Windows mode authentication - anonymous and authenticated accesson same page

Discussion in 'ASP .Net Security' started by Christoph Erdle, Jul 30, 2003.

  1. Hi,

    at the moment I'm developing a Web-Application with C# and encounter problems
    using Windows NTLM authentication with IIS 6.0 (W2k3EE).

    I use an aspx-page, in which depending on the user's authentication different
    content is provided. There's an area for anonymous access and one for
    authenticated users.

    In the code im checking the state of the authentication via the Property
    Page.User.Identity.IsAuthenticated. Hasn't the user been authenticated yet, all
    works fine, i get the parts for anonymous access. But if the user is
    authenticated, most of the time the user gets the parts for anonymous access,
    seldom the one for authenticated users (meening
    Page.User.Identity.IsAuthenticated is false most of the time).

    As this aspx-page has to grant both anonymous and authenticated access, i worked
    with the following web.config:

    <snip>
    <!-- Grant access to all files to all (anonymous and authenticated) users
    -->
    <authentication mode="Windows" />
    <authorization>
    <!-- Allow all users -->

    <allow users="*"/>

    </authorization>

    <!-- For the Page myPage.aspx special access control is required. So i added
    the users "user1" and "user2" to the list of allowed users on that page and
    replaced everybody with anonymous (* with ?)
    -->
    <location path="myPage.aspx">
    <system.web>
    <authorization>
    <allow users="?, user1, user2" roles="Users"/>
    </authorization>
    </system.web>
    </location>

    </snip>

    What's wrong in the web.config, as getting such weird results?

    Thanks for your help,
    Christoph Erdle
    --
    Life is very short and there's no time
    For fussing and fighting, my friends
    (The Beatles)
    Christoph Erdle, Jul 30, 2003
    #1
    1. Advertising

Want to reply to this thread or ask your own question?

It takes just 2 minutes to sign up (and it's free!). Just click the sign up button to choose a username and then you can ask your own questions on the forum.
Similar Threads
  1. =?Utf-8?B?QUFPTVRpbQ==?=
    Replies:
    1
    Views:
    511
    John Timney \( MVP \)
    May 17, 2006
  2. GeoffreyD
    Replies:
    2
    Views:
    516
    Steven Cheng[MSFT]
    Jan 29, 2008
  3. developer
    Replies:
    2
    Views:
    207
    [MSFT]
    Aug 31, 2004
  4. Gary K

    Anonymous & Authenticated Access (Together?)

    Gary K, Oct 26, 2004, in forum: ASP .Net Web Services
    Replies:
    1
    Views:
    116
    Gary K
    Oct 27, 2004
  5. Abhijit
    Replies:
    0
    Views:
    149
    Abhijit
    Apr 12, 2004
Loading...

Share This Page