Showing posts with label MVC. Show all posts
Showing posts with label MVC. Show all posts

Session Authoraization in MVC

If you are using Session Authorization in your MVC Application then you need to check the existence of the session in each controller method.
In order to avoid this, you can make your own attribute that inherits from AuthorizeAttribute, and by overriding AuthorizeCore and HandleUnauthorizedRequest methods. You can place this attribute on the needed controllers.

Following is the code for the Custom Attribute to check the session

AuthorizeSessionAttribute.cs
public class AuthorizeSessionAttribute : AuthorizeAttribute
{
    protected override bool AuthorizeCore(HttpContextBase httpContext)
    {
        return httpContext.Session["UserID"] != null;
    }

    protected override void HandleUnauthorizedRequest(AuthorizationContext 

filterContext)
    {
        filterContext.Result = new RedirectResult("/account/login");
    }
}
Usage:

In a controller method
public class SomeController : Controller
{
    [AuthorizeSession]
    public ActionResult Index()
    {
    }
}
In a controller
[AuthorizeSession]
public class SomeController : Controller
{
    public ActionResult Index()
    {
    }
}
Here it will applies to all the methods in the controller.
If you want a single method need to by pass this session Authorization then you need to put the [AllowAnonymous] attribute to that method as below
[AuthorizeSession]
public class SomeController : Controller
{
    public ActionResult Index()
    {
    }

    [AllowAnonymouse]
    public ActionResut publicpage()
    {
    }
}

Change Model's value in View on Postback

In MVC, if you change any value of the model in the postback action, it won't reflect in the View when it is redisplayed. It is because of the design of the HTML Helpers.

For example, if you have a view like below


<% using (Html.BeginForm()) { %>
    <%= Html.TextBoxFor(m => m.FirstName) %>

    <%= Html.TextBoxFor(m => m.LastName) %>
    <input type="submit" value="OK" />
<% } %>


which you are posting to the following action:

[HttpPost]
public ActionResult Sample(SampleModel model)
{
    model.FirstName = "Krish";
    model.LastName = "S";
    return View(model);
}

Here the 'FirstName' Property of the model is changed in the Action. But, when the view is redisplayed the old value will be used.

To avoid this remove the value from the 'ModelState'.So it will rebuild the control agin in the view with new data.

[HttpPost]
public ActionResult Sample(SampleModel model)
{
    ModelState.Remove("FirstName");
    ModelState.Remove("LastName");
    model.FirstName = "Krish";
    model.LastName = "S";
    return View(model);
}

Conditionally disable a Control in ASP.NET MVC

In MVC, you can disable a control based on some property from the model using the following

<%: Html.TextBoxFor(m => m.date2,Model.VoiceMessage? null: new { @disabled = true })%>


Here, I am disabling the textbox based on the "VoiceMessage" field. It adds the "disabled" attribute, if "VoiceMessage" value is false.
If any other attributes are present then you can write like  below

<%: Html.TextBoxFor(m => m.date2, Model.VoiceMessage?(object) new { @id = "textbox1" } : (object)new { @id = "textbox1",@disabled=true })%>