【发布时间】:2014-11-10 12:22:09
【问题描述】:
我们公司有 SSO 站点,如果用户未通过身份验证,我们所有的应用程序都会在该站点中被重定向。 SSO 站点使用表单身份验证对用户进行身份验证。它适用于所有应用程序。(ASP.NET 应用程序)
现在我们有了使用 VS 2013 创建的新 MVC5 应用程序。我正在尝试使用表单身份验证。如果用户未通过身份验证,我想将用户重定向到登录网址(SSO 站点)。下面是我的代码。但是当我调试时,用户总是经过身份验证。 IsAutheticated 属性为 true,AuthenticationType 为“Negotiate”,Identity 为“Windows”(即使在配置文件中为“Forms”)
(请注意,如果这有所不同,我正在使用 IIS express 在 VS 中进行调试。它也是 MVC 5 应用程序,是不是因为 OWIN。我怎么知道?)
<system.web>
<compilation debug="true" targetFramework="4.5" />
<authentication mode="Forms" >
<forms loginUrl="/Account/Login"></forms>
</authentication>
<authorization>
<deny users="?" />
</authorization>
public class AccountController : Controller
{
public ActionResult Login()
{
string loginUrl = AppSettings.Authentication.LoginUrl;
string failOverUrl = AppSettings.Authentication.FailoverLoginUrl;
string securityGroup = AppSettings.Authentication.SecurityGroup;
if (!User.Identity.IsAuthenticated) // IsAutheticated is always true, why?
{
var returnUrl = "someresturnurl";
MyAuthenticator.Authenticate(loginUrl, failOverUrl, returnUrl, securityGroup);
}
else
{
// Redirect the user if they are already authenticated.
return RedirectToAction("Index", "Home");
}
}
}
【问题讨论】:
标签: authentication asp.net-mvc-5 owin