KnowledgeHub
Questions
Tags
Users
Search
Alex Rivera
|
Logout
Edit Question
Title
Body
I am having problems allowing a specific Role access to a specific page in a subdirectory. My ASP.NET application has a directory, ~/Forms/Administration that has limited access. There is a specific file, ~/Forms/Administration/Default.aspx that I want to give 1 additional user role access to, as well as the Admin role. In ~/Forms/Administration, I have a web.config file that looks like this: <?xml version="1.0" encoding="utf-8"?> <configuration> <system.web> <authorization> <allow roles="Administrator, User" /> <deny users="*"/> </authorization> </system.web> <location path="Forms/Administration/Default.aspx"> <system.web> <authorization> <allow roles="Administrator, User, AdditionalUser" /> </authorization> </system.web> </location> </configuration> The Admin user works just fine, but AdditionalUser always fails. I've tried a number of things - listing the location as <location path="Forms/Administration/Default.aspx"> And as <location path="~/Forms/Administration/Default.aspx"> Is the deny="*" from the first generic rule taking precedent? I tried changing <deny users="*"/> To <deny users="?"/> But that ends up giving AdditionalUser access to everything . Suggestions? EDIT: I tried putting the location specific allow before the generic deny rule, in case order mattered. Same problem. UPDATE: I am clearly missing something here: I removed the deny * config, and left only the location specific section. Then, instead of allowing on certain roles, I set that one to deny all (*). However, it is not de
Tags (comma-separated)
Save Edits
Cancel