I know "session" in asp.net. I used to store user data and required info whenever needed into session. (but I didn't know how to make session time out and all. just to store data at server side)
but now I'm using asp.net WEB API mvc 4 project. I have added angular support in it. by using ui-route for page routing I redirect user from one page to another page.
For now when user gets logged in, I store user name into html storage and show it in every page as WELCOME user. Till now everything works fine.
But question is- I don't know how to restrict unknown user from accessing web apis. How can I authentic valid user? I don't know anything in it. How can I check whether user is authorized to see the page or not?
As I store user name into html storage, at routing time I can only check whether logged in user is accessing page or not. But html storage can be tempered. So I wonder how to put security.