如何正确实现会话的用户系统
我以前从未真正实现过注册/登录系统,因此我正在尝试用 C#/ASP.NET 制作自己的注册/登录系统(不使用 ASP.NET 的内置会员提供程序)。我有点不清楚的是如何利用会话/cookies 来让用户在会话期间和会话之间保持登录状态。
protected void Login_User(object sender, EventArgs e)
{
string username = usernameField.Text;
string password = passwordField.Text;
User user = UserRepository.FindUser(username);
if (user != null)
{
if (user.Password.Equals(Hash(password)))
{
// How do I properly login the user and keep track of his session?
}
else
Response.Write("Wrong password!");
}
else
Response.Write("User does not exist!");
}
I've never actually implemented a registration/login system before, so I'm trying my hand at making my own in C#/ASP.NET (not using ASP.NET's built-in membership provider). What I'm a little unclear on is how to utilize Session/cookies to keep a user logged in during and between sessions.
protected void Login_User(object sender, EventArgs e)
{
string username = usernameField.Text;
string password = passwordField.Text;
User user = UserRepository.FindUser(username);
if (user != null)
{
if (user.Password.Equals(Hash(password)))
{
// How do I properly login the user and keep track of his session?
}
else
Response.Write("Wrong password!");
}
else
Response.Write("User does not exist!");
}
如果你对这篇内容有疑问,欢迎到本站社区发帖提问 参与讨论,获取更多帮助,或者扫码二维码加入 Web 技术交流群。
绑定邮箱获取回复消息
由于您还没有绑定你的真实邮箱,如果其他用户或者作者回复了您的评论,将不能在第一时间通知您!
发布评论
评论(3)
对于正确的登录系统来说,它相当复杂。
使用 HttpContext.Current.User 的好处是您可以标记方法属性。
我不确定正常的 asp.net 但它在 asp MVC 中工作得很好
如果你想使用 cookie,请尝试 System.Web.Securitiy.FormsAuthenticationTicket 和 FormsAuthentication
示例
its quite complicate for proper login system.
the good thing of using HttpContext.Current.User is u can mark method attribute.
i'm not sure for normal asp.net but it work very well in asp MVC
if u want to use cookies, try System.Web.Securitiy.FormsAuthenticationTicket and FormsAuthentication
sample
您可以使用 RedirectFromLogin 重定向到用户请求但无法访问的页面由于身份验证而进行访问,或者如果您想保持对用户重定向到的位置的控制,可以使用 SetAuthCookie
You can use RedirectFromLogin to redirect to the page the user requested but was unable to visit due to authentication or if you want to maintain control of where the user gets redirected to you can use SetAuthCookie
使用这个:
Use this: