I created a role based menu for which I followed this tutorial. Some where down that page you\'ll see this line of code:
String[] roles = Roles.GetRolesForU
Here's an extension method of the above solution.
public static List<string> Roles(this ClaimsIdentity identity)
{
return identity.Claims
.Where(c => c.Type == ClaimTypes.Role)
.Select(c => c.Value)
.ToList();
}
Controller.User.Identity
is a ClaimsIdentity
. You can get a list of roles by inspecting the claims...
var roles = ((ClaimsIdentity)User.Identity).Claims
.Where(c => c.Type == ClaimTypes.Role)
.Select(c => c.Value);
--- update ---
Breaking it down a bit more...
using System.Security.Claims;
// ........
var userIdentity = (ClaimsIdentity)User.Identity;
var claims = userIdentity.Claims;
var roleClaimType = userIdentity.RoleClaimType;
var roles = claims.Where(c => c.Type == ClaimTypes.Role).ToList();
// or...
var roles = claims.Where(c => c.Type == roleClaimType).ToList();
I don't think any of the answers is entirely correct as they all take the principal identity of the logged in user. User
is a ClaimsPrincipal
and can have multiple identities (ClaimsPrincipal.Identities
property). ClaimsPrincipal.Identity
is the principal identity of those identities. So to get all roles of the user you need to get roles from all identities. This is what the built-in ClaimPrincipal.IsInRole(string roleName)
method does i.e. it checks the given roleName
exists in any of the identities.
So the correct way to get all roles is something like this:
public static class ClaimsPrincipalExtensions
public static IEnumerable<string> GetRoles(this ClaimsPrincipal principal)
{
return principal.Identities.SelectMany(i =>
{
return i.Claims
.Where(c => c.Type == i.RoleClaimType)
.Select(c => c.Value)
.ToList();
});
}
}
and used as
var roles = User.GetRoles()
Also, note the use of claim type set in the identity Identity.RoleClaimType
instead of the static claim type ClaimTypes.Role
. This is needed because the role claim type can be overridden per identity e.g. when identity is received via a JWT token which provides ability to use a custom claim name as the role claim type.
After getting Identity User from SignIn Manager, callGetRolesAsync on UserManager and pass identity user as parameter. It will return of List of roles, identity user enrolled in
var rolesList = await userManager.GetRolesAsync(identityuser).ConfigureAwait(false);
Don't use @using System.IdentityModel.Claims namespace, Instead of that use
@using System.Security.Claims
@using System.Security.Claims
@using Microsoft.AspNet.Identity
@{
var claimsIdentity = User.Identity as System.Security.Claims.ClaimsIdentity;
var customUserClaim = claimsIdentity != null ? claimsIdentity.Claims.FirstOrDefault(x => x.Type == "cutomType") : null;
var customTypeValue= customUserClaim != null ? customUserClaim .Value : User.Identity.GetUserName();
var roleOfUser = claimsIdentity != null ? claimsIdentity.Claims.FirstOrDefault(x => x.Type == ClaimTypes.Role).Value :"User";
}