Question about Security

Ask a Question related to ASP.NET General, Design and Development.

  1. #1

    Default Question about Security

    I'm going to be writing an asp.net application that certain users have
    access to specific pages and others don't. User authorization will be
    handled within the application via a login page. My question is, what is a
    good approach to use to prevent certain users from accessing a page while
    allowing others access?

    As it stands, I'm planning to use a session variable to first make sure the
    user has been logged into the system and second has access to the requested
    page. If either case is false, the user would be redirected to the login
    page.

    Is there a better way to handle this in asp.net?



    Jeff Cope Guest

  2. Similar Questions and Discussions

    1. CF security question
      I was wondering, is it possible, and if so a good idea, to put your secured admin pages behind CF security and .htaccess? In other words put your...
    2. A Question regarding SWF security when using FCS
      I know that there is probably no way to completely secure your Flash development work if you want to have end users see it...I was wondering (not...
    3. Security Question
      Hey all... I am after some help.. I have a database where i want only employees within a particular organisation to read details about other...
    4. Another question for AIX Security
      When I did a security review on Solaris two years ago, one of the items I checked was to verify permission for both files /var/adm/utmp and...
    5. Security Question ???
      We have a small peer to peer network with nine XP-Pro Computers networked and connected to the Internet through a DSl router/modem. One computer is...
  3. #2

    Default Re: Question about Security

    I would suggest to derive all your pages from a custom "BasePage" (that
    itself is dervied from the standard Page class. Within this base class,
    you could expose logic to test the user's security context that is being
    tested in your web forms, eg

    if (!HasPermission(CustomPermission.EditContent))
    {
    //show error or whatever
    }


    The granularity may be chosen depending on your needs:

    protected bool IsAdmin();
    protected bool HasPermission(CustomPermission permission);
    protected bool IsInRole (CustomRole role);



    HTH

    Philipp




    Jeff Cope wrote:
    > I'm going to be writing an asp.net application that certain users have
    > access to specific pages and others don't. User authorization will be
    > handled within the application via a login page. My question is, what is a
    > good approach to use to prevent certain users from accessing a page while
    > allowing others access?
    >
    > As it stands, I'm planning to use a session variable to first make sure the
    > user has been logged into the system and second has access to the requested
    > page. If either case is false, the user would be redirected to the login
    > page.
    >
    > Is there a better way to handle this in asp.net?
    >
    >
    >
    Philipp Sumi Guest

  4. #3

    Default Re: Question about Security

    Thanks for your help.


    jeffreycope Guest

Posting Permissions

  • You may not post new threads
  • You may post replies
  • You may not post attachments
  • You may not edit your posts

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139