asp.net mvc authorization using roles

前端 未结 5 1870
别那么骄傲
别那么骄傲 2020-12-07 15:11

I\'m creating an asp.net mvc application that has the concept of users. Each user is able to edit their own profile. For instance:

  • PersonID=1 can edit thei
5条回答
  •  广开言路
    2020-12-07 15:46

    Maybe you could organize the controller action such that the URL is more like http://localhost/person/editme and it displays the edit form for the currently-logged-in user. That way there's no way a user could hack the URL to edit someone else.

提交回复
热议问题