Restrict access to method to a user role.
namespace MyApps.Web.Models
{
using System;
using System.Web;
using System.Web.Mvc;
[AttributeUsage(AttributeTargets.Method)]
public class AjaxUserAttribute : ActionFilterAttribute
{
public override void OnActionExecuting(ActionExecutingContext filterContext)
{
if (HttpContext.Current.User.IsInRole("User")) return;
filterContext.HttpContext.Response.StatusCode = 401;
filterContext.Result = new HttpUnauthorizedResult();
}
}
}
Comments