ASP.NET 2.0 All-In-One Desk Reference For Dummies®
by Doug Lowe, Jeff Cogswell, Ken Cox - Microsoft MVP
Chapter 1. Security: Using Login Controls
In This Chapter
✓ | Understanding authentication and authorization |
✓ | Using the Security Administration tool |
✓ | Restricting access |
✓ | Handling logins and lost passwords |
✓ | Managing users and roles programmatically |
Most of us feel uneasy about implementing Web site security, perhaps because it’s hard to be 100% sure that you’ve got it right. Inadvertently allowing the Internet’s bad guys to get in could be a Career Limiting Move (CLM) or worse. Therefore, it’s comforting to put security in the hands of people who’ve done it before. Enter Microsoft’s ASP.NET team. The team realized that so many of us were reinventing the security wheel (sometimes creating an oval wheel, out of whack) that it made sense to build membership and login capabilities directly into ASP.NET 2.0.
Out of the box, we have all the tools we need to let people log in to the site, view what we allow them to view, and recover their lost passwords. Our goal in this chapter is to implement security while writing as little code as possible. We can do this by leveraging the standard authorization tools and functions in ASP.NET.

As you work with membership terminology, note that roles refer to groups or categories of users. In addition, the terms users and members are interchangeable.
Understanding Authentication and Authorization
Authentication and authorization are easy to confuse. It might help to ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access