【问题标题】:Alert on gridview edit based on permission基于权限的gridview编辑警报
【发布时间】:2014-07-30 02:53:00
【问题描述】:

我在行的开头有一个带有编辑选项的gridview。我还维护一个名为 Permission 的单独表,在其中维护用户权限。我拥有三种不同类型的权限,例如管理员、潜在客户、程序员。这三个都可以访问gridview。除了管理员,如果有人试图在单击编辑选项时编辑网格视图,我需要发出类似This row has important validation and make sure you make proper changes 的警报。

当我编辑时,发生在名为Application 的表上的操作。该表有一个名为Comments 的列。此外,只有当他们尝试编辑 Comments 列中包含这些值的行时,才会发出警报。

ManLog datas Funding Approved Exported Applications

到目前为止我的尝试。

public bool IsApplicationUser(string userName)
{
    return CheckUser(userName);
}

public static bool CheckUser(string userName)
{
    string CS = ConfigurationManager.ConnectionStrings["ConnectionString"].ToString();
    DataTable dt = new DataTable();
    using (SqlConnection connection = new SqlConnection(CS))
    {
        SqlCommand command = new SqlCommand();
        command.Connection = connection;
        string strquery = "select * from Permissions where AppCode='Nest' and UserID = '" + userName + "'";
        SqlCommand cmd = new SqlCommand(strquery, connection);
        SqlDataAdapter da = new SqlDataAdapter(cmd);
        da.Fill(dt);
    }
    if (dt.Rows.Count >= 1)
        return true;
    else
        return true;
}

 protected void Details_RowCommand(object sender, GridViewCommandEventArgs e)
{
    string currentUser = HttpContext.Current.Request.LogonUserIdentity.Name;
    string str = ConfigurationManager.ConnectionStrings["ConnectionString"].ToString();
    string[] words = currentUser.Split('\\');
    currentUser = words[1];
    bool appuser = IsApplicationUser(currentUser);
    if (appuser)
    {
        DataSet ds = new DataSet();
        using (SqlConnection connection = new SqlConnection(str))
        {
            SqlCommand command = new SqlCommand();
            command.Connection = connection;
            string strquery = "select Role_Cd from User_Role where AppCode='PM' and UserID = '" + currentUser + "'";
            SqlCommand cmd = new SqlCommand(strquery, connection);
            SqlDataAdapter da = new SqlDataAdapter(cmd);
            da.Fill(ds);
        }

        if (e.CommandName.Equals("Edit") && ds.Tables[0].Rows[0]["Role_Cd"].ToString().Trim() != "ADMIN")
        {
            int index = Convert.ToInt32(e.CommandArgument);

            GridView gvCurrentGrid = (GridView)sender;
            GridViewRow row = gvCurrentGrid.Rows[index];

            string strID = ((Label)row.FindControl("lblID")).Text;
            string strAppName = ((Label)row.FindControl("lblAppName")).Text;
            Response.Redirect("AddApplication.aspx?ID=" + strID + "&AppName=" + strAppName + "&Edit=True");
        }
    }
}

如果我需要添加一些内容,请告诉我。感谢您的任何建议。

【问题讨论】:

    标签: c# asp.net .net c#-4.0 gridview


    【解决方案1】:
    public static bool CheckUserAdminOrNot(your arguments)
    {
        string currentUser = HttpContext.Current.Request.LogonUserIdentity.Name;
        string str = ConfigurationManager.ConnectionStrings["ConnectionString"].ToString();
        string[] words = currentUser.Split('\\');
        currentUser = words[1];
        bool appuser = IsApplicationUser(currentUser);
        if (appuser)
        {
            DataSet ds = new DataSet();
            using (SqlConnection connection = new SqlConnection(str))
            {
                SqlCommand command = new SqlCommand();
                command.Connection = connection;
                string strquery = "select Role_Cd from User_Role where AppCode='PM' and UserID = '" + currentUser + "'";
                SqlCommand cmd = new SqlCommand(strquery, connection);
                SqlDataAdapter da = new SqlDataAdapter(cmd);
                da.Fill(ds);
            }
    
            if(user is not Admin)
    
                return string that you want....
            }
        }
    }
    

    之后,您在 ajax 中获得响应,使用此响应并重定向页面并在您想要的 url 中传递值...

    【讨论】:

      猜你喜欢
      • 1970-01-01
      • 2017-08-24
      • 2014-11-18
      • 1970-01-01
      • 1970-01-01
      • 1970-01-01
      • 2021-05-15
      • 2018-04-01
      • 2018-01-27
      相关资源
      最近更新 更多