【问题标题】:Forms Authentication User.IsInRole(), Authorize attribute - not working on production serverForms Authentication User.IsInRole(), Authorize 属性 - 不适用于生产服务器
【发布时间】:2013-08-06 15:16:10
【问题描述】:

对不起我的英语不好。

事实:

  • ASP.NET MVC3
  • EF5.
  • 表单认证
  • roleManager 已禁用

我的实现遵循this concept! + 见下面的代码

一切正常

  • 本地服务器 IIS Win7 (WebDeploy)
  • 和我的旧 Windows Server 2008

直到我将应用程序部署到一个

  • 新的 Windows Server 2008 网络

我的角色有问题

  • isInRole()
  • [Authorize(Roles = "member,admin")] 属性

工作不正常。

这里有一些代码 sn-ps + 调试输出

助手类

public static class UserHelper
{
        public static bool IsAdmin(this ViewUserControl pg)
        {
            // @TODO Delete (Glimpse output)

            string s = HttpContext.Current.User.IsInRole("admin") ? "UserHelper.IsAdmin()  IsInRole() == true" : "UserHelper.IsAdmin() Application_AuthenticateRequest  IsInRole() == false";
            string b = pg.Page.User.IsInRole("admin") ? "UserHelper.IsAdmin()  IsInRole() == true" : "UserHelper.IsAdmin() Application_AuthenticateRequest  IsInRole() == false";

            Trace.Write(s);
            Trace.Write(b);           

            var id = HttpContext.Current.User.Identity as FormsIdentity;
            Trace.Write("UserHelper.isAdmin(): UserData"+id.Ticket.UserData);

            // ============================

            return HttpContext.Current.User.IsInRole("admin");
        }
}

Global.asax.cs

public class MvcApplication : HttpApplication
{
    protected void Application_AuthenticateRequest(Object sender, EventArgs e)
    {
        if (HttpContext.Current.User == null) return;
        if (!HttpContext.Current.User.Identity.IsAuthenticated) return;
        if (!(HttpContext.Current.User.Identity is FormsIdentity)) return;

        var id = HttpContext.Current.User.Identity as FormsIdentity;
        var userState = new UserState();
        userState.FromString(id.Ticket.UserData);
        HttpContext.Current.User = new GenericPrincipal(id, userState.Rollen.Split(new[] { ',' }));

        // @TODO Delete (Glimpse output)
        Trace.Write("Global.asax.cs -> Application_AuthenticateRequest Userdata: "+id.Ticket.UserData);
        string s = HttpContext.Current.User.IsInRole("admin") ? "Global.asax.cs -> Application_AuthenticateRequest IsInRole() == true" : "Global.asax.cs -> Application_AuthenticateRequest IsInRole() == false";
        Trace.Write(s);
    }

AccountController.cs(示例)

   [Authorize(Roles = "member,admin")]
   [UserActive]
   public ActionResult ChangePassword()
   {
     return View();
   }

FormAuthService.cs

public class FormAuthService : IFormsAuthentication
{
    public void Login(string userName, bool createPersistentCookie, IEnumerable<string> roles, int? userID = null)
    {
        var str = string.Join(",", roles);

        var userData = new UserState
        {
            Benutzername = userName,
            ID = userID.HasValue ? userID.Value : 0,
            Rollen = str,
            IsAdmin = str.Split(',').Contains("admin")
        };

        var authTicket = new FormsAuthenticationTicket(
            1,
            userName,
            DateTime.Now,
            DateTime.Now.AddDays(30),
            createPersistentCookie,
            userData.ToString(),
            "/"
        );

        var cookie = new HttpCookie(FormsAuthentication.FormsCookieName, FormsAuthentication.Encrypt(authTicket));

        if (authTicket.IsPersistent)
            cookie.Expires = authTicket.Expiration;

        HttpContext.Current.Response.Cookies.Add(cookie);
    }
}

我正在使用 Glimpse 调试我的代码。 我想要实现的是第一个屏幕截图......

在我的 UserHelper 类 和所有其他具有 [Authorize] 属性的类中 它适用于本地此设置。

但是当我将应用程序部署到远程 IIS 时 它无法识别我以管理员身份登录(我已登录但角色不起作用)。您可以看到,在第二个屏幕截图中,带有“admin”的 UserData 存在,但 IsInRole 方法失败....

截图:

本地主机 http://s13.postimg.org/o9uqhlv6v/wi_local_glimpse_works.png

远程服务器 http://s9.postimg.org/pcavzvczj/wi_local_glimpse_works23.png

我错过了什么?有人遇到过同样的问题吗?

【问题讨论】:

  • 这可能很明显,但您是否检查了远程数据库以确保您的用户表和角色行存在?它可能就像创建表格和数据一样简单。
  • 您好,数据库应该没问题。我在本地环境中使用与生产服务器上相同的(远程)数据库。我检查了两次。

标签: asp.net-mvc authentication iis forms-authentication


【解决方案1】:

好的,我自己解决了,This post 让我走上了正轨。

一个问题是,我无法更改目录权限 应用程序池用户 默认网站

所以我在 IIS 7.5 中创建了一个新网站 并再次部署我的应用程序。

然后我检查了应用程序池用户对该目录的权限。

D:\webapplication -> right click -> Properties -> Security -> allow modify 
for the Application Pool User.

最后我得到了一些 .dll 丢失的错误(真的不知道为什么)。所以我upgraded我的 ASP.NET MVC 3 应用程序到 MVC 4,现在一切正常(本地和远程)。

【讨论】:

    猜你喜欢
    • 2023-03-04
    • 1970-01-01
    • 2015-07-18
    • 1970-01-01
    • 1970-01-01
    • 1970-01-01
    • 2017-03-31
    • 1970-01-01
    • 1970-01-01
    相关资源
    最近更新 更多