以前用ASP,PHP,JSP編寫網站代碼的時候,站點安全性總是一件頭疼的事情,雖然我們編寫了用戶登錄,注冊,驗證頁面,但是效果總是不理想。有時候我們不得不用大量的session變量來存放相關信息,處處設防。而在.NET環境下,這個問題處理起來就非常容易了。關鍵是要充分理解web.config文件。首先,介紹一下web.config文件。
<?xml version="1.0" encoding="utf-8" ?> <configuration> <system.web> <!-- 動態調試編譯 設置 compilation debug="true" 以將調試符號(.pdb 信息) 插入到編譯頁中。因為這將創建執行起來 較慢的大文件,所以應該只在調試時將該值設置為 true,而所有其他時候都設置為 false。有關更多信息,請參考有關 調試 ASP.NET 文件的文檔。 --> <compilation defaultLanguage="vb" debug="true" /> <!-- 自定義錯誤信息 設置 customErrors mode="On" 或 "RemoteOnly" 以啟用自定義錯誤信息,或設置為 "Off" 以禁用自定義錯誤信息。 為每個要處理的錯誤添加 <error> 標記。 --> <customErrors mode="RemoteOnly" /> <!-- 身份驗證 此節設置應用程序的身份驗證策略??赡艿哪J绞?/“Windows/”、 /“Forms/”、/“Passport/”和 /“None/” --> <authentication mode="Windows" /> <!-- 授權 此節設置應用程序的授權策略。可以允許或拒絕用戶或角色訪問 應用程序資源。通配符:"*" 表示任何人,"?" 表示匿名 (未授權的)用戶。 --> <authorization> <allow users="*" /> <!-- 允許所有用戶 --> <!-- <allow users="[逗號分隔的用戶列表]" roles="[逗號分隔的角色列表]"/> <deny users="[逗號分隔的用戶列表]" roles="[逗號分隔的角色列表]"/> --> </authorization> <!-- 應用程序級別跟蹤記錄 應用程序級別跟蹤在應用程序內為每一頁啟用跟蹤日志輸出。 設置 trace enabled="true" 以啟用應用程序跟蹤記錄。如果 pageOutput="true",則 跟蹤信息將顯示在每一頁的底部。否則,可以通過從 Web 應用程序 根瀏覽 "trace.axd" 頁來查看 應用程序跟蹤日志。 --> <trace enabled="false" requestLimit="10" pageOutput="false" traceMode="SortByTime" localOnly="true" /> <!-- 會話狀態設置 默認情況下,ASP.NET 使用 cookie 標識哪些請求屬于特定的會話。 如果 cookie 不可用,則可以通過將會話標識符添加到 URL 來跟蹤會話。 若要禁用 cookie,請設置 sessionState cookieless="true"。 --> <sessionState mode="InProc" stateConnectionString="tcpip=127.0.0.1:42424" sqlConnectionString="data source=127.0.0.1;user id=sa;password=" cookieless="false" timeout="20" /> <!-- 全球化 此節設置應用程序的全球化設置。 --> <globalization requestEncoding="utf-8" responseEncoding="utf-8" /> </system.web> </configuration> |
<authentication mode="Forms"> <forms name="yourAuthCookie" loginUrl="login.aspx" protection="All" path="/" /> </authentication> <authorization> <deny users="?" /> </authorization> |
<location path="test.aspx"> <system.web> <authorization> <allow users="?" /> </authorization> </system.web> </location> |
解決了上面兩個問題,相信大家心里一定有底了吧!下面就開始實現login.aspx頁面。利用C#和SQL Server2000,創建一個webform頁面,加入相應的控件。具體代碼如下:
<%@ Page language="c#" Codebehind="login.aspx.cs" AutoEventWireup="false" Inherits="secure.login" %> <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN" > <HTML> <HEAD> <title>Secure Site</title> <meta content="Microsoft Visual Studio 7.0" name="GENERATOR"> <meta content="C#" name="CODE_LANGUAGE"> <meta content="javascript" name="vs_defaultClientScript"> <meta content="http://schemas.microsoft.com/intellisense/ie5" name="vs_targetSchema"> </HEAD> <body MS_POSITIONING="GridLayout"> <form id="login" method="post" runat="server"> <table cellSpacing="0" cellPadding="0" border="0"> <tr> <td vAlign="top" align="left"> <asp:label id="Message" Runat="server" ForeColor="#ff0000"> </asp:label> </td> </tr> <tr> <td vAlign="top" align="left"> <b>E-mail:</b> </td> </tr> <tr> <td vAlign="top" align="left"> <asp:textbox id="username" Runat="server" Width="120"> </asp:textbox> </td> </tr> <tr> <td vAlign="top" align="left"> <b>Password:</b> </td> </tr> <tr> <td vAlign="top" align="left"> <asp:textbox id="password" Runat="server" Width="120" TextMode="Password"> </asp:textbox> </td> </tr> <tr> <td vAlign="top" align="left"> <asp:checkbox id="saveLogin" Runat="server" Text="<b>Save my login</b>"> </asp:checkbox> </td> </tr> <tr> <td vAlign="top" align="right"> <asp:imagebutton id="btnLogin" Runat="server" ImageUrl="/images/w2k/login/btnLogin.gif"> </asp:imagebutton> </td> </tr> </table> </form> </body> </HTML> |
private void InitializeComponent() { this.btnLogin.Click += new System.Web.UI.ImageClickEventHandler(this.btnLogin_Click); . . . } |
事件注冊好之后,自然就是編寫事件處理函數了:
private void btnLogin_Click(object sender, System.Web.UI.ImageClickEventArgs e) { CCommonDB sql = new CCommonDB(); string redirect = ""; if((redirect = sql.AuthenticateUser(this.Session, this.Response, username.Text, password.Text, saveLogin.Checked)) != string.Empty) { // Redirect the user Response.Redirect(redirect); } else { Message.Text = "Login Failed!"; } } |
讀者看完上面的代碼之后一定想問CCommonDB是哪里來的東東,這是我編寫的一個類,用來處理用戶登錄信息的,如果成功則把相關信息寫入session、Cookie和SQL數據庫,同時跳到default.aspx頁面。具體如下:
CCommonDB.cs namespace secure.Components { public class CCommonDB : CSql { public CCommonDB() : base() { } public string AuthenticateUser( System.Web.SessionState.HttpSessionState objSession, // Session Variable System.Web.HttpResponse objResponse, // Response Variable string email, // Login string password, // Password bool bPersist // Persist login ) { int nLoginID = 0; int nLoginType = 0; // Log the user in Login(email, password, ref nLoginID, ref nLoginType); if(nLoginID != 0) // Success { // Log the user in System.Web.Security.FormsAuthentication.SetAuthCookie(nLoginID.ToString(), bPersist); // Set the session varaibles objSession["loginID"] = nLoginID.ToString(); objSession["loginType"] = nLoginType.ToString(); // Set cookie information incase they made it persistant System.Web.HttpCookie wrapperCookie = new System.Web.HttpCookie("wrapper"); wrapperCookie.Value = objSession["wrapper"].ToString(); wrapperCookie.Expires = DateTime.Now.AddDays(30); System.Web.HttpCookie lgnTypeCookie = new System.Web.HttpCookie("loginType"); lgnTypeCookie.Value = objSession["loginType"].ToString(); lgnTypeCookie.Expires = DateTime.Now.AddDays(30); // Add the cookie to the response objResponse.Cookies.Add(wrapperCookie); objResponse.Cookies.Add(lgnTypeCookie); return "/candidate/default.aspx"; } case 1: // Admin Login { return "/admin/default.aspx"; } case 2: // Reporting Login { return "/reports/default.aspx"; } default: { return string.Empty; } } } else { return string.Empty; } } /// <summary> /// Verifies the login and password that were given /// </summary> /// <param name="email">the login</param> /// <param name="password">the password</param> /// <param name="nLoginID">returns the login id</param> /// <param name="nLoginType">returns the login type</param> public void Login(string email, string password, ref int nLoginID, ref int nLoginType) { ResetSql(); DataSet ds = new DataSet(); // Set our parameters SqlParameter paramLogin = new SqlParameter("@username", SqlDbType.VarChar, 100); paramLogin.Value = email; SqlParameter paramPassword = new SqlParameter("@password", SqlDbType.VarChar, 20); paramPassword.Value = password; Command.CommandType = CommandType.StoredProcedure; Command.CommandText = "glbl_Login"; Command.Parameters.Add(paramLogin); Command.Parameters.Add(paramPassword); Adapter.TableMappings.Add("Table", "Login"); Adapter.SelectCommand = Command; Adapter.Fill(ds); if(ds.Tables.Count != 0) { DataRow row = ds.Tables[0].Rows[0]; // Get the login id and the login type nLoginID = Convert.ToInt32(row["Login_ID"].ToString()); nLoginType = Convert.ToInt32(row["Login_Type"].ToString()); } else { nLoginID = 0; nLoginType = 0; } } } abstract public class CSql { private SqlConnection sqlConnection; // Connection string private SqlCommand sqlCommand; // Command private SqlDataAdapter sqlDataAdapter; // Data Adapter private DataSet sqlDataSet; // Data Set public CSql() { sqlConnection = new SqlConnection(ConfigurationSettings.AppSettings ["ConnectionString"]); sqlCommand = new SqlCommand(); sqlDataAdapter = new SqlDataAdapter(); sqlDataSet = new DataSet(); sqlCommand.Connection = sqlConnection; } /// <summary> /// Access to our sql command /// </summary> protected SqlCommand Command { get { return sqlCommand; } } /// <summary> /// Access to our data adapter /// </summary> protected SqlDataAdapter Adapter { get { return sqlDataAdapter; } } /// <summary> /// Makes sure that everything is clear and ready for a new query /// </summary> protected void ResetSql() { if(sqlCommand != null) { sqlCommand = new SqlCommand(); sqlCommand.Connection = sqlConnection; } if(sqlDataAdapter != null) sqlDataAdapter = new SqlDataAdapter(); if(sqlDataSet != null) sqlDataSet = new DataSet(); } /// <summary> /// Runs our command and returns the dataset /// </summary> /// <returns>the data set</returns> protected DataSet RunQuery() { sqlDataAdapter.SelectCommand = Command; sqlConnection.Open(); sqlConnection.Close(); sqlDataAdapter.Fill(sqlDataSet); return sqlDataSet; } } } |
新聞熱點
疑難解答
圖片精選