Sign Up

Sign Up to our social questions and Answers Engine to ask questions, answer people’s questions, and connect with other people.

Have an account? Sign In

Have an account? Sign In Now

Sign In

Login to our social questions & Answers Engine to ask questions answer people’s questions & connect with other people.

Sign Up Here

Forgot Password?

Don't have account, Sign Up Here

Forgot Password

Lost your password? Please enter your email address. You will receive a link and will create a new password via email.

Have an account? Sign In Now

You must login to ask a question.

Forgot Password?

Need An Account, Sign Up Here

Please briefly explain why you feel this question should be reported.

Please briefly explain why you feel this answer should be reported.

Please briefly explain why you feel this user should be reported.

Sign InSign Up

The Archive Base

The Archive Base Logo The Archive Base Logo

The Archive Base Navigation

  • Home
  • SEARCH
  • About Us
  • Blog
  • Contact Us
Search
Ask A Question

Mobile menu

Close
Ask a Question
  • Home
  • Add group
  • Groups page
  • Feed
  • User Profile
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Buy Points
  • Users
  • Help
  • Buy Theme
  • SEARCH
Home/ Questions/Q 7662975
In Process

The Archive Base Latest Questions

Editorial Team
  • 0
Editorial Team
Asked: May 31, 20262026-05-31T13:56:19+00:00 2026-05-31T13:56:19+00:00

There is so much information and terms here I find it hard to start

  • 0

There is so much information and terms here I find it hard to start think about users. What options would I have for creating a user-based ASP.net MVC 3 web app? I’ve read of membership, providers, authorization, authentication, session, cookies, roles and profiles, but I can’t seem to get a grasp on the big picture of how user-things are handled.

What are the pros/cons of using a built-in microsoft solution here? What is it even called?
Can I use my own database only (I want to work database first)?

In my mind I think like so: I have users and roles in a database. Users have roles. I want to deny access to some actions depending on if the user is logged in and has a specific role. Am I over-simplifying the issue? Where should I start?

At the moment I’m thinking of doing a 100% home brew system like when I was developing using PHP but since there’s so much info I feel like that would not be a good approach here.

  • 1 1 Answer
  • 0 Views
  • 0 Followers
  • 0
Share
  • Facebook
  • Report

Leave an answer
Cancel reply

You must login to add an answer.

Forgot Password?

Need An Account, Sign Up Here

1 Answer

  • Voted
  • Oldest
  • Recent
  • Random
  1. Editorial Team
    Editorial Team
    2026-05-31T13:56:21+00:00Added an answer on May 31, 2026 at 1:56 pm

    You want users and roles, i.e. you want to authenticate users and authorize them with privileges using roles. I would highly recommend not rolling your own, as you would in PHP. Instead, I recommend using the .NET “Provider” services — specifically, the MembershipProvider (for authentication) and the RoleProvider (for authorization).

    You can still use the Providers with your own db, they are not exclusive to or exclusive with code first. However, I would recommend NOT storing application-specific user information in the Provider’s user or member tables. Instead, you can have your own code-first User, and link it to the membership system through the user’s username.

    The reason I recommend this is because it reduces the amount of work you have to do. You need not worry about encrypting or hashing passwords — the provider does it for you. You have full API to control your users and roles through the System.Web.Security namespace.

    As for Profiles, this is a separate Provider service that you do not need to use. It allows you to store information about users whether or not they have registered for a user account in your system. Technically you can have “anonymous users”, but anyone who has created a password-based login is instead referred to as a “member”.

    Regarding cookies, authentication of a user in .NET is done through the FormsAuthentication class. After you have authenticated a user using System.Web.Security.Membership, you can call FormsAuthentication.SetAuthCookie to write their authentication cookie. This fully integrates both the User and their Roles into the Controller.User property, which implements the IPrincipal interface. You can use this object to get the user’s name, and find out which roles they are in.

    Reply to comments

    I answered a very similar question here. Basically, it’s up to you whether or not to have the membership in a completely separate db than your application, but I consider it good practice, because I have done this quite a bit and I have no complaints. Especially if you are using code first, since you can lose your entire db if you use the DropCreateDatabaseIfModelChanges or DropCreateDatabaseAlways initializers.

    There is also a new membership provider. I think the NuGet package is called “ASP.NET Universal Providers”, and they are in the System.Web.Providers namespace instead of the old System.Web.Security namespace. I haven’t had a chance to work with them yet, but from what I gather, they are more compatible with code first. For one thing, the tables aren’t named like aspnet_Foo, and there are no views or stored procedures created in the db. The table names are just normal dbo.Users, dbo.Roles, etc.

    As for linking the provider users with your app (content) User entities, see the answer I linked to above. The easiest way to do this is to just have a field in your content db for UserName, and link that to the provider db’s UserName. No foreign keys necessary, since you integrate them at the app-level, not the db level.

    • 0
    • Reply
    • Share
      Share
      • Share on Facebook
      • Share on Twitter
      • Share on LinkedIn
      • Share on WhatsApp
      • Report

Sidebar

Related Questions

There is so much written about unit testing but I have hardly found any
I have searched for examples on idempotent and non-idempotent operations but there aren't much
Q1: Is there something like too much ajax?? Explanation: I have been seeing programmers
I have the following database table with information about people, diseases, and drugs: PERSON_T
I am looking for information about providing a license, or terms of use, for
There are some discussions about the same question but I would like to ask
I've been wondering about how hard it would be to write some Python code
There have been a couple of questions about limiting login attempts, but none have
Is there a library much like how openssl is imported into C programs that
I won't post any code, because there is too much that could be relevant.

Explore

  • Home
  • Add group
  • Groups page
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Users
  • Help
  • SEARCH

Footer

© 2021 The Archive Base. All Rights Reserved
With Love by The Archive Base

Insert/edit link

Enter the destination URL

Or link to existing content

    No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.