【问题标题】:Authenticating username and password using Session使用 Session 验证用户名和密码
【发布时间】:2015-12-08 21:48:49
【问题描述】:

我在 stackoverflow 和 Google 上都查看了这里,但无法找到与我的问题相关的答案,所以我将其发布在这里。

我有一个登录页面,用户被引导输入他们的用户名和密码,它们都存储在 MySQL 数据库中。用户名以纯文本形式存储,密码经过哈希处理(使用 CrackStation - https://crackstation.net/hashing-security.htm#aspsourcecode),哈希值存储在数据库中。我能够使用用户名和密码成功让用户登录一次,但我想使用 SESSION 以便用户可以在网站上导航,而不必每次进入不同页面时都登录。我很容易在我的测试环境中使用 SESSION,因为密码以纯文本形式存储,但现在密码被散列,我无法让 Session 在我的代码中工作。所以我想知道我可以做些什么来获取密码以在 SESSION 中进行验证。

我在登录页面上使用的代码如下:

protected void Page_Load(object sender, EventArgs e)
{
    try
    {
        admin = Convert.ToInt16(Request.QueryString["Admin"]);               
        Instructor = Convert.ToInt16(Request.QueryString["Inst"]);               

        if (Session["username"] == null || (string)(Session["username"]) == "")
        {                   
            token = Request.QueryString["tokenNumber"];

            lblUsername.Visible = true;
            txtUsername.Visible = true;
            lblPassword.Visible = true;
            txtPassword.Visible = true;
            btnlogin.Visible = true;
        }

        else if (Session["username"] != null || (string)(Session["username"]) != "")
        {                   
            username = (string)Session["username"];
            userType = (string)Session["userType"];
            pass = (string)Session["password"];                   

            if (userType == "Participant")
            {                       
                Response.Redirect("/srls/StudentUser");
            }
            else if (userType == "Coordinator")
            {
                Response.Redirect("/srls/CoordinatorUser");                       
            }
            else if (userType == "Instructor")
            {
                Response.Redirect("/srls/InstructorUser");
            }
        }


    }
    catch (Exception exc) //Module failed to load
    {
        Exceptions.ProcessModuleLoadException(this, exc);
    }
}

protected void btnlogin_Click(object sender, System.EventArgs e)
{
    char activation;

    if (Request.QueryString["tokenNum"] != null)
    {
        using (OdbcConnection dbConnection = new OdbcConnection(srlsConnStr))
        {
            dbConnection.Open();
            {
                OdbcCommand dbCommand = new OdbcCommand();
                dbCommand.Connection = dbConnection;
                dbCommand.CommandText = @"SELECT tokenNum FROM srlslogin WHERE user_email_pk = ?";
                dbCommand.Parameters.AddWithValue("@user_email_pk", txtUsername.Text);
                dbCommand.ExecuteNonQuery();

                OdbcDataReader dataReader = dbCommand.ExecuteReader();
                while (dataReader.Read())
                {
                    if (token == dataReader["tokenNum"].ToString())
                    {
                        updateActivationStatus(txtUsername.Text);
                        LoginWithPasswordHashFunction();
                    }
                    else
                    {
                        test.Text = "You are not authorized to login! Please activate your account following the activation link sent to your email " + txtUsername.Text + " !";
                    }
                }
            }
            dbConnection.Close();
        }

    }
    else if (Request.QueryString["tokenNum"] == null)
    {
        using (OdbcConnection dbConnection = new OdbcConnection(srlsConnStr))
        {
            dbConnection.Open();
            {
                OdbcCommand dbCommand1 = new OdbcCommand();
                dbCommand1.Connection = dbConnection;
                dbCommand1.CommandText = @"SELECT * FROM srlslogin WHERE user_email_pk = ?;";

                dbCommand1.Parameters.AddWithValue("@user_email_pk", txtUsername.Text);
                dbCommand1.ExecuteNonQuery();

                OdbcDataReader dataReader1 = dbCommand1.ExecuteReader();
                if (dataReader1.Read())
                {
                    activation = Convert.ToChar(dataReader1["activation_status"]);
                    if (activation == 'Y')
                    {
                        activation status, activation == Y";
                        LoginWithPasswordHashFunction();
                    }
                    else
                    {
                        lblMessage.Text = "Please activate your account following the Activation link emailed to you at <i>" + txtUsername.Text + "</i> to Continue!";
                    }
                }
                else
                {
                    lblMessage.Text = "Invalid Username or Password";
                }
                dataReader1.Close();
            }
            dbConnection.Close();
        }
    }
}

private void LoginWithPasswordHashFunction()
{
    List<string> salthashList = null;
    List<string> usernameList = null;

    try
    {
        using (OdbcConnection dbConnection = new OdbcConnection(srlsConnStr))
        {
            dbConnection.Open();
            {
                OdbcCommand dbCommand = new OdbcCommand();
                dbCommand.Connection = dbConnection;
                dbCommand.CommandText = @"SELECT slowhashsalt, user_email_pk FROM srlslogin WHERE user_email_pk = ?;";

                dbCommand.Parameters.AddWithValue(@"user_email_pk", txtUsername.Text);
                OdbcDataReader dataReader = dbCommand.ExecuteReader();
                while (dataReader.HasRows && dataReader.Read())
                {
                    if (salthashList == null)
                    {
                        salthashList = new List<string>();
                        usernameList = new List<string>();
                    }

                    string saltHashes = dataReader.GetString(dataReader.GetOrdinal("slowhashsalt"));
                    salthashList.Add(saltHashes);

                    string userInfo = dataReader.GetString(dataReader.GetOrdinal("user_email_pk"));

                    usernameList.Add(userInfo);
                }

                dataReader.Close();

                if (salthashList != null)
                {

                    for (int i = 0; i < salthashList.Count; i++)
                    {
                        bool validUser = PasswordHash.ValidatePassword(txtPassword.Text, salthashList[i]);
                        if (validUser == true)
                        {                                    
                            Session["user_email_pk"] = usernameList[i];

                            OdbcCommand dbCommand1 = new OdbcCommand();
                            dbCommand1.Connection = dbConnection;
                            dbCommand1.CommandText = @"SELECT user_status FROM srlslogin WHERE user_email_pk = ?;";

                            dbCommand1.Parameters.AddWithValue("@user_email_pk", txtUsername.Text);
                            dbCommand1.ExecuteNonQuery();

                            OdbcDataReader dataReader1 = dbCommand1.ExecuteReader();
                            while (dataReader1.Read())
                            {
                                user_status = dataReader1["user_status"].ToString();
                                Session["userType"] = user_status;
                            }

                            Response.BufferOutput = true;

                            if (user_status == "Participant")
                            {
                                Response.Redirect("/srls/StudentUser", false);
                            }
                            else if (user_status == "Coordinator")
                            {
                                Response.Redirect("/srls/CoordinatorUser", false);
                            }
                            else if (user_status == "Instructor")
                            {
                                Response.Redirect("/srls/InstructorUser", false);
                            }

                            dataReader1.Close();
                Response.Redirect(/srls/StudentUser) - Goes to Login Page";
                        }
                        else
                        {
                            lblMessage.Text = "Invalid Username or Password! Please Try Again!";
                        }
                    }
                }
            }
            dbConnection.Close();
        }
    }
    catch (Exception ex)
    {

    }

【问题讨论】:

  • 您是否熟悉PostBacks,例如您需要存储在OnSession_Start 中,例如声明一个像这样的变量,例如HttpContext.Current.Session["isValidUser"] = false;,然后在您的登录或验证部分代码中设置session 变量如果有效用户为 true HttpContext.Current.Session["isValidUser"] = true;,因为按钮会导致 PostBack,您需要在 Page_Load 事件中的登录中进行一些 if(!IsPostBack) 检查。
  • 感谢@MethodMan 的建议,我会看一下,看看效果如何。

标签: c# mysql asp.net session session-variables


【解决方案1】:

您应该在会话中存储用户名和密码。您应该存储用户已成功登录的“事实”。但实际上您甚至不应该自己这样做。 ASP.NET 带有各种身份验证方法。请查看http://www.asp.net/identity 以开始使用。

【讨论】:

  • 感谢@Mark 的回答,我会看一下链接并从那里开始。
【解决方案2】:

这不是很好的解决方案。不要在会话中存储用户名的登录名、密码、类型等。用户登录您的系统后,只需存储他的 ID。我使用下一种方式:我有登录页面,我有 MasterPage,我所有的网络表单都是从 MasterPage 继承的。在 Page_Init 的 MasterPage 中,我执行以下操作:

string users_role = MyClass.GetUsersRoleById(Session["id"].ToString());

我在数据库中有用户的角色,所以我可以通过 ID 排除用户的角色。例如,每个角色都有一个文件夹。你可以这样做:

if (String.IsNullOrEmpty(users_role)) //if null it means that user have no any role or you didn't checked for authorization first
    Response.Redirect(users_role); //redirect to role's page: e.g. Admin, User, Student, Teacher, so on.

【讨论】:

    猜你喜欢
    • 1970-01-01
    • 1970-01-01
    • 1970-01-01
    • 2023-03-13
    • 1970-01-01
    • 2018-05-26
    • 2013-12-26
    • 2016-01-24
    相关资源
    最近更新 更多