Class AccountController
- Namespace
- ProjectTemplate.Web.Controllers
- Assembly
- ProjectTemplate.Web.dll
Provides actions for user authentication, including login, logout, and access denied handling.
public class AccountController : Controller, IActionFilter, IAsyncActionFilter, IFilterMetadata, IDisposable
- Inheritance
-
AccountController
- Implements
- Inherited Members
Remarks
This controller exposes endpoints for user authentication workflows. It supports external authentication providers and enforces security best practices such as requiring local return URLs to prevent open redirect vulnerabilities. Actions are decorated with appropriate authorization and anti-forgery attributes as needed.
Constructors
AccountController(IAuthenticationSchemeProvider)
Provides actions for user authentication, including login, logout, and access denied handling.
public AccountController(IAuthenticationSchemeProvider schemeProvider)
Parameters
schemeProviderIAuthenticationSchemeProviderThe authentication scheme provider used to retrieve available external authentication schemes for login operations. Cannot be null.
Remarks
This controller exposes endpoints for user authentication workflows. It supports external authentication providers and enforces security best practices such as requiring local return URLs to prevent open redirect vulnerabilities. Actions are decorated with appropriate authorization and anti-forgery attributes as needed.
Methods
AccessDenied()
Handles requests to the access denied page and returns a view indicating that the user does not have permission to access the requested resource.
[HttpGet("/Account/AccessDenied")]
[AllowAnonymous]
public IActionResult AccessDenied()
Returns
- IActionResult
A view result that displays the access denied page with a 403 Forbidden status code.
Remarks
This action is accessible to all users, including unauthenticated users. The response status code is set to 403 to indicate forbidden access.
Login(string?)
Displays the login page and provides available external authentication providers.
[HttpGet("/Account/Login")]
[AllowAnonymous]
public Task<IActionResult> Login(string? returnUrl = null)
Parameters
returnUrlstringThe URL to redirect to after a successful login. If null or empty, the user is redirected to the application's root. Must be a local URL.
Returns
- Task<IActionResult>
A view result that renders the login page with available external authentication providers, or a bad request result if the return URL is not local.
Remarks
This action is accessible without authentication. Only local return URLs are permitted to prevent open redirect vulnerabilities.
Logout(string?)
Signs out the current user and redirects to the specified return URL.
[Authorize]
[HttpPost("/Account/Logout")]
[ValidateAntiForgeryToken]
public Task<IActionResult> Logout(string? returnUrl = null)
Parameters
returnUrlstringThe URL to redirect to after sign-out. If null or empty, defaults to the application's root ('/'). Must be a local URL.
Returns
- Task<IActionResult>
A redirect result to the specified local return URL if sign-out is successful; otherwise, a bad request result if the return URL is not local.
Remarks
This action requires an authenticated user, a valid anti-forgery token, and only accepts local URLs for redirection to help prevent cross-site request forgery and open redirect vulnerabilities.