DevBetterCom / DevBetterWeb

A simple web application for devBetter
https://devbetter.com/
140 stars 57 forks source link

Use a Policy for Auth Access to Profile etc. #189

Open ardalis opened 3 years ago

ardalis commented 3 years ago

See: https://docs.microsoft.com/en-us/aspnet/core/security/authorization/policies?view=aspnetcore-5.0

Address authentication for everything under /Pages/Profile to eliminate duplication of [Authorize] attribute.

ardalis commented 3 years ago

See also: https://ardalis.com/favor-privileges-over-role-checks/