AspNet Identity MVC - How to catch Signed In Event

Viewed 2015

I am using ASPNet Identity 2.0 (Full framework, not the core framework) and MVC. I would like to execute C# code once the user successfully login to the site.

i know that i can write some code right after the SignInManager.PasswordSignInAsync command and it will work for new login but not will not work for users who used "remember me" feature and returned to the site later (Cookie authentication).

I am looking for an option to catch the event of all the users who signed in to the site either by entering the password and by using the "remember me" cookie.

3 Answers

What you're after is FormsAuthentication_OnAuthenticate (I appreciate Forms-based authentication was not mentioned in the question, but it's an example of Cookie-based remember me authentication, adapt at will)

Unfortunately, there is no trigger for OnCookieBasedFormsAuthenticate_SessionCreate :)

So what you can do is check the Forms-based authentication every so often, because it (and Application_AuthenticateRequest) is fired for every request, CSS pages, images etc, going off to the database to check multiple times per request is an overly resource hungry idea. Luckily the forms cookie ticket has an issued on date and we can use that to check:

public void FormsAuthentication_OnAuthenticate(object sender, FormsAuthenticationEventArgs args)
    {
        if (FormsAuthentication.CookiesSupported)
        {
            if (Request.Cookies[FormsAuthentication.FormsCookieName] != null)
            {
                try
                {
                    FormsAuthenticationTicket ticket = FormsAuthentication.Decrypt(
                      Request.Cookies[FormsAuthentication.FormsCookieName].Value);

                    if ((DateTime.Now - ticket.IssueDate).TotalMinutes > 10)
                    {
                        if(/*Insert logic to check username here with ticket.Name*/)
                        {
                            //recreate cookie with new issuedate
                            FormsAuthentication.SetAuthCookie(ticket.Name, ticket.IsPersistent);
                        }
                        else
                        {
                            FormsAuthentication.SignOut();
                        }
                    }
                    Debug.WriteLine($"{ticket.Name} {ticket.IssueDate.ToUniversalTime()}");
                }
                catch (Exception e)
                {
                    //Elmah
                    ErrorSignal.FromCurrentContext().Raise(e);
                    //Cannot decrypt cookie, make the user sign in again
                    FormsAuthentication.SignOut();
                }
            }
        }
        else
        {
            throw new HttpException("Cookieless Forms Authentication is not supported for this application.");
        }
    }

This is not the same as cookie expiration, because the user will still retain login status; the user should never see any login request unless there account is no longer valid.

Related