Configures the user's credentials for Web applications that use forms-based authentication.
Assembly: System.Web (in System.Web.dll)
The class provides a way to programmatically access and modify the user section of a configuration file.
This type is part of a group that includes the FormsAuthenticationCredentials, the FormsAuthenticationUserCollection, and the FormsAuthenticationConfiguration types. The types other than the collection type directly affect the underlying configuration tags.
The can write information into the related section of the configuration file at machine, site, or application level only. Any attempt to write in a configuration file at a different level in the hierarchy will result in an error message generated by the parser. However, you can use this class to read configuration information at any level in the hierarchy. For safety and scalability, it is recommended that you use an external repository, such as a database, to keep the users' credentials.
The following code example shows how to obtain the FormsAuthenticationUserCollection to access the objects of an existing Web application. The configuration file will contain a setup similar to the following.
If you use the credentials Element for forms for authentication (ASP.NET Settings Schema) section, be sure to follow the guidelines explained at ASP.NET Authentication. For scalability and better security, it is recommended you use an external database to store the users' credentials. For more information about building secure ASP.NET applications, search the Microsoft MSDN Web site (msdn.microsoft.com) for "Securing Your ASP.NET Application" and "Building Secure ASP.NET Applications: Authentication, Authorization, and Secure Communication."
<authentication mode="Forms"> <forms name="MyAppCookieName" loginUrl="/login.aspx"> defaultUrl="formsdefault.aspx" protection="Encryption" timeout="5" path="aspnet" slidingExpiration="false" cookieless="UseCookies" domain="domainName"> <credentials passwordFormat="SHA1"> <user name="aspnetuser1" password="5BAA61E4C9B93F3F0682250B6CF8331B7EE68FD8"/> <user name="aspnetuser2" password="E38AD214943DAAD1D64C102FAEC29DE4AFE9DA3D"/> </credentials> </forms> </authentication>
// Get the Web application configuration. System.Configuration.Configuration configuration = WebConfigurationManager.OpenWebConfiguration( "/aspnet"); // Get the section. AuthenticationSection authenticationSection = (AuthenticationSection)configuration.GetSection( "system.web/authentication"); // Get the users collection. FormsAuthenticationUserCollection formsAuthenticationUsers = authenticationSection.Forms.Credentials.Users;
Windows 7, Windows Vista, Windows XP SP2, Windows XP Media Center Edition, Windows XP Professional x64 Edition, Windows XP Starter Edition, Windows Server 2008 R2, Windows Server 2008, Windows Server 2003, Windows Server 2000 SP4, Windows Millennium Edition, Windows 98
The .NET Framework and .NET Compact Framework do not support all versions of every platform. For a list of the supported versions, see .NET Framework System Requirements.