At our company network, the roles in Active Directory(AD) are not appropriately assigned for my application. So I created a simple table in my database mapping all the users in the AD and their roles. There is literally only two columns in this table, user and role.
I hope to take advantage of the powerful role management in asp.net, I want to use features like [Authorize(Roles = "Managers")]
. is there a simple way to use these custom roles without setting up complicated role and membership provider?
application background: sql server, linq, asp.net mvc
It is really easy to implement custom role provider. Basically you will need to implement two functions.
Look at the article: Custom Role Provider for MVC
Article provided in the event the website goes down.
Custom Role Provider for MVC
In a previous article, I explain how to create Custom Membership Provider to authorize the user and protect controls and pages. But what if you want to show or protect some area, controller or page for a specific group of users? For example, allow access to Admin Panel only for admins.
In .Net Framework for this purpose is Role Provider. But again, it uses own DB for store user roles. So let's create and configure Custom Role Provider which will use our DB or any other storage. As before we should overwrite class from .NET:
For the minimum functionality, we need implement and overwrite two functions GetRolesForUser and IsUserInRole. First, one is used to get a list of all user roles (or groups):
As you can see I locate the user in my DB by username parameter of the function (in my case it’s can be username or email) and create the string list of user roles.
Second function is to check if user in the role (or group):
Then we need to configure in web.config file solution to use created role provider. May need to set
cacheRolesInCookie
to false for debugging purposes or behavior will be unpredictable.Now you can protect controllers, actions, pages for a specific group of users which are in specified roles by set Authorize attribute: