public ActionResult ValidateUser(string userName, string password) { WebUser webUser = null; SessionManager.DoWork(session => { webUser = session.Query <WebUser>().SingleOrDefault(s => s.UserName.Trim().Equals(userName.Trim())); if (webUser != null && password != WebUser.ChangeMd5(password.Trim())) { webUser = null; } else if (webUser != null && webUser.Password == WebUser.ChangeMd5(password.Trim())) { SessionHelper.Data(SessionKey.UserId, webUser.Id); SessionHelper.Data(SessionKey.UserName, webUser.UserName); } }); return(webUser.ToJSON()); }