Mixing ASP.NET and ASP.NET MVC Web Forms

I am having problems with forms authentication. The root web.config is configured to deny access to all unauthenticated users with a structure like:

Controllers
Folder - WebForms
Folder1 - WebForms
Model
Shared Folder - Web Forms with web.config to allow public access views of
web.config with deny

I also need to have a public controller, but if I leave the authorize attribute from the root web.config it will still block access to the views folder. I want to avoid doing something like below, I can avoid it.

Controllers
WebForms
 -Folder
 -Folder2
 -web.config to ban unauthorized users
Views
web.config with public access

Does anyone have any thoughts to get the first directory structure working?

+1


a source to share


1 answer


I am having problems with what the config sections look like. Can you edit the post and drop those sections into the code block (the binary button on the text editor toolbar).

Is the purpose of blocking everything WebForms and making the MVC driven bits public?



(The only thing left to do is add this to the comment, but I have no comments to comment yet.)

[Edit] For the sake of something useful, but admitting that I still don't know the ultimate purpose for which the bits you want to block are on the MVC side, is it possible to use security attributes in your controllers? For example, instead of trying to block actions (or entire controllers) in the web.config file, you can add [Authorize (Roles = "Your Circles") to specific actions or to the top of the controller. Pros and cons of this approach, but I like it since I don't have to mess with the config file I just don't like. This assumes, of course, that you are using the standard ASP.NET membership provider, but even if you collapsed yourself, you should accomplish the task in a similar manner with some extra effort. Just a thought ...

0


a source







All Articles