【问题标题】:Storing "remember me" information locally c# (total newbeginner)在本地存储“记住我”信息 c# (total newbeginner)
【发布时间】:2012-02-05 19:34:28
【问题描述】:

几天前我开始使用 c# 编程,所以我是这方面的新手。根据我在其他语言方面的经验,我发现它有些“简单”。

我正在构建一个用户登录我的应用程序的系统,该系统正在运行。我想要一个“记住我”的设置,将信息存储在本地。做这个的最好方式是什么?我只会保存用户名和密码哈希。

编辑:这是一个桌面应用程序。只需使用HttpWebRequest 将登录信息发送到 php 脚本

【问题讨论】:

  • 不确定这意味着什么...我正在使用带有 Win7 的 Visual Studio 2010。信息被提交到一个 php 文件
  • 如何“提交”信息?
  • 这是一个网络或桌面应用程序? PHP 文件将哪些信息提交到何处?你系统的哪个部分是 PHP 的,哪个是 C# 的?
  • @Shai :可能不是最好的方法,但我只是使用 HttpWebRequest 并使用 GET 发送信息
  • @djacobson :这是桌面。数据库是 mysql,我用 PHP 制作了一个简单的框架,应用程序连接到该框架。

标签: c# winforms login store


【解决方案1】:

如果您使用的是 ASP .NET,您可以在登录用户时通过第二个参数设置身份验证 cookie

FormsAuthentication.SetAuthCookie(model.UserName, true);

第二个参数为您的请求设置 cookie 并设置“记住我”选项。

【讨论】:

  • 这适用于桌面应用程序吗?我对我的申请有点不清楚。
【解决方案2】:

您可以在 C# 中创建应用程序设置

here's what you will do.

别忘了加密。

【讨论】:

    【解决方案3】:

    您可以使用ConfigurationManager 类来管理应用程序的设置。

    您可以使用此功能将新密钥添加到您的配置文件中:

    public bool setSetting(string pstrKey, string pstrValue)
    {
        Configuration objConfigFile =
            ConfigurationManager.OpenExeConfiguration(ConfigurationUserLevel.None);
        bool blnKeyExists = false;
    
        foreach (string strKey in objConfigFile.AppSettings.Settings.AllKeys)
        {
            if (strKey == pstrKey)
            {
                blnKeyExists = true;
                objConfigFile.AppSettings.Settings[pstrKey].Value = pstrValue;
                break;
            }
        }
        if (!blnKeyExists)
        {
            objConfigFile.AppSettings.Settings.Add(pstrKey, pstrValue);
        }
        objConfigFile.Save(ConfigurationSaveMode.Modified);
        ConfigurationManager.RefreshSection("appSettings");
        return true;
    }
    

    然后保存您的用户名(例如)

    setSetting("username", usernameTextBox.Text);
    

    一旦您的应用程序启动,您就可以从您的ConfigurationManager 中读取您之前保存的信息

    usernameTextBox.Text = ConfigurationManager.AppSettings["username"];
    

    【讨论】:

    • 注意:显然,不要使用用户的密码进行此操作。通常,您会从网站收到一个令牌并将其存储起来。尽管从安全角度来看,这仍然是一个狡猾的领域。
    • @NeilBarnwell :我在存储密码之前对密码进行哈希处理是什么?安全性在应用程序中并不是一个大问题。它更像是一个噱头,因为我想学习它。但是令牌也可以工作:)
    • 问题是,无论你是否散列它,有人可以窃取整个文件并将其原样复制到他们自己的机器上,以假装他们是其他人。您可以通过使用从环境中获取的东西对散列值进行加盐来消除这种情况。这基本上与浏览器 cookie 可能遇到的问题相同,所以我想研究浏览器如何解决这些问题值得一看。
    【解决方案4】:

    我从您的问题中了解到,php 文件是服务器,而对于客户端,您使用的是 windows 窗体。您正在执行某种 HTML 报废并在您的 win-form 中显示结果 HTML。如果这是你正在做的,那么

    //1. Create a dictionary to store cookie collection
    
        public static Dictionary<string, Cookie> CookieCollection { get; set; }
    
    //2. Store cookie in that collection
    
    
    foreach (Cookie clientcookie in response.Cookies)
         {
                        if (!CookieCollection.ContainsKey("AuthCookieName"))
                            CookieCollection .Add(userName, clientcookie);
                        else
                            CookieCollection ["userName"] = clientcookie;
        }
    
    //3. If remember me is clicked then send the same while creating request
    
        request.CookieContainer.Add(request.RequestUri, 
    new Cookie("AuthCookieName", CookieCollection ["userName"]));
    

    其中 AuthCookieName 是身份验证 cookie 的名称。唯一的缺点是当应用程序存在时,存储在字典中的所有 cookie 都会消失。解决方案可能是序列化 cookie 并将其存储在数据库中,如果记住我被选中。

    【讨论】:

      猜你喜欢
      • 2014-08-01
      • 1970-01-01
      • 2013-12-16
      • 2015-06-08
      • 1970-01-01
      • 2014-05-05
      • 1970-01-01
      • 1970-01-01
      • 2020-07-11
      相关资源
      最近更新 更多