Asp.net mvc security

How can I prevent anonymous access to my ASP.NET mvc controllers? Specifically, I want to require authenticated access to all controllers, but allow anonymous access to resource type files such as .css and .js files. Don't plan on using membership services as I am using Microsoft Geneva.

+1


a source to share


2 answers


One way is for your controllers to inherit (your own) ControllerBase.

Add



[Authorize]

for this class.

+1


a source


You can use the Authorize attribute (action filter) for each action method in every controller if you don't want to subclass the base controller.



See here for action filters: http://www.asp.net/learn/mvc/tutorial-14-cs.aspx

0


a source







All Articles