Click here to Skip to main content
15,886,091 members

Role Based Form Authentication is not working

vicvis asked:

Open original thread
I was trying to implement role based form authentication but in the end cookie not contain roles though i have provided.

Login.aspx
C#
if (Login1.UserName == "user" && Login1.Password == "user")
       {
           string role = "admin,member";

           FormsAuthenticationTicket t = new FormsAuthenticationTicke(1,Login1.UserName,DateTime.Now, DateTime.Today, false, role,"/");
           string cookiester = FormsAuthentication.Encrypt(t);
           HttpCookie cookie = new HttpCookie      (FormsAuthentication.FormsCookieName,cookiester);
           Response.Cookies.Add(cookie);
           if (t.IsPersistent)
           {
               cookie.Expires = t.Expiration;
           }
           String strRedirect = Request["ReturnUrl"];
           if (strRedirect == null)
           {
               strRedirect = "Default.aspx";
               Response.Redirect(strRedirect);
           }

          if(HttpContext.Current.User.IsInRole("admin"))
          {

           Response.Redirect("Secure/Secure.aspx");
          }
          }
       }
     }

Here i am taking "user" and provideing him "admin" rights.
Only admin role can log in to the "Secure\Secure.aspx" as per my web config:

XML
<location path="Secure">
	<system.web>
		<authorization>
			<allow roles="admin" />
			<deny users="*" />
		</authorization>
	</system.web>
</location> 


My global.aspx contains:
C#
protected void Application_AuthenticateRequest(Object sender, EventArgs e)
{
    HttpCookie authCookie =Context.Request.Cookies,FormsAuthentication.FormsCookieName];
    if (authCookie != null) 
    {
        FormsAuthenticationTicket t = FormsAuthentication.Decrypt(authCookie.Value);
        string[] roles = t.UserData.Split(new Char[] { ',' });
        GenericPrincipal userPrincipal = 
new GenericPrincipal(new GenericIdentity    (t.Name), roles);
        Context.User = userPrincipal; 
        
    }
}



What is wrong in this code? Why i cant use "admin" roles in this?
Tags: C#, ASP.NET

Plain Text
ASM
ASP
ASP.NET
BASIC
BAT
C#
C++
COBOL
CoffeeScript
CSS
Dart
dbase
F#
FORTRAN
HTML
Java
Javascript
Kotlin
Lua
MIDL
MSIL
ObjectiveC
Pascal
PERL
PHP
PowerShell
Python
Razor
Ruby
Scala
Shell
SLN
SQL
Swift
T4
Terminal
TypeScript
VB
VBScript
XML
YAML

Preview



When answering a question please:
  1. Read the question carefully.
  2. Understand that English isn't everyone's first language so be lenient of bad spelling and grammar.
  3. If a question is poorly phrased then either ask for clarification, ignore it, or edit the question and fix the problem. Insults are not welcome.
  4. Don't tell someone to read the manual. Chances are they have and don't get it. Provide an answer or move on to the next question.
Let's work to help developers, not make them feel stupid.
Please note that all posts will be submitted under the http://www.codeproject.com/info/cpol10.aspx.



CodeProject, 20 Bay Street, 11th Floor Toronto, Ontario, Canada M5J 2N8 +1 (416) 849-8900