الفريق العربي للبرمجةأرشيف المنتديات · 2000 – 2023
نسخة أرشيفية للقراءة فقط — التسجيل والمشاركة مغلقان، والمحتوى محفوظ كما كان.

لايعمل هذا الكود لحماية الموقع من خلال Forms Authenticaion

بدأه mr_viva في 21 مايو 2008 · 1 رد · 734 مشاهدة · في ASP.NET
مشاركة: واتساب X فيسبوك تيليجرام
#1 صاحب الموضوع

المشكلة تتلخص في انو المتصح ما بيعمل تحويل للمستخدم الى صفحة اللوج ان في حال انه ادخل اسم الصفحة المطلوبة مباشر , أرجو من الأخوان المساعدة و شكرا

هذا الكود في web.config

<?xml version="1.0"?>
<configuration xmlns="http://schemas.microsoft.com/.NetConfiguration/v2.0">
	<!-- Register a new config section-->
	<configSections>
		<section name="SmallBusinessDataProviders" type="SmallBusinessDataProvidersSection" requirePermission="false"/>
	</configSections>
	<!-- Connection string, currently configured for SQL Express-->
	<connectionStrings>
		<remove name="SQLConnectionString"/>
		<remove name="AccessFileName"/>
		<!--<add name="AccessconnString" connectionString="Provider=Microsoft.Jet.OLEDB.4.0;Data Source=\web\App_Data\airflights2003.mdb" providerName="System.Data.OleDb"/> -->
		<add name="AccessconnString" connectionString="Dsn=AirFlight_573411" providerName="System.Data.Odbc"/>
		<!--<add name="AccessconnString" connectionString="FILEDSN=d:\hosting\yaldeeb14879\_dsn\access_airflights2003.dsn" providerName="System.Data.Odbc" />-->
		<!-- //<add name="AccessconnString" connectionString="Provider=Microsoft.Jet.OLEDB.4.0;Data Source=t:\site2\App_Data\airflights2003.mdb" providerName="System.Data.OleDb"/>-->
		<add name="SQLConnectionString" connectionString="Data Source=.\SQLExpress;integrated security=true;attachdbfilename=|DataDirectory|SmallCompanyDB.mdf;user instance=true"/>
	</connectionStrings>

  <system.web>
    <customErrors mode="Off"/>
    <compilation debug="true"/>

    <authentication mode= "Forms">

		  <forms name=".ASPXAUH" 
             loginUrl="Start.aspx" 
             protection="All" 
             timeout="30" 
            />

	  </authentication>

	  <authorization>
		  <deny users="?" />
	  </authorization>



  </system.web>

	<location path="Default.aspx">
		<system.web>
			<authorization>
				<allow users="?"/>
			</authorization>
		</system.web>
	</location>
	<location path="news.aspx">
		<system.web>
			<authorization>
				<allow users="?"/>
			</authorization>
		</system.web>
	</location>
	<location path="Contact.aspx">
		<system.web>
			<authorization>
				<allow users="?"/>
			</authorization>
		</system.web>
	</location>
	<location path="About.aspx">
		<system.web>
			<authorization>
				<allow users="?"/>
			</authorization>
		</system.web>
	</location>
	<location path="RegisterAgents.aspx">
		<system.web>
			<authorization>
				<allow users="?"/>
			</authorization>
		</system.web>
	</location>
	<location path="test.aspx">
		<system.web>
			<authorization>
				<allow users="?"/>
			</authorization>
		</system.web>
	</location>

	</configuration>

وهذا الكود في globals.asax

Sub Application_AuthenticateRequest(ByVal sender As Object, ByVal e As EventArgs)
        ' Fires upon attempting to authenticate the use
        If Not (HttpContext.Current.User Is Nothing) Then
            If HttpContext.Current.User.Identity.IsAuthenticated Then
                If TypeOf HttpContext.Current.User.Identity Is FormsIdentity Then
                    Dim fi As FormsIdentity = CType(HttpContext.Current.User.Identity, FormsIdentity)
                    Dim fat As FormsAuthenticationTicket = fi.Ticket

                    Dim astrRoles As String() = fat.UserData.Split("|"c)
                    HttpContext.Current.User = New System.Security.Principal.GenericPrincipal(fi, astrRoles)
                End If
            End If
        End If
    End Sub

وهذا كود زر login في صفحة login

Protected Sub CmdLogin_Click(ByVal sender As Object, ByVal e As System.EventArgs) Handles CmdLogin.Click
        Dim usertype As String
        'FormsAuthentication.RedirectFromLoginPage(Me.txtUsername.Text, True)
        usertype = authinUser(Me.txtUsername.Text, Me.Txtpassword.Text)
        If usertype = "Agent" Then 'Me.txtUsername.Text = "1" And Me.Txtpassword.Text = "1" Then
            Me.Panel1.Visible = True
            lblStatus.Text = "لقد تم تسجيل الدخول بنجاح"
            Session("UserName") = Me.txtUsername.Text
            Session("Usertype") = usertype
            Panel2.Visible = False
            Panel4.Visible = True
            cmdReg.Visible = False
            issticket()
end sub






Private Function authinUser(ByVal username As String, ByVal userpassword As String) As String
        Dim df As New DataFunctions
        Dim agetnid As String
        Dim adminid As String
        Dim commid As String
        authinUser = ""
        agetnid = df.GetId("select * from agents where agent_login='" & username & "' and agent_password='" & userpassword & "'and agent_notactive=0 ")
        If agetnid <> 0 Then
            authinUser = "Agent"
        ElseIf agetnid = 0 Then
            adminid = df.GetId("select * from users where user_name='" & username & "' and user_password='" & userpassword & "' and user_type='Admin'")
            If adminid <> 0 Then
                authinUser = "Admin"
            ElseIf adminid = 0 Then
                commid = df.GetId("select * from users where user_name='" & username & "' and user_password='" & userpassword & "'and user_type='Commite' ")
                If commid <> 0 Then
                    authinUser = "Commite"
                End If
            End If
        End If

        delete72hourRes()
    End Function



   Private Sub issticket()
        Dim strRole As String
        strRole = Session("usertype").ToString
        Dim fat As FormsAuthenticationTicket = New FormsAuthenticationTicket(1, _
             txtUsername.Text, DateTime.Now, _
             DateTime.Now.AddMinutes(30), True, strRole, _
             FormsAuthentication.FormsCookiePath)
        Response.Cookies.Add(New HttpCookie(FormsAuthentication.FormsCookieName, _
         FormsAuthentication.Encrypt(fat)))
        'Response.Redirect(FormsAuthentication.GetRedirectUrl(txtUsername.Text, False))

    End Sub
#2

يجب أن يتم منع المستخدمين الغير معرفين من دخول الصفحات ما عدا صفحة اللوغين و الصفحات التي لا تحتاج حماية.

مثلاً منع الدخول على الصفحة test يجب التعديل في كود الـweb.config

<location path="test.aspx">
<system.web>
<authorization>
<deny users="?"/>
</authorization>
</system.web>
</location>

مواضيع مشابهة