Feb 06

The MVC framework: wrapping up authorization

In the last post we’ve seen how we can use the AuthorizeAttribute for authorizing a specific request. At the time, I’ve forgot to mention one detail regarding authorization. Besides using the AuthorizeAttribute or creating your own custom attribute for deciding who can access a specific action method, you can also create your custom authentication code by overriding the OnAuthorization method that your controller inherits from ControllerBase. This might be a good option when you want to reuse you authorization code through several controllers and their action methods.