Sign Up

Sign Up to our social questions and Answers Engine to ask questions, answer people’s questions, and connect with other people.

Have an account? Sign In

Have an account? Sign In Now

Sign In

Login to our social questions & Answers Engine to ask questions answer people’s questions & connect with other people.

Sign Up Here

Forgot Password?

Don't have account, Sign Up Here

Forgot Password

Lost your password? Please enter your email address. You will receive a link and will create a new password via email.

Have an account? Sign In Now

You must login to ask a question.

Forgot Password?

Need An Account, Sign Up Here

Please briefly explain why you feel this question should be reported.

Please briefly explain why you feel this answer should be reported.

Please briefly explain why you feel this user should be reported.

Sign InSign Up

The Archive Base

The Archive Base Logo The Archive Base Logo

The Archive Base Navigation

  • Home
  • SEARCH
  • About Us
  • Blog
  • Contact Us
Search
Ask A Question

Mobile menu

Close
Ask a Question
  • Home
  • Add group
  • Groups page
  • Feed
  • User Profile
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Buy Points
  • Users
  • Help
  • Buy Theme
  • SEARCH
Home/ Questions/Q 523803
In Process

The Archive Base Latest Questions

Editorial Team
  • 0
Editorial Team
Asked: May 13, 20262026-05-13T08:30:01+00:00 2026-05-13T08:30:01+00:00

I want to use the the AuthorizeAttribute to control which users are allowed access

  • 0

I want to use the the AuthorizeAttribute to control which users are allowed access to my actions. I just want to clarify that my logic is in order.

  1. I create my own implementation of IPrincipal
  2. I post a user’s credentials to a login action of a security controller.
  3. I validate the credentials with a UserService class and assign the IPrincipal returned from my UserService class to HttpContext.User
  4. My WebAuthorizeAttribute, which inherits AuthorizeAttribute, checks the current HttpContext.User.Identity.IsAuthenticated and HttpContext.User.IsInRole to determine if the user has access to the action.

Is the the normal flow of things? I know I could inherit MembershipProvider, but I don’t need all of the functionality there, really just the ability to login with two different roles.

  • 1 1 Answer
  • 0 Views
  • 0 Followers
  • 0
Share
  • Facebook
  • Report

Leave an answer
Cancel reply

You must login to add an answer.

Forgot Password?

Need An Account, Sign Up Here

1 Answer

  • Voted
  • Oldest
  • Recent
  • Random
  1. Editorial Team
    Editorial Team
    2026-05-13T08:30:02+00:00Added an answer on May 13, 2026 at 8:30 am

    You’ll have to store IPrincipal somewhere and restore it with every request. If you’ll use FormsAuthentication, this is good solution:

    ASP.NET 2.0 Forms authentication – Keeping it customized yet simple

    you can find other solutions here:

    Where to store logged user information on ASP.NET MVC using Forms Authentication?

    and propably in many other StackOverflow questions:)

    EDIT

    About MyBusinessLayerSecurityClass.CreatePrincipal(id, id.Name):

    You should read this page:

    http://msdn.microsoft.com/en-us/library/aa480476.aspx

    Specially this:

    The
    FormsAuthenticationModule
    class constructs a
    GenericPrincipal
    object and stores it in the HTTP
    context. The
    GenericPrincipal
    object holds a reference to a
    FormsIdentity
    instance that represents the currently
    authenticated user. You should allow
    forms authentication to manage these
    tasks for you. If your applications
    have specific requirements, such as
    setting the User
    property to a custom class that
    implements the
    IPrincipal interface,
    your application should handle the
    PostAuthenticate
    event. The
    PostAuthenticate
    event occurs after the
    FormsAuthenticationModule
    has verified the forms authentication
    cookie and created the
    GenericPrincipal and
    FormsIdentity
    objects. Within this code, you can
    construct a custom
    IPrincipal object
    that wraps the
    FormsIdentity object,
    and then store it in the
    HttpContext. User
    property.

    FormsIdentity is managed automatically after you set authentication cookie. All you have to do is wrap it up in your IPrincipal. All this happens when HttpContext.Current.User property is not null (it is GenericPrincipal, which you replace shortly after). When HttpContext.Current.User is null then there was no authentication cookie created earlier and user is not authenticated.

    • 0
    • Reply
    • Share
      Share
      • Share on Facebook
      • Share on Twitter
      • Share on LinkedIn
      • Share on WhatsApp
      • Report

Sidebar

Ask A Question

Stats

  • Questions 350k
  • Answers 350k
  • Best Answers 0
  • User 1
  • Popular
  • Answers
  • Editorial Team

    How to approach applying for a job at a company ...

    • 7 Answers
  • Editorial Team

    How to handle personal stress caused by utterly incompetent and ...

    • 5 Answers
  • Editorial Team

    What is a programmer’s life like?

    • 5 Answers
  • Editorial Team
    Editorial Team added an answer Yes. I have a mixture of sql and code migrations.… May 14, 2026 at 7:04 am
  • Editorial Team
    Editorial Team added an answer Never figured I'd answer my own question on SO but… May 14, 2026 at 7:04 am
  • Editorial Team
    Editorial Team added an answer From my answer to this question: Adobe Flash is on… May 14, 2026 at 7:04 am

Related Questions

Some Background to begin: I've implemented a custom MembershipProvider that validates a user from
I have a child class of AuthorizeAttribute named CheckArticleExistence. I would like to set
I am using asp.net mvc 1.0. I know asp.net mvc has a couple attribute
I need to redirect users to the Change Password page if their password has
I have 2 attributes that I use within the controllers of my MVC application.

Trending Tags

analytics british company computer developers django employee employer english facebook french google interview javascript language life php programmer programs salary

Top Members

Explore

  • Home
  • Add group
  • Groups page
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Users
  • Help
  • SEARCH

Footer

© 2021 The Archive Base. All Rights Reserved
With Love by The Archive Base

Insert/edit link

Enter the destination URL

Or link to existing content

    No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.