J'ai fait quelque chose comme ça :
- Utilisez le fichier Global.asax.cs pour charger les rôles que vous souhaitez comparer dans l'état de la session, du cache ou de l'application, ou chargez-les à la volée dans le contrôleur ValidateUser.
Attribuez l'attribut [Authorize] à vos contrôleurs, vous voulez exiger l'autorisation pour les éléments suivants
[Authorize(Roles = "Admin,Tech")]
ou pour autoriser l'accès, par exemple les contrôleurs Login et ValidateUser utilisent l'attribut suivant
Mon formulaire de connexion
<form id="formLogin" name="formLogin" method="post" action="ValidateUser">
<label for="txtUserName">Username: (AD username) </label>
<input id="txtUserName" name="txtUserName" role="textbox" type="text" />
<label for="txtPassword">Password: </label>
<input id="txtPassword" name="txtPassword" role="textbox" type="password" />
<input id="btnLogin" type="submit" value="LogIn" class="formbutton" />
@Html.Raw("<span id='lblLoginError'>" + @errMessage + "</span>")
Contrôleur de connexion et contrôleur ValidateUser invoqués depuis le post du formulaire
La validation de l'utilisateur est une authentification via un service WCF qui valide contre le contexte Windows AD local au service, mais vous pouvez changer cela pour votre propre mécanisme d'authentification.
using System;
using System.Collections.Generic;
using System.Linq;
using System.Web;
using System.Web.Mvc;
using System.Web.Security;
using System.Security.Principal;
using MyMVCProject.Extensions;
namespace MyMVCProject.Controllers
public class SecurityController : Controller
public ActionResult Login(string returnUrl)
Session["LoginReturnURL"] = returnUrl;
Session["PageName"] = "Login";
return View("Login");
public ActionResult ValidateUser()
Session["PageName"] = "Login";
ViewResult retVal = null;
string loginError = string.Empty;
HttpContext.User = null;
var adClient = HttpContext.Application.GetApplicationStateWCFServiceProxyBase.ServiceProxyBase<UserOperationsReference.IUserOperations>>("ADService").Channel;
var username = Request.Form["txtUserName"];
var password = Request.Form["txtPassword"];
//check for ad domain name prefix
if (username.Contains(@"\"))
username = username.Split('\\')[1];
//check for the existence of the account
var acctReq = new UserOperationsReference.DoesAccountExistRequest();
acctReq.userName = username;
//account existence result
var accountExist = adClient.DoesAccountExist(acctReq);
if (!accountExist.DoesAccountExistResult)
//no account; inform the user
return View("Login", new object[] { "NO_ACCOUNT", accountExist.errorMessage });
var authReq = new UserOperationsReference.AuthenticateRequest();
authReq.userName = username;
authReq.passWord = password;
var authResponse = adClient.Authenticate(authReq);
String verifiedRoles = string.Empty;
//check to make sure the login was as success against the ad service endpoint
if (authResponse.AuthenticateResult == UserOperationsReference.DirectoryServicesEnumsUserProperties.SUCCESS)
Dictionary<string, string[]> siteRoles = null;
//get the role types and roles
if (HttpContext.Application["UISiteRoles"] != null)
siteRoles = HttpContext.Application.GetApplicationState<Dictionary<string, string[]>>("UISiteRoles");
string groupResponseError = string.Empty;
if (siteRoles != null && siteRoles.Count > 0)
//get the user roles from the AD service
var groupsReq = new UserOperationsReference.GetUsersGroupsRequest();
groupsReq.userName = username;
//execute the service method for getting the roles/groups
var groupsResponse = adClient.GetUsersGroups(groupsReq);
//retrieve the results
if (groupsResponse != null)
groupResponseError = groupsResponse.errorMessage;
var adRoles = groupsResponse.GetUsersGroupsResult;
if (adRoles != null)
//loop through the roles returned from the server
foreach (var adRole in adRoles)
//look for an admin role first
foreach (var roleName in siteRoles.Keys)
var roles = siteRoles[roleName].ToList();
foreach (var role in roles)
if (adRole.Equals(role, StringComparison.InvariantCultureIgnoreCase))
//we found a role, stop looking
verifiedRoles += roleName + ";";
if (String.IsNullOrEmpty(verifiedRoles))
//no valid role we need to inform the user
return View("Login", new object[] { "NO_ACCESS_ROLE", groupResponseError });
if (verifiedRoles.EndsWith(";"))
verifiedRoles = verifiedRoles.Remove(verifiedRoles.Length - 1, 1);
//all is authenticated not build the auth ticket
var authTicket = new FormsAuthenticationTicket(
1, // version
username, // user name
DateTime.Now, // created
DateTime.Now.AddMinutes(20), // expires
true, // persistent?
verifiedRoles // can be used to store roles
//encrypt the ticket before adding it to the http response
string encryptedTicket = FormsAuthentication.Encrypt(authTicket);
var authCookie = new HttpCookie(FormsAuthentication.FormsCookieName, encryptedTicket);
Session["UserRoles"] = verifiedRoles.Split(';');
//redirect to calling page
retVal = View("Login", new object[] { authResponse.AuthenticateResult.ToString(), authResponse.errorMessage });
return retVal;
L'utilisateur est authentifié, créez maintenant la nouvelle identité
protected void FormsAuthentication_OnAuthenticate(Object sender, FormsAuthenticationEventArgs e)
if (FormsAuthentication.CookiesSupported == true)
HttpCookie authCookie = Context.Request.Cookies[FormsAuthentication.FormsCookieName];
if (authCookie == null || authCookie.Value == "")
FormsAuthenticationTicket authTicket = null;
authTicket = FormsAuthentication.Decrypt(authCookie.Value);
// retrieve roles from UserData
if (authTicket.UserData == null)
//get username from ticket
string username = authTicket.Name;
Context.User = new GenericPrincipal(
new System.Security.Principal.GenericIdentity(username, "MyCustomAuthTypeName"), authTicket.UserData.Split(';'));
Sur mon site, en haut de mon _Layout.cshtml, j'ai quelque chose comme ceci
bool authedUser = false;
if (User != null && User.Identity.AuthenticationType == "MyCustomAuthTypeName" && User.Identity.IsAuthenticated)
authedUser = true;
Puis dans le corps
if (authedUser)
<span id="loggedIn_userName">
<label>User Logged In: </label>@User.Identity.Name.ToUpper()
<span id="loggedIn_userName_none">
<label>No User Logged In</label>