Can you explain Forms authentication in detail?

 Posted by ArticlesMaint on 9/16/2009 | Category: ASP.NET Interview questions | Views: 4413

Answer: -
In old ASP if you where said to create a login page and do authentication you have to do hell lot of custom coding. Now in ASP.NET that has made easy by introducing Forms authentication. So let us see in detail what form authentication is.
Forms authentication uses a ticket cookie to see that user is authenticated or not. That means when user is authenticated first time a cookie is set to tell that this user is authenticated. If the cookies expire then Forms authentication mechanism sends the user to the login page.

Following are the steps, which defines steps for Forms authentication:-

• Configure Web.config file with forms authentication. As shown below in the config file you can see we have give the cookie name and loginurl page.

<!-- Other settings omitted. -->
<authentication mode="Forms">
<forms name="logincookies"
path="/" />

• Remove anonymous access to the IIS web application, following are changes done to web.config file.

<!-- Other settings omitted. -->
<deny users="?" />

• Create the login page, which will accept user information. You will have create your login page that is the Login.aspx, which will actually take the user data.

• Finally a small coding in the login button.
Let us assume that the login page has two textboxes TX name and txtapssword.
Also, import System.Web.Security and put the following code in login button of the page.

If Page.IsValid Then
If FormsAuthentication.Authenticate(txtName.Text, txtPassword.Text) Then
FormsAuthentication.RedirectFromLoginPage(txtName.Text, False)
lblStatus.Text = "Error not proper user"
End If
End If

Asked In: Many Interviews | Alert Moderator 

Comments or Responses

Login to post response