Book Image

ASP.NET MVC 4 Mobile App Development

By : Andy Meadows
Book Image

ASP.NET MVC 4 Mobile App Development

By: Andy Meadows

Overview of this book

The ASP.NET MVC 4 framework is used to build scalable web applications with the help of design patterns and .NET Framework. The Model-View-Controller (MVC) is a design principle which separates the components of a web application. This separation helps you to modify, develop, and test different components of a web application. ASP.NET MVC 4 Mobile App Development helps you to develop next generation applications, while guiding you to deal with the constraints the mobile web places on application development. By the end of the book, you will be well versed with all the aspects of mobile app development. ASP.NET MVC 4 Mobile App Development introduces you to developing mobile web apps using the ASP.NET MVC 4 framework. Walking you through the process of creating a homebrew recipe sharing application, this book teaches you the fundamentals and concepts relevant to developing Internet-ready mobile-enabled web apps. Through the sample application, you will learn how to secure your apps against XSS and CSRF attacks, open up your application to users using third party logins such as Google or Facebook, and how to use Razor, HTML 5, and CSS 3 to create custom views and content targeting mobile devices. Using these custom views, you will then learn how to create web apps with a native mobile device feel using jQuery mobile. By the end of the book, you will be presented with a set of challenges to prove to yourself that you now have the skills to extend your existing web applications to the mobile web or create new mobile web apps.
Table of Contents (23 chapters)
ASP.NET MVC 4 Mobile App Development
Credits
About the Author
Acknowledgment
About the Reviewers
www.PacktPub.com
Preface
7
Separating Functionality Using Routes and Areas
Index

Authorization


Authentication gives us a means to identify our users, but it is authorization that provides us a mechanism to enable or restrict the actions authenticated users may perform.

Restricting access

In ASP.NET MVC, access is restricted through the use of the Authorize attributes that may be placed on controllers or actions. If the Authorize attribute is at the controller level, anonymous users may be granted access to specific actions via the AllowAnonymous keyword.

The Authorize attribute

If you take a look at the AccountController class, you will see the class declared with the Authorize attribute. However, the Login action is decorated with the AllowAnonymous attribute:

[Authorize]
public class AccountController : Controller
{
  [AllowAnonymous]
  public ActionResult Login(string returnUrl)
  {
    ViewBag.ReturnUrl = returnUrl;
    return View();
  }
  /* ... */
}

The application of the Authorize attribute states that only authenticated users may access the account controller. The...