So, I want to block users from access a website after some unsuccessful login attempts with windows authentication. I already implemented that authentication and to block them, I thought about using a custom role provider.
My problem is that I get stuck in the GetRolesForUser method (no other method is reached) no matter if the user belongs to that role or not, which makes me think that the user is always unauthorized.
Here's my code:
public class Auth : RoleProvider{
public override string ApplicationName { get => throw new NotImplementedException(); set => throw new NotImplementedException(); }
//other not implemented stuff
public override string[] GetRolesForUser(string username)
{
PrincipalContext domainctx = new PrincipalContext(ContextType.Machine, null);
UserPrincipal userPrincipal = UserPrincipal.FindByIdentity(domainctx, IdentityType.SamAccountName, username);
return userPrincipal.GetGroups().Select(g => g.Name).ToArray();
//breakpoint always stops the line above
//it is returing the right roles tho
}
public override bool IsUserInRole(string username, string roleName)
{
PrincipalContext domainctx = new PrincipalContext(ContextType.Machine, null);
UserPrincipal userPrincipal = UserPrincipal.FindByIdentity(domainctx, IdentityType.SamAccountName, username);
return userPrincipal.IsMemberOf(domainctx, IdentityType.Name, roleName);
}
}
Can you spot any problem here? Also, am I going in the right direction to block a user's access? Thanks!!