web.config

Discussion in 'ASP .Net Security' started by olap, Jun 24, 2004.

  1. olap

    olap Guest

    do you know why if i've got an entry in the web.config like this:

    <location path="Reportistica/Cruscotto">
    <system.web>
    <authorization>
    <allow users="Domain\MArio"/>
    <deny users="*"/>
    </authorization>
    </system.web>
    </location>

    it works

    instead if i've got an entry like this:


    <location path="Reportistica/Cruscotto/OLAP/Page.htm">
    <system.web>
    <authorization>
    <allow users="Domain\MArio"/>
    <deny users="*"/>
    </authorization>
    </system.web>
    </location>

    it doesn't work, and everyone can access that page?


    thx
     
    olap, Jun 24, 2004
    #1
    1. Advertising

  2. Most likely this is because .htm files are not served by the ASP.NET
    runtime, but are served by IIS directly. Therefore, this request never
    enters the ASP.NET pipeline and the security is not enforced.

    I've seen references on how to set up ASP.NET to handle other types of
    requests such as htm and image files. However, you might be better off just
    converting this page to an aspx page so you don't have to go through that
    hassle.

    Joe K.

    "olap" <> wrote in message
    news:...
    > do you know why if i've got an entry in the web.config like this:
    >
    > <location path="Reportistica/Cruscotto">
    > <system.web>
    > <authorization>
    > <allow users="Domain\MArio"/>
    > <deny users="*"/>
    > </authorization>
    > </system.web>
    > </location>
    >
    > it works
    >
    > instead if i've got an entry like this:
    >
    >
    > <location path="Reportistica/Cruscotto/OLAP/Page.htm">
    > <system.web>
    > <authorization>
    > <allow users="Domain\MArio"/>
    > <deny users="*"/>
    > </authorization>
    > </system.web>
    > </location>
    >
    > it doesn't work, and everyone can access that page?
    >
    >
    > thx
    >
    >
     
    Joe Kaplan \(MVP - ADSI\), Jun 24, 2004
    #2
    1. Advertising

  3. olap

    ranganh Guest

    Dear Olap,

    The htm files are not served by asp.net and are served by IIS itself. To enable security for that page, go to your application's virtual directory.

    Go to Properties, Configuration and in the list, click add to add the .htm extension and set the same properties as that of the one's for .aspx which is being listed in the grid.

    Once you are done with that, the htm files will be served by asp.net and the security would be enforced.

    hope it helps.

    "olap" wrote:

    > do you know why if i've got an entry in the web.config like this:
    >
    > <location path="Reportistica/Cruscotto">
    > <system.web>
    > <authorization>
    > <allow users="Domain\MArio"/>
    > <deny users="*"/>
    > </authorization>
    > </system.web>
    > </location>
    >
    > it works
    >
    > instead if i've got an entry like this:
    >
    >
    > <location path="Reportistica/Cruscotto/OLAP/Page.htm">
    > <system.web>
    > <authorization>
    > <allow users="Domain\MArio"/>
    > <deny users="*"/>
    > </authorization>
    > </system.web>
    > </location>
    >
    > it doesn't work, and everyone can access that page?
    >
    >
    > thx
    >
    >
    >
     
    ranganh, Jun 28, 2004
    #3
    1. Advertising

Want to reply to this thread or ask your own question?

It takes just 2 minutes to sign up (and it's free!). Just click the sign up button to choose a username and then you can ask your own questions on the forum.
Similar Threads
  1. =?Utf-8?B?RGFuaWVs?=

    Machine.config & web.config

    =?Utf-8?B?RGFuaWVs?=, Jan 18, 2004, in forum: ASP .Net
    Replies:
    2
    Views:
    13,477
    Hermit Dave
    Jan 18, 2004
  2. =?Utf-8?B?QXVndXN0aW4gUHJhc2FubmEuIEo=?=

    Web.Config Get Config settings at runtime.

    =?Utf-8?B?QXVndXN0aW4gUHJhc2FubmEuIEo=?=, Feb 5, 2004, in forum: ASP .Net
    Replies:
    3
    Views:
    2,314
    Kevin Spencer
    Feb 6, 2004
  3. Bob
    Replies:
    7
    Views:
    1,005
    Saravana [MVP]
    May 5, 2004
  4. Benny Ng
    Replies:
    9
    Views:
    10,248
    Benny Ng
    Oct 13, 2005
  5. CSharpner
    Replies:
    0
    Views:
    1,143
    CSharpner
    Apr 9, 2007
Loading...

Share This Page