOpenId library for authentication.

Is it safe for me to permit/deny administrative functions on the site by simply comparing the current session’s ‘ClaimedID’ (as returned in the OpenIdLogin_LoggedIn event, as member DotNetOpenId.RelyingParty,OpenIdEventArgs.Response.ClaimedIdentifier) to a known administrator’s OpenID (i.e. mine)?

If so, is it safe for this ID to be visible (e.g. in open source code), or should it be ‘hidden’ in a configuration file or a database row? (I know it’s better design to make it configurable, my question is just about safety.)

  • 1 1 Answer
  • 0 Views
  • 0 Followers
  • 0
Share
  • Facebook
  • Report

Leave an answer
Cancel reply

You must login to add an answer.

Forgot Password?

Need An Account, Sign Up Here

1 Answer

  • Voted
  • Oldest
  • Recent
  • Random
  1. 2026-05-10T22:32:03+00:00Added an answer on May 10, 2026 at 10:32 pm

    Jarrett makes some good comments about using database tables.

    Just to answer another one of your questions, no, it’s not a confidentiality thing to put your OpenID in your code generally. If setting up roles seems overkill for your site, a simple equality check against your ClaimedIdentifier is just perfect.

    • 0
    • Reply
    • Share
      Share
      • Share on Facebook
      • Share on Twitter
      • Share on LinkedIn
      • Share on WhatsApp
      • Report

Sidebar

Related Questions

Once I read an MSDN article that encouraged the following programming paradigm (its not
In Asp.net MVC one is encouraged to derive custom ActionResults, however should these classes
I read that using directive is not encouraged in C++ saying never put using
I understand that the best way to deploy a rails site is with passenger.
I remember from C days that we were encouraged to use i > -1
At work we use perforce and are encouraged to make regular commits to it
I've created a jQuery Mobile site with PHP which requires authentication and is so
It seems to me that dictionaries are encouraged over defining classes and using classes.
On the one hand, we are encouraged to just create fields, and not encrust
I'm encouraged by so many warm-hearted Java experts that I dare to throw another

Explore

  • Home
  • Add group
  • Groups page
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Users
  • Help
  • SEARCH

Footer

© 2021 The Archive Base. All Rights Reserved
With Love by The Archive Base

Insert/edit link

Enter the destination URL

Or link to existing content

    No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.