You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

从DNN数据库验证登录用户及解决连接字符串格式错误

Answers to Your ASP.NET/DNN Questions

First off, let's break down your three main issues one by one—no jargon, just practical solutions:

1. Verifying Encrypted Passwords Without Decrypting Them

The golden rule here is: never decrypt stored passwords. Instead, you re-hash the user's login input and compare it to the stored hash. Here's how it works:

When a user registers, you take their password, combine it with a unique "salt" (a random string), hash the whole thing, and store both the hash and salt in your database. During login:

  1. Look up the stored hash and salt for the username the user entered.
  2. Take their input password, add the same salt, and hash it using the exact same algorithm you used during registration.
  3. If the new hash matches the stored one, the password is correct—no decryption needed.

For DNN specifically, since it uses the ASP.NET Membership system, you can skip writing custom hash logic entirely. Use the built-in Membership.ValidateUser method—it handles all the heavy lifting:

if (Membership.ValidateUser(txtUsername.Text, txtPassword.Text))
{
    FormsAuthentication.SetAuthCookie(txtUsername.Text, false);
    // Redirect to your app's home page
}
else
{
    // Show an error like "Invalid username or password"
}

If you need to build custom verification (e.g., outside the Membership system), replicate DNN's hashing logic. Most DNN versions use SHA256 with a base64-encoded salt. Here's a quick example:

public bool CheckPassword(string inputPassword, string storedHash, string storedSalt)
{
    // Convert salt from base64 to bytes
    byte[] saltBytes = Convert.FromBase64String(storedSalt);
    // Convert input password to bytes
    byte[] passwordBytes = Encoding.UTF8.GetBytes(inputPassword);
    
    // Combine password and salt
    byte[] combined = new byte[passwordBytes.Length + saltBytes.Length];
    Buffer.BlockCopy(passwordBytes, 0, combined, 0, passwordBytes.Length);
    Buffer.BlockCopy(saltBytes, 0, combined, passwordBytes.Length, saltBytes.Length);
    
    // Hash using SHA256 (match DNN's algorithm)
    using (var sha256 = SHA256.Create())
    {
        byte[] hashedInput = sha256.ComputeHash(combined);
        string computedHash = Convert.ToBase64String(hashedInput);
        
        // Compare the two hashes
        return computedHash == storedHash;
    }
}

2. Fixing the "Format of the initialization string does not conform to specification" Error

This error is almost always tied to a broken connection string. Let's fix it:

  • Check your web.config: Make sure your connection string is properly defined in the <connectionStrings> section. A valid SQL Server connection string looks like this:
    <connectionStrings>
        <add name="DNNConnection" 
             connectionString="Server=YOUR_SERVER;Database=YOUR_DNN_DB;User ID=DB_USER;Password=DB_PASS;" 
             providerName="System.Data.SqlClient" />
    </connectionStrings>
    
  • Common mistakes to avoid:
    • Missing semicolons between key-value pairs (easy to miss!).
    • Typos in keys (e.g., "Server" instead of "Serve"—small mistake, big problem).
    • Empty connection string (double-check the connectionString attribute isn't blank).
    • Using the wrong provider name (for SQL Server, it's System.Data.SqlClient; for newer SQL Server Core, use Microsoft.Data.SqlClient).
  • Confirm you're using the right name: When accessing the string in code, use the exact name from web.config:
    string connString = ConfigurationManager.ConnectionStrings["DNNConnection"].ConnectionString;
    

3. Retrieving Username and Password Data from DNN Database

DNN stores user credentials in two core tables from the ASP.NET Membership schema:

  • aspnet_Users: Holds basic user info, including UserName (the login username) and UserId.
  • aspnet_Membership: Stores password-related data:
    • Password: The hashed password (never plain text—DNN doesn't store raw passwords).
    • PasswordSalt: The salt used to hash the password.
    • UserId: Links to the aspnet_Users table.

To fetch this data, run a SQL query like:

SELECT u.UserName, m.Password, m.PasswordSalt
FROM aspnet_Users u
INNER JOIN aspnet_Membership m ON u.UserId = m.UserId
WHERE u.UserName = 'your_target_username'

Critical Note: Never retrieve the password hash to display or modify it directly. Stick to the Membership.ValidateUser method or custom verification logic above to authenticate users—it's far more secure.


内容的提问来源于stack exchange,提问作者user9356915

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.22 09:29:08