//
        //POST: /Admin/LoginOn
        [HttpPost]
        public ActionResult LoginOn(WebMasterLoginOn model, string returnUrl)
        {
            if (ModelState.IsValid)
            {
                using (Aspx2_comEntities ENS = new Aspx2_comEntities())
                {
                    WebMaster WM = ENS.WebMaster.FirstOrDefault(p => p.Uid == model.Uid);
                    
                    if (WM == null)
                    {
                        ModelState.AddModelError("", "管理员帐号不存在!");
                    }
                    else
                    {
                        if (WM.Pwd == model.Pwd)
                        {                            if (Url.IsLocalUrl(returnUrl) && returnUrl.Length > 1 && returnUrl.StartsWith("/")
                            && !returnUrl.StartsWith("//") && !returnUrl.StartsWith("/\\"))
                            {
                                return Redirect(returnUrl);
                            }
                            else
                            {
                                return RedirectToAction("Main", "Admin");
                            }
                        }
                        else
                        { 
                            ModelState.AddModelError("", "登录密码错误!"); 
                        }
                    }
                }
                //if (Membership.ValidateUser(model.Uid, model.Pwd))
                //{
                //    Response.Write("OK");
                //    Response.End();
                //}
                //else
                //{
                //    Response.Write("ERROR");
                //    Response.End();
                //}
            }
            return View();
        }
这个是我的登录模块我想知道..如何为登录用户分配权限以便 我之后调用        [Authorize]