ASP.NET Web Pages - WebSecurity Object
Description
WebSecurity ObjectProvides security and authentication for ASP.NET Web Pages applications.
Through the WebSecurity object, you can create user accounts, log in and log out users, reset or change passwords, and many other security-related functions.
WebSecurity Object Reference Manual - Properties
| Properties | Description |
|---|---|
| CurrentUserId | Gets the ID of the currently logged-in user. |
| CurrentUserName | Gets the name of the currently logged-in user. |
| HasUserId | Returns true if there is a current user ID. |
| IsAuthenticated | Returns true if the current user is logged in. |
WebSecurity Object Reference Manual - Methods
| Methods | Description |
|---|---|
| ChangePassword() | Changes the password for the specified user. |
| ConfirmAccount() | Confirms an account using an account confirmation token. |
| CreateAccount() | Creates a new user account. |
| CreateUserAndAccount() | Creates a new user account. |
| GeneratePasswordResetToken() | Generates a password reset token that can be sent to the user via email so that the user can reset their password. |
| GetCreateDate() | Gets the time when the specified membership was created. |
| GetPasswordChangeDate() | Gets the date and time when the password was changed. |
| GetUserId() | Gets the user ID based on the username. |
| InitializeDatabaseConnection() | Initializes the WebSecurity system (database). |
| IsConfirmed() | Checks whether a user has been confirmed. Returns true if confirmed. (For example, confirmation can be done via email.) |
| IsCurrentUser() | Checks whether the current user's name matches the specified username. Returns true if it matches. |
| Login() | Sets the authentication token and logs in the user. |
| Logout() | Removes the authentication token and logs out the user. |
| RequireAuthenticatedUser() | Sets the HTTP status to 401 (Unauthorized) if the user is not authenticated. |
| RequireRoles() | Sets the HTTP status to 401 (Unauthorized) if the current user is not a member of the specified role. |
| RequireUser() | Sets the HTTP status to 401 (Unauthorized) if the current user is not the user with the specified username. |
| ResetPassword() | If the password reset token is valid, changes the user's password to a new password. |
| UserExists() | Checks whether the specified user exists. |
Technical Data
| Name | Value |
|---|---|
| Class | WebMatrix.WebData.WebSecurity |
| Namespace | WebMatrix.WebData |
| Assembly | WebMatrix.WebData.dll |
Initialize the WebSecurity Database
If you want to use the WebSecurity object in your code, you must first create or initialize the WebSecurity database.
In your web root directory, create a page named_AppStart.cshtmlthe page (if it already exists, edit the page directly).
Copy the following code into the file:
_AppStart.cshtml
WebSecurity.InitializeDatabaseConnection("Users", "UserProfile", "UserId", "Email", true);
}
The code above will run every time the website (application) starts. It initializes the WebSecurity database.
"Users"Is the name of the WebSecurity database (Users.sdf).
"UserProfile"Is the name of the database table that contains user profile information.
"UserId"Is the name of the column that contains the user ID (primary key).
"Email"Is the name of the column that contains the username.
The last parametertrueIs a boolean value that indicates that if the user profile table and membership table do not exist, the tables will be created automatically. If you do not want to create the tables automatically, set the parameter tofalse。
| Althoughtruemeans automatic database creationTable, but the database will not be created automatically. Therefore the database must exist. |
WebSecurity Database
UserProfileThe table creates and saves a record for each user, with the user ID (primary key) and username (email):
| UserId | |
|---|---|
| 1 | [email protected] |
| 2 | [email protected] |
| 3 | [email protected] |
MembershipThe table contains membership information, such as when the user was created, whether the membership has been confirmed, when the membership was confirmed, and so on.
The details are as follows (some columns are not displayed):
| User Id |
Create Date |
Confirmation Token |
Is Confirmed |
Last Password Failure |
Password | Password Change |
|---|---|---|---|---|---|---|
| 1 | 12.04.2012 16:12:17 | NULL | True | NULL | AFNQhWfy.... | 12.04.2012 16:12:17 |
Note: If you want to see all columns and content, open the database and look at each table inside.
Simple Membership Configuration
When you use the WebSecurity object, if your site is not configured to use the ASP.NET Web Pages membership systemSimpleMembership, an error may occur.
If the configuration of the hosting provider's server is different from the configuration of your local server, an error may also occur. To solve this problem, add the following elements to the Web.config file of your website:
<add key="enableSimpleMembership" value="true" />
</appSettings>
Other extensions