Jul 23, 2013 at 7:43 PM

did I get it right, that FormsAuthenticationProvider.OnValidateIdentity is the right place for checking, if the current user has the right to access to currently requested page/ ressource?

Did I also get it right, that OnResponseSignIn is the right place, to perform an application-internal claims-mapping?

There is also a delegate OnValidateLogin. What is the purpose of this delegate? It seems like it never get called.