【问题标题】:Logout issue with browser back button浏览器后退按钮的注销问题
【发布时间】:2013-01-20 13:34:23
【问题描述】:

我使用 ASP.Net MVC 4 创建了登录/注销功能。我使用自己创建的表单针对 Active Directory 对用户进行身份验证。它在功能上运行良好。

在安全方面仍然存在一个大问题。用户单击注销链接后,他/她成功注销并再次重定向到登录表单。控制器中的代码如下所示。

    public ActionResult Logout()
    {
        // Tried to include below 3 lines in _Layout.cshtml as well. But not identifying.
        Response.Cache.SetExpires(DateTime.UtcNow.AddMinutes(-1));
        Response.Cache.SetCacheability(System.Web.HttpCacheability.NoCache);
        Response.Cache.SetNoStore();            

        Session.Abandon();              

        return RedirectToAction("Login");
    }

但是,一旦单击浏览器后退按钮,用户就可以返回到其他页面并浏览页面。

我尝试了几种解决方案,不同的方法,但都没有奏效。似乎 MVC 方法与 ASP.NET 表单有很大不同。感谢您在这方面的帮助。

(我希望使用 C#/MVC 方式解决此问题。不使用 JavaScript 来禁用/关闭注销时的浏览器。)

更新:代码片段

    [HttpPost]
    public ActionResult Login(LoginModel authUser)
    {
        // Call Helper to get LDAP info. Will return username with groups or null      
        UserModel userProfile = LdapLoginHelper.AuthenticateUser(authUser);

        if (userProfile != null)
        {                
            Session["UserName"] = userProfile.UserName;
            Session["LdapGroups"] = userProfile.LdapGroups;

            if (userProfile.LdapGroups.Contains("Administrators"))
            {
                // To be implemented                   
            }
            else
            {
                // To be implemented      
            }

            // Successful login. Redirect to main page
            return RedirectToAction("Home", "Home");
        }
        else
        {
            // Invalid Login. Redirect to Login page
            return RedirectToAction("Login");
        }            
    }



    public ActionResult Logout()
    {
        // Not worked
        Response.Cache.SetExpires(DateTime.UtcNow.AddMinutes(-1));
        Response.Cache.SetCacheability(System.Web.HttpCacheability.NoCache);
        Response.Cache.SetNoStore();
        Session.Abandon();

        /// Tried this too. Not worked.
        /// Session.Clear();
        /// FormsAuthentication.SignOut();

        //// Tried this also. Not worked.
        //// WebSecurity.Logout();

        return RedirectToAction("Login");
    }

除了这个常见的 _Layout.cshtml 页面标题如下所示。

<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="utf-8" />
<meta http-equiv="Pragma" content="no-cache">
<meta http-equiv="Expires" content="-1">
<meta http-equiv="CACHE-CONTROL" content="NO-CACHE">
.
. 
.

【问题讨论】:

  • 您是否使用 [Authorize] 属性装饰了您的控制器/操作?身份验证信息如何持久化?通常你有会话和用于身份验证的 cookie。您确定您的用户在您的 Logout() 操作后不再经过身份验证吗?
  • 我仍在为授权编写自定义属性。用户登录后,用户名将分配给会话变量。
  • 你能告诉我们你的登录方法是什么样的吗?关于您为什么不想使用 ASP.NET 内置授权/身份验证功能的几句话也会有所帮助
  • 将使用登录、注销代码 sn-ps 进行更新。由于客户的请求,没有使用 ASP.NET 内置的授权/身份验证功能,他们将使用 Active Directory。
  • 试试这里的解决方案怎么样:stackoverflow.com/questions/16337149/…

标签: c# authentication asp.net-mvc-4


【解决方案1】:

在您的 global.asax 页面中添加以下代码并从您的 logout() 函数中删除前 3 行。

protected void Application_BeginRequest()
{
    Response.Cache.SetCacheability(HttpCacheability.NoCache);
    Response.Cache.SetExpires(DateTime.UtcNow.AddHours(-1));
    Response.Cache.SetNoStore();
}

【讨论】:

    【解决方案2】:

    我只将 SetExpires 与 DateTime.Now 一起使用,这将使您的本地服务器时间与 cookie 相匹配。使用 DateTime.UtcNow.Addminutes(-1) 可能是真正的罪魁祸首。

    另外,如果您使用表单身份验证,我看不到您对

    的调用
    FormsAuthentication.SignOut();
    

    【讨论】:

    • 这正是我要推荐的。事实上......我认为默认的 mvc 模板会生成一个带有登录/注销逻辑的帐户控制器,因此应该能够将其用作参考点。
    • Mvc4 在模板中做 OpenAuth。好像 Facebook 是您的默认提供商一样。如果使用该模板,这是您首先要做的事情之一。这个问题意味着 openauth 被踢出表单。
    • @MichaelViktorStarberg 不确定我是否理解您的评论,但 MVC4 模板具有 OpenAuth 和 WebSecurity 以及 SimpleMembership,它取代了现有的 ASP.NET 角色和成员资格,因此您没有对 Facebook 的身份验证。好读:weblogs.asp.net/jgalloway/archive/2012/08/29/…
    • 尝试使用 FormsAuthentication.SignOut();也是,但后退按钮场景仍然存在。将使用代码更新问题。客户的请求是使用AD/LDAP进行基于组的身份验证。
    • 你试过不使用 UtcNow 吗?
    【解决方案3】:

    将以下属性添加到在控制器中返回安全页面的任何 ActionResult 方法应该可以工作:

    public class MyControllerForAuthorizedStuff
    {
        [OutputCache(NoStore = true, Duration = 0, Location = OutputCacheLocation.None)]
        public ActionResult Index()
        {
            return View();
        }
    } 
    

    【讨论】:

      猜你喜欢
      • 2022-01-09
      • 2015-04-21
      • 1970-01-01
      • 2012-07-09
      • 1970-01-01
      • 1970-01-01
      • 2017-01-18
      • 2013-12-26
      • 1970-01-01
      相关资源
      最近更新 更多