我理解对于我通常称为"角色"或"权限"的事物的声明的用法.我知道声明更为通用,但从我在实践中看到的情况来看,它通常归结为:如果用户有这组声明,他们可以访问某些区域或执行某些功能.
想象一下wiki应用程序.你可能有一个content_contributor要求,将允许用户添加的内容,一个content_admin要求,将允许用户删除内容和modify_user要求,将允许参与者权限其他用户发放.
将此示例更进一步,我可能希望限制用户,以便他们只能看到自己或他们的团队创建的内容.
如果用户只能看到他们自己创建的内容,我们是否会对他们创建的每个内容提出索赔,或者我们是否会将该授权委托给该应用程序?
我在ASP.NET MVC应用程序中使用ASP.NET Identity(数据库优先)。我按照此处的说明使用数据库优先方法设置ASP.NET Identity。
我的AspNetUsers表与Employee表有关系(Employee表具有UserId外键,AspNetUsers实体具有ICollection<Employee>属性)。
我想将ICollection<Employee>属性添加到ApplicationUser,如下所示:
public class ApplicationUser : IdentityUser<int, CustomUserLogin, CustomUserRole, CustomUserClaim>
{
public ICollection<Employee> Employees { get; set; }
public async Task<ClaimsIdentity> GenerateUserIdentityAsync(UserManager<ApplicationUser, int> manager)
{
// Note the authenticationType must match the one defined in CookieAuthenticationOptions.AuthenticationType
var userIdentity = await manager.CreateIdentityAsync(this, DefaultAuthenticationTypes.ApplicationCookie);
// Add custom user claims here
return userIdentity;
}
}
Run Code Online (Sandbox Code Playgroud)
但是,当我这样做时,会收到以下错误消息:
EntityType'AspNetUserLogins'没有定义键。定义此EntityType的键。AspNetUserLogins:EntityType:EntitySet'AspNetUserLogins'基于类型'AspNetUserLogins',但未定义键。
为什么会收到此错误消息?我该如何解决?