C#實現的Check Password,並根據輸錯密碼的次數分狀況鎖定帳戶:若是輸入錯誤3次,登陸帳戶鎖定5分鐘並提示X點X分後重試登陸。若是5分鐘後再次輸入,累計輸入錯誤密碼累計達到5次。則帳戶會被永久鎖定,需聯繫系統管理員進行把數據庫中的輸入錯誤的次數(errorcount)進行清零解鎖才能登錄。實現代碼以下:數據庫
public class UserInfo1 { public string Error_count { get; set; } public string Error_time { get; set; } }
public ExecutionResult CheckAccountPwd(string account, string password) { ExecutionResult execRes; execRes = new ExecutionResult(); string[] strs = account.Split(new string[] { "\\" }, StringSplitOptions.RemoveEmptyEntries); if (strs.Length < 2) { execRes.Status = false; execRes.Message = "無效的帳號。"; } else { UserInfo1 info1 = null; execRes = CallEEPMethod.Execute(dbName, "sDEM2131", "GetUserInfo", strs[1].ToLower()); if (execRes.Status && execRes.Anything != null) { info1 = JsonConvert.DeserializeObject<UserInfo1>(execRes.Anything.ToString()); if (info1 != null) { int errcount = Convert.ToInt32(info1.Error_count); DateTime errtime = Convert.ToDateTime(info1.Error_time); if (errcount != 5) { //int errorCount DateTime dt0 = DateTime.Now; DateTime dt1 = errtime.AddMinutes(5); double s = (dt1 - dt0).TotalSeconds; if (errcount == 3 && s > 0) { execRes.Status = false; execRes.Message = "密碼連續輸入錯誤3次,請於 " + errtime.AddMinutes(+5).ToString("yyyy-MM-dd HH:mm:ss") + " 以後重試,thanks!"; } else { if (CheckFromLDAP(strs[1], password, strs[0])) { CPU.Models.UserInfo userInfo = CheckUser(strs[1]); if (userInfo == null) { execRes.Status = false; execRes.Message = "您沒有權限操做此係統!"; } else { execRes.Status = true; execRes.Anything = userInfo; //error count 清0 CallEEPMethod.Execute(dbName, "sDEM2131", "UpdateUserLoginError", strs[1].ToLower() + ","+"0" + "," + DateTime.Now.ToString("yyyy/MM/dd HH:mm:ss")); } } else { execRes.Status = false; // 次數+1 if (errcount + 1 > 1) execRes.Message = "密碼連續輸入錯誤" + (errcount+1).ToString() + "次。密碼連續輸錯5次將鎖定!"; else execRes.Message = "密碼輸入錯誤!"; dt0 = DateTime.Now; CallEEPMethod.Execute(dbName, "sDEM2131", "UpdateUserLoginError", strs[1].ToLower() + "," + (errcount + 1).ToString()+"," + DateTime.Now.ToString("yyyy/MM/dd HH:mm:ss")); if (errcount + 1 == 3) execRes.Message = "密碼連續輸入錯誤" + (errcount + 1).ToString() + "次,請於 " + dt0.AddMinutes(5).ToString("yyyy-MM-dd HH:mm:ss") + " 以後重試,thanks!"; if (errcount + 1 == 5) execRes.Message = "帳號密碼連續輸入錯誤5次,已鎖定!請聯繫管理員解鎖,thanks!"; } } } else { execRes.Status = false; execRes.Message = "帳號密碼連續輸入錯誤5次,已鎖定!請聯繫管理員解鎖,thanks!"; } } else { execRes.Status = false; execRes.Message = "找不到此帳號,請從新輸入!"; } } else { execRes.Status = false; execRes.Message = "找不到此帳號,請從新輸入!"; } } return execRes; }
根據登陸不一樣的網域進行Form驗證dom
private bool CheckFromLDAP(string ntID, string ntPWD, string domain)//根據登陸的不一樣網域進行Form驗證 { bool result = false; string strUser; try { strUser = domain + "\\" + ntID; if (domain.ToLower().Equals("gi")) domain = "gi.compal.com"; else if (domain.ToLower().Equals("cqc_cci")) domain = "10.140.1.1"; else if (domain.ToLower().Equals("vn")) domain = "10.144.2.101"; else if (domain.ToLower().Equals("njp_cci")) domain = "10.128.50.1"; else domain = "compal.com"; DirectoryEntry entry = new DirectoryEntry("LDAP://" + domain, strUser, ntPWD); using (DirectorySearcher searcher = new DirectorySearcher(entry)) { searcher.Filter = string.Format("(&(objectClass=user)(sAMAccountName={0}))", ntID); SearchResult sr = searcher.FindOne(); using (SearchResultCollection results = searcher.FindAll()) { if (results.Count > 0) { //if (results[0].Properties.Contains("employeeID")) // empID = results[0].Properties["employeeID"][0].ToString(); //else // empID = results[0].Properties["extensionattribute3"][0].ToString(); result = true; } } } } catch (Exception ex) { //LogHelper.Error(ex.Message); } return result; }
根據不一樣的用戶登陸進行權限管理spa
public bool CheckPermission(string controllerName, string actionName,string plant, string userID) { bool result = false; //if (actionName.StartsWith("_")) // actionName = actionName.Substring(1); UserInfo userInfo = CheckUser(userID); if (userInfo!=null) { if (controllerName == "Home") result = true; else if (userInfo.Permissions.Contains(controllerName)) { if (!string.IsNullOrEmpty(plant)) { if (userInfo.PlantCode.ToLower() == plant.ToLower() || userInfo.PlantCode == "ALL") result = true; } else result = true; } } return result; }