asp.net identity get all roles of logged in user
Asked Answered
T

7

89

I created a role based menu for which I followed this tutorial. Some where down that page you'll see this line of code:

String[] roles = Roles.GetRolesForUser();

It returns all roles of the currently logged in user. I was wondering how to accomplish this with the new ASP.NET Identity system?

It's still pretty new and there is not much to find about it.

Thaddeusthaddus answered 10/2, 2014 at 22:7 Comment(2)
A great explanation of Claims and Identity for .NET Core : andrewlock.net/introduction-to-authentication-with-asp-net-core (not mine)Pizzeria
The selected answer is not entirely correct. See answer https://mcmap.net/q/236051/-asp-net-identity-get-all-roles-of-logged-in-userLundberg
N
155

Controller.User.Identity is a ClaimsIdentity. You can get a list of roles by inspecting the claims...

var roles = ((ClaimsIdentity)User.Identity).Claims
                .Where(c => c.Type == ClaimTypes.Role)
                .Select(c => c.Value);

--- update ---

Breaking it down a bit more...

using System.Security.Claims;

// ........

var userIdentity = (ClaimsIdentity)User.Identity;
var claims = userIdentity.Claims;
var roleClaimType = userIdentity.RoleClaimType;
var roles = claims.Where(c => c.Type == ClaimTypes.Role).ToList();

// or...
var roles = claims.Where(c => c.Type == roleClaimType).ToList();
Nena answered 10/2, 2014 at 23:29 Comment(7)
According to this doc msdn.microsoft.com/en-us/library/… , there is no Role in ClaimTypes. Do I need to add it or something?Thaddeusthaddus
ASP.NET Identity uses System.Security.Claims.ClaimTypes msdn.microsoft.com/en-us/library/…. Also, the ClaimsIdentity object also has a RoleClaimType property that contains the same value and you can use that instead.Nena
Could you update your answer to show me how that will look like in code? Tried a few ways, but I don't see RoleClaimType.Thaddeusthaddus
Maybe it's just that things have changed in 2 years, but this doesn't seem to be correct. I just looked in my DB (tables created by EF), and there is a record in the AspNetUserRoles table, but no corresponding record in the AspNetUserClaims table, so Claims don't necessarily get added when a user is added to a Role.Gwendolyn
(from c in ((ClaimsIdentity)User.Identity).Claims where c.Type.Equals("role") select c.Value).ToArray() //since asked for arrayDingman
This answer would be great if it explained that ASP.NET Identity is not involved in this answer, only ASP.NET MVCRunt
This answer is not entirely correct. Please see https://mcmap.net/q/236051/-asp-net-identity-get-all-roles-of-logged-in-userLundberg
R
23

Here's an extension method of the above solution.

    public static List<string> Roles(this ClaimsIdentity identity)
    {
        return identity.Claims
                       .Where(c => c.Type == ClaimTypes.Role)
                       .Select(c => c.Value)
                       .ToList();
    }
Redness answered 5/12, 2014 at 20:48 Comment(2)
How to access it ?Alcaic
This is an extension method off of the "System.Security.Claims.ClaimsIdentity" object.Redness
H
15

After getting the Identity User from SignInManager, call GetRolesAsync on UserManager and pass identity user as parameter.

It will return a list of roles the identity user has enrolled in.

var rolesList = await userManager.GetRolesAsync(identityuser).ConfigureAwait(false);
Hetti answered 13/6, 2019 at 18:30 Comment(1)
the selected answer is for claims not the answer for the OP which was asking for roles - this answers the OPAlliterative
L
8

I don't think any of the answers is entirely correct as they all take the principal identity of the logged in user. User is a ClaimsPrincipal and can have multiple identities (ClaimsPrincipal.Identities property). ClaimsPrincipal.Identity is the principal identity of those identities. So to get all roles of the user you need to get roles from all identities. This is what the built-in ClaimPrincipal.IsInRole(string roleName) method does i.e. it checks the given roleName exists in any of the identities.

So the correct way to get all roles is something like this:

    public static class ClaimsPrincipalExtensions

       public static IEnumerable<string> GetRoles(this ClaimsPrincipal principal)
        {
            return principal.Identities.SelectMany(i =>
            {
                return i.Claims
                    .Where(c => c.Type == i.RoleClaimType)
                    .Select(c => c.Value)
                    .ToList();
            });
        }
    }

and used as

var roles = User.GetRoles()

Also, note the use of claim type set in the identity Identity.RoleClaimType instead of the static claim type ClaimTypes.Role . This is needed because the role claim type can be overridden per identity e.g. when identity is received via a JWT token which provides ability to use a custom claim name as the role claim type.

Lundberg answered 9/8, 2020 at 9:11 Comment(1)
3 years later and this worked perfectly for passing IPrincipal to a custom auth methodBibbie
F
4

Don't use @using System.IdentityModel.Claims namespace, Instead of that use

@using System.Security.Claims

    @using System.Security.Claims
    @using Microsoft.AspNet.Identity
    @{      
       var claimsIdentity = User.Identity as System.Security.Claims.ClaimsIdentity;
       var customUserClaim = claimsIdentity != null ? claimsIdentity.Claims.FirstOrDefault(x => x.Type == "cutomType") : null;
       var customTypeValue= customUserClaim != null ? customUserClaim .Value : User.Identity.GetUserName();
       var roleOfUser = claimsIdentity != null ? claimsIdentity.Claims.FirstOrDefault(x => x.Type == ClaimTypes.Role).Value :"User";

}
Ferrin answered 9/4, 2018 at 12:59 Comment(1)
What is this supposed to answer? Who is using System.IdentityModel.Claims and where?Runt
N
1

try below:

var roles = user.Claims.Where(c => c.Type == ClaimTypes.Role).Select(x => x.Value).FirstOrDefault();
Noticeable answered 12/9, 2022 at 0:52 Comment(1)
The only short and working solution I found.Chamois
J
0

You can also use such syntax:

var userClaims = User.Identity as System.Security.Claims.ClaimsIdentity;
var roles = userClaims.FindAll("http://schemas.microsoft.com/ws/2008/06/identity/claims/role").ToList();
Jeu answered 31/1, 2023 at 14:18 Comment(0)

© 2022 - 2024 — McMap. All rights reserved.