Custom "Access Denied" Message

J

Jay Nesbitt

I'm using forms authentication along with role based authorization in my web
app. The problem I'm having is that when a user that has already been
authenticated tries to access an url that they are not authorized for, they
get kicked back to the login page. This makes no since to me since the user
has already been authenticated. Why does asp.net do this? Is there a
workaround for this that will allow me to present unauthorized users with a
custom "Access Denied" page? I know I could do this programatically in each
page but I would prefer a solution that would allow me to do it
declaritively in the web.config file. Any ideas?

Thanks
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Members online

No members online now.

Forum statistics

Threads
473,755
Messages
2,569,537
Members
45,020
Latest member
GenesisGai

Latest Threads

Top