ASP.NET MVC - 自动注销

时间:2016-05-09 14:25:27

标签: c# asp.net-mvc

在我的应用程序中,我希望在一段时间不活动后关闭用户。用户使用他们的Google帐户登录。

Web.config文件中,我将<sessionState mode="InProc" timeout="10" />置于<system.web>下,但是在10分钟后,该用户未被注销。

我希望自动注销的另一件事是在完成注销之前执行一段代码。此代码只是更新数据库表中的字段。我不想使用JavaScript,因为如果用户离开网站,我希望自动注销能够正常工作。

修改

@Igor

要求的Startup.Auth.cs内的代码
using System;
using Microsoft.AspNet.Identity;
using Microsoft.AspNet.Identity.Owin;
using Microsoft.Owin;
using Microsoft.Owin.Security.Cookies;
using Microsoft.Owin.Security.Google;
using Owin;
using StudentLive.Models;

namespace StudentLive
{
    public partial class Startup
    {
        // For more information on configuring authentication, please visit http://go.microsoft.com/fwlink/?LinkId=301864
        public void ConfigureAuth(IAppBuilder app)
        {
            // Configure the db context, user manager and signin manager to use a single instance per request
            app.CreatePerOwinContext(ApplicationDbContext.Create);
            app.CreatePerOwinContext<ApplicationUserManager>(ApplicationUserManager.Create);
            app.CreatePerOwinContext<ApplicationSignInManager>(ApplicationSignInManager.Create);

            // Enable the application to use a cookie to store information for the signed in user
            // and to use a cookie to temporarily store information about a user logging in with a third party login provider
            // Configure the sign in cookie
            app.UseCookieAuthentication(new CookieAuthenticationOptions
            {
                AuthenticationType = DefaultAuthenticationTypes.ApplicationCookie,
                LoginPath = new PathString("/Account/Login"),
                Provider = new CookieAuthenticationProvider
                {
                    // Enables the application to validate the security stamp when the user logs in.
                    // This is a security feature which is used when you change a password or add an external login to your account.  
                    OnValidateIdentity = SecurityStampValidator.OnValidateIdentity<ApplicationUserManager, ApplicationUser>(
                        validateInterval: TimeSpan.FromMinutes(30),
                        regenerateIdentity: (manager, user) => user.GenerateUserIdentityAsync(manager))
                }
            });            
            app.UseExternalSignInCookie(DefaultAuthenticationTypes.ExternalCookie);

            // Enables the application to temporarily store user information when they are verifying the second factor in the two-factor authentication process.
            app.UseTwoFactorSignInCookie(DefaultAuthenticationTypes.TwoFactorCookie, TimeSpan.FromMinutes(5));

            // Enables the application to remember the second login verification factor such as phone or email.
            // Once you check this option, your second step of verification during the login process will be remembered on the device where you logged in from.
            // This is similar to the RememberMe option when you log in.
            app.UseTwoFactorRememberBrowserCookie(DefaultAuthenticationTypes.TwoFactorRememberBrowserCookie);

            // Uncomment the following lines to enable logging in with third party login providers
            //app.UseMicrosoftAccountAuthentication(
            //    clientId: "",
            //    clientSecret: "");

            //app.UseTwitterAuthentication(
            //   consumerKey: "",
            //   consumerSecret: "");

            //app.UseFacebookAuthentication(
            //   appId: "",
            //   appSecret: "");

            app.UseGoogleAuthentication(new GoogleOAuth2AuthenticationOptions()
            {
                ClientId = "XXXXXXXXXXXXXXXXXXXXXXXXXXXX",
                ClientSecret = "XXXXXXXXXXXXXXXXXXXX"
            });
        }
    }
}

1 个答案:

答案 0 :(得分:6)

您需要修改CookieAuthenticationOptions实例,并提供有关到期的其他详细信息。

来自文档

  
      
  • SlidingExpiration - SlidingExpiration设置为true,以指示中间件在处理到期时间超过到期时间的请求时,以新的到期时间重新发布新Cookie。
  •   
  • ExpireTimeSpan - 控制Cookie从创建点开始保持有效的时间。到期信息位于受保护的cookie票证中。因此,即使在浏览器已清除它之后将其传递给服务器,也会忽略过期的cookie。
  •   

代码:

app.UseCookieAuthentication(new CookieAuthenticationOptions
{
    // add these lines
    SlidingExpiration = true,
    ExpireTimeSpan = TimeSpan.FromMinutes(10),
    // rest of your code
}