ASP.NET Web Pages - WebSecurity Object


Description

WebSecurity ObjectProvides security and authentication for ASP.NET Web Pages applications.

Through the WebSecurity object, you can create user accounts, log in and log out users, reset or change passwords, and many other security-related functions.


WebSecurity Object Reference Manual - Properties

Properties Description
CurrentUserId Gets the ID of the currently logged-in user.
CurrentUserName Gets the name of the currently logged-in user.
HasUserId Returns true if there is a current user ID.
IsAuthenticated Returns true if the current user is logged in.

WebSecurity Object Reference Manual - Methods

Methods Description
ChangePassword() Changes the password for the specified user.
ConfirmAccount() Confirms an account using an account confirmation token.
CreateAccount() Creates a new user account.
CreateUserAndAccount() Creates a new user account.
GeneratePasswordResetToken() Generates a password reset token that can be sent to the user via email so that the user can reset their password.
GetCreateDate() Gets the time when the specified membership was created.
GetPasswordChangeDate() Gets the date and time when the password was changed.
GetUserId() Gets the user ID based on the username.
InitializeDatabaseConnection() Initializes the WebSecurity system (database).
IsConfirmed() Checks whether a user has been confirmed. Returns true if confirmed. (For example, confirmation can be done via email.)
IsCurrentUser() Checks whether the current user's name matches the specified username. Returns true if it matches.
Login() Sets the authentication token and logs in the user.
Logout() Removes the authentication token and logs out the user.
RequireAuthenticatedUser() Sets the HTTP status to 401 (Unauthorized) if the user is not authenticated.
RequireRoles() Sets the HTTP status to 401 (Unauthorized) if the current user is not a member of the specified role.
RequireUser() Sets the HTTP status to 401 (Unauthorized) if the current user is not the user with the specified username.
ResetPassword() If the password reset token is valid, changes the user's password to a new password.
UserExists() Checks whether the specified user exists.


Technical Data

Name Value
Class WebMatrix.WebData.WebSecurity
Namespace WebMatrix.WebData
Assembly WebMatrix.WebData.dll


Initialize the WebSecurity Database

If you want to use the WebSecurity object in your code, you must first create or initialize the WebSecurity database.

In your web root directory, create a page named_AppStart.cshtmlthe page (if it already exists, edit the page directly).

Copy the following code into the file:

_AppStart.cshtml

@{
WebSecurity.InitializeDatabaseConnection("Users", "UserProfile", "UserId", "Email", true);
}

The code above will run every time the website (application) starts. It initializes the WebSecurity database.

"Users"Is the name of the WebSecurity database (Users.sdf).

"UserProfile"Is the name of the database table that contains user profile information.

"UserId"Is the name of the column that contains the user ID (primary key).

"Email"Is the name of the column that contains the username.

The last parametertrueIs a boolean value that indicates that if the user profile table and membership table do not exist, the tables will be created automatically. If you do not want to create the tables automatically, set the parameter tofalse。

lamp Althoughtruemeans automatic database creationTable, but the database will not be created automatically. Therefore the database must exist.


WebSecurity Database

UserProfileThe table creates and saves a record for each user, with the user ID (primary key) and username (email):

UserId Email
1 john@johnson.net
2 peter@peterson.com
3 lars@larson.eut

MembershipThe table contains membership information, such as when the user was created, whether the membership has been confirmed, when the membership was confirmed, and so on.

The details are as follows (some columns are not displayed):

User
Id
Create
Date
Confirmation
Token
Is
Confirmed
Last
Password
Failure
Password Password
Change
1 12.04.2012 16:12:17 NULL True NULL AFNQhWfy.... 12.04.2012 16:12:17

Note: If you want to see all columns and content, open the database and look at each table inside.


Simple Membership Configuration

When you use the WebSecurity object, if your site is not configured to use the ASP.NET Web Pages membership systemSimpleMembership, an error may occur.

If the configuration of the hosting provider's server is different from the configuration of your local server, an error may also occur. To solve this problem, add the following elements to the Web.config file of your website:

<appSettings>
<add key="enableSimpleMembership" value="true" />
</appSettings>


Other extensions