asp.net.ph

UrlAuthorizationModule Class

System.Web.Security Namespace


Provides URL-based authorization services for allowing or denying access to specified resources. This class cannot be inherited.

UrlAuthorizationModule Class Members

Collapse   Constructors

Visibility Constructor Parameters
public UrlAuthorizationModule ( )

Collapse   Methods

Visibility Name Parameters Return Type
public static CheckUrlAccessForPrincipal ( String virtualPath , IPrincipal user , String verb ) Boolean
public Dispose ( ) Void
public Init ( HttpApplication app ) Void

Remarks

The UrlAuthorizationModule determines whether the current user is permitted access to the requested URL, based on the user Name or the list of roles that a user is a member of. For information about how the user name is determined, see ASP.NET Authentication. For information about how to manage user roles, see Managing Authorization Using Roles.

Authorization for a user or a role is managed using the authorization configuration element. You can allow or deny a user or a role using the allow or deny subelements, respectively. The allow and deny subelements are interpreted in the order they appear in the configuration. Once an element specifies that access is allowed or denied, the UrlAuthorizationModule completes its authorization check. For example, the following authorization section from a Web.config file requires users to log on ( by denying anonymous users ), and then allows only users in the Administrators role to have access. Users not in the Administrators role are denied.

<authorization>
   <deny users = "?" />
   <allow roles = "Administrators" />
   <deny users = "*" />
</authorization>

A user or role must be specifically denied to refuse the user or role permission to a URL. That is, if the previous example had not specified the <deny users = "*" /> element, then all authenticated users would have been allowed access to the requested URL, regardless of what role they were a member of.

See Also

FileAuthorizationModule Class   ASP.NET Authorization Skip Navigation Links




Home
Suggested Reading


Previous page Back to top Next page

© 2000-2010 Rey Nuñez All rights reserved.

If you have any question, comment or suggestion
about this site, please send us a note

You can help support asp.net.ph