mix of anonymous and windows authentication and force windows authentication for certain webmethods

Viewed 111

I set up a .NET MVC project that uses both anonymous and windows authentication to users. It is also configured enabled in IIS for those 2 authentication methods. How can we only force windows authentication and start to ask user for windows username/password for certain webmethods (calling from client side's ajax) in certain cs code for page:

Default.aspx
  Default.aspx.cs

when certain webmethod is targeted:

        [WebMethod]
        [ScriptMethod(UseHttpGet = true)]
        public static string retr_key()

to pop up windows authentication request for user and once user passes that authentication, no need to ask for second time.

What needs to be done in web.config? And what authorize attribute should be used?

1 Answers

To enforce authorization on a method a [Authorize] attribute should be used. It can be used both on class and on a method.

When not used, the authorization is not performed. If used on a class and a method should not have authorization, an [AllowAnonymous] attribute can be used.

To globally specify authorization scheme (WinAuth/Forms/etc), the web.config file should be used.

Related