代码之家  ›  专栏  ›  技术社区  ›  ryan

ASP.NET登录控件自定义身份验证失败

  •  1
  • ryan  · 技术社区  · 15 年前

    我的密码

    protected void LogonForm_Authenticate(object sender, AuthenticateEventArgs e)
    {
        bool auth = false;
    
        if (FormsAuthentication.Authenticate(LogonForm.UserName, LogonForm.Password))
        {
            auth = true;
        }
    
        e.Authenticated = auth;
    
    }
    

    结果是假的。当我没有指定OnAuthenticate事件时,用户将被验证,它将按预期工作。给什么?

    我只想调用默认的OnAuthenticate代码,然后在代码末尾添加一个额外的检查。我在两种情况下都使用LDAP进行身份验证。

    2 回复  |  直到 15 年前
        1
  •  2
  •   andrei m    15 年前

    正如MSDN文档中所提到的那样 FormsAuthentication.Authenticate 方法,以防凭据存储在Web.config文件中,如下所示:

    <authentication mode="Forms">
        <forms loginUrl="login.aspx">
            <credentials passwordFormat="Clear">
                <user name="user1" password="password1" />
                <user name="user2" password="password2" />
            </credentials>
     </forms>
    </authentication>
    

    但是,如果要针对从MembershipProvider抽象类(如SqlMembershipProvider、ActiveDirectoryMembershipProvider或其他自定义提供程序)继承的成员资格提供程序验证凭据,则应使用 Membership.ValidateUser 方法代替。

    我认为替换

    if (FormsAuthentication.Authenticate(LogonForm.UserName, LogonForm.Password))
    

    具有

    if (Membership.ValidateUser(LoginUser.UserName, LoginUser.Password))
    

    会解决你的问题。

        2
  •  1
  •   ewitkows    15 年前

    你能提供更多的代码吗?Authenticate only Authenticate's a user,it not set a cookie,etc.使用此方法确定用户名/密码是否有效(也称为如果返回True)

    请改为设置cookie:

    Dim boolVal as Boolean = FormsAuthentication.Authenticate(LogonForm.UserName, LogonForm.Password)
    If boolVal Then
       FormsAuthentication.SetAuthCookie(LogonForm.UserName,False)
    End If
    
    推荐文章