Table of Contents

Class AccountController

Namespace
ProjectTemplate.Web.Controllers
Assembly
ProjectTemplate.Web.dll

Provides actions for user authentication, including login, logout, and access denied handling.

public class AccountController : Controller, IActionFilter, IAsyncActionFilter, IFilterMetadata, IDisposable
Inheritance
AccountController
Implements
Inherited Members

Remarks

This controller exposes endpoints for user authentication workflows. It supports external authentication providers and enforces security best practices such as requiring local return URLs to prevent open redirect vulnerabilities. Actions are decorated with appropriate authorization and anti-forgery attributes as needed.

Constructors

AccountController(IAuthenticationSchemeProvider)

Provides actions for user authentication, including login, logout, and access denied handling.

public AccountController(IAuthenticationSchemeProvider schemeProvider)

Parameters

schemeProvider IAuthenticationSchemeProvider

The authentication scheme provider used to retrieve available external authentication schemes for login operations. Cannot be null.

Remarks

This controller exposes endpoints for user authentication workflows. It supports external authentication providers and enforces security best practices such as requiring local return URLs to prevent open redirect vulnerabilities. Actions are decorated with appropriate authorization and anti-forgery attributes as needed.

Methods

AccessDenied()

Handles requests to the access denied page and returns a view indicating that the user does not have permission to access the requested resource.

[HttpGet("/Account/AccessDenied")]
[AllowAnonymous]
public IActionResult AccessDenied()

Returns

IActionResult

A view result that displays the access denied page with a 403 Forbidden status code.

Remarks

This action is accessible to all users, including unauthenticated users. The response status code is set to 403 to indicate forbidden access.

Login(string?)

Displays the login page and provides available external authentication providers.

[HttpGet("/Account/Login")]
[AllowAnonymous]
public Task<IActionResult> Login(string? returnUrl = null)

Parameters

returnUrl string

The URL to redirect to after a successful login. If null or empty, the user is redirected to the application's root. Must be a local URL.

Returns

Task<IActionResult>

A view result that renders the login page with available external authentication providers, or a bad request result if the return URL is not local.

Remarks

This action is accessible without authentication. Only local return URLs are permitted to prevent open redirect vulnerabilities.

Logout(string?)

Signs out the current user and redirects to the specified return URL.

[Authorize]
[HttpPost("/Account/Logout")]
[ValidateAntiForgeryToken]
public Task<IActionResult> Logout(string? returnUrl = null)

Parameters

returnUrl string

The URL to redirect to after sign-out. If null or empty, defaults to the application's root ('/'). Must be a local URL.

Returns

Task<IActionResult>

A redirect result to the specified local return URL if sign-out is successful; otherwise, a bad request result if the return URL is not local.

Remarks

This action requires an authenticated user, a valid anti-forgery token, and only accepts local URLs for redirection to help prevent cross-site request forgery and open redirect vulnerabilities.