ASP.NET Core如何返回包含ApplicationUser且不含密码属性的Post对象
解决方案
以下两种是最常用的实现方式,按需选择即可:
方案1:使用DTO(数据传输对象,推荐)
这是行业通用的最佳实践,既可以过滤敏感字段,也能实现数据库实体和前端返回结构的解耦,避免后续修改数据库结构影响对外接口。
- 首先定义仅包含需返回字段的DTO类:
// 公开的用户信息DTO,只保留需要对外展示的字段 public class PublicUserDto { public string Id { get; set; } public string UserName { get; set; } public string? AvatarUrl { get; set; } // 其他你需要公开的用户字段自行添加 } // 帖子返回DTO public class PostDto { public int Id { get; set; } public string Contents { get; set; } public ulong Timestamp { get; set; } public PublicUserDto ApplicationUser { get; set; } }
- 修改Controller的查询逻辑,直接投影到DTO,无需手动
Include,EF Core会自动关联查询所需字段,性能比全量加载关联实体更高:
[Authorize] [HttpGet("{id}")] public async Task<ActionResult<PostDto>> GetPost(int id) { var postDto = await _context.Posts .Where(x => x.Id == id) .Select(p => new PostDto { Id = p.Id, Contents = p.Contents, Timestamp = p.Timestamp, ApplicationUser = new PublicUserDto { Id = p.ApplicationUser.Id, UserName = p.ApplicationUser.UserName // 其他需要的用户字段赋值 } }) .FirstOrDefaultAsync(); if (postDto == null) { return NotFound(); } return postDto; }
方案2:给敏感字段加[JsonIgnore]特性(快速实现)
如果你不想额外定义DTO,只需要快速隐藏敏感字段,可以在ApplicationUser类中重写IdentityUser的敏感属性,添加序列化忽略特性:
using System.Text.Json.Serialization; public class ApplicationUser : IdentityUser { [JsonIgnore] public override string PasswordHash { get; set; } [JsonIgnore] public override string SecurityStamp { get; set; } [JsonIgnore] public override string ConcurrencyStamp { get; set; } // 其他需要隐藏的字段比如手机号、邮箱等都可以重写后加[JsonIgnore] }
注意:该方案是全局生效的,所有返回ApplicationUser的接口序列化时都会忽略加了[JsonIgnore]的字段,如果有后台管理接口需要用到这些字段则不适用。
内容的提问来源于stack exchange,提问作者Tim Eulink
相关产品推荐
相关产品推荐

