Go Premium for a chance to win a PS4. Enter to Win

x
?
Solved

Site Map Data source

Posted on 2007-11-16
5
Medium Priority
?
214 Views
Last Modified: 2013-11-07
When I setup my sitemap in asp.net, how can I define within the site map that this particular menu should only be displayed if the person is logged in?

And in roles="*", what are the other possible values? How does that work?
0
Comment
Question by:Starr Duskk
  • 3
  • 2
5 Comments
 
LVL 16

Accepted Solution

by:
McExp earned 2000 total points
ID: 20300610
you would need to use Membership to control what the user has access to and then the SiteMap Menu will be security trimmed acordingly.

See the extract below from my web.config

      <location path="admin/Gallery">
            <system.web>
                  <authorization>
                        <allow roles="adminPhotos"/>
                        <deny users="*"/>
                  </authorization>
            </system.web>
      </location>

The above will only allow users who are in the role adminPhotos access to the area ~/admin/Gallery. All other things in the site (asp:Menu etc) will automatically security trim.
0
 
LVL 16

Expert Comment

by:McExp
ID: 20300634
How are your users logging into the site do you use Forms Auth?

I should have said you need to use Membership and RolesProviders and a Secured SiteMap, see bellow for another snip from my web.config

            <membership defaultProvider="AccessMembershipProvider">
                  <providers>
                        <clear/>
                        <add name="AccessMembershipProvider" type="Samples.AccessProviders.AccessMembershipProvider" connectionStringName="ASPNetDB" enablePasswordRetrieval="false" enablePasswordReset="true" requiresUniqueEmail="true" requiresQuestionAndAnswer="false" minRequiredPasswordLength="6" minRequiredNonalphanumericCharacters="0" applicationName="RAdmin" hashAlgorithmType="SHA1" passwordFormat="Hashed"/>
                  </providers>
            </membership>
            <roleManager enabled="true" cacheRolesInCookie="true" defaultProvider="AccessRoleProvider">
                  <providers>
                        <add connectionStringName="ASPNetDB" applicationName="RedsAdmin" name="AccessRoleProvider" type="Samples.AccessProviders.AccessRoleProvider"/>
                  </providers>
            </roleManager>
            <siteMap enabled="true" defaultProvider="SecuredSiteMapProvider">
                  <providers>
                        <clear/>
                        <add name="SecuredSiteMapProvider" description="Default SiteMap provider." type="System.Web.XmlSiteMapProvider " siteMapFile="Web.sitemap" securityTrimmingEnabled="true"/>
                  </providers>
            </siteMap>

As you can see I use the Access provider, if you are using Sql Server your code will differ slightly. However the concert still applies.
0
 
LVL 2

Author Comment

by:Starr Duskk
ID: 20301490
well, I guess I'll have to take your word for it, since I can't test it at this point. :)

thanks!
0
 
LVL 16

Expert Comment

by:McExp
ID: 20301650
As an alternative to this you can show/hide menu items in the Databound event of the asp:menu. in this you can use "User.Identity.IsAuthenticated" and you wouldn't need any of what I have suggested above. If you need more info, ask and I'll find the solution I have provided to others before.
0
 
LVL 2

Author Comment

by:Starr Duskk
ID: 20302230
Okay, I"ll open a new question. thanks!
0

Featured Post

Free Tool: IP Lookup

Get more info about an IP address or domain name, such as organization, abuse contacts and geolocation.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

It was really hard time for me to get the understanding of Delegates in C#. I went through many websites and articles but I found them very clumsy. After going through those sites, I noted down the points in a easy way so here I am sharing that unde…
In real business world data are crucial and sometimes data are shared among different information systems. Hence, an agreeable file transfer protocol need to be established.
We’ve all felt that sense of false security before—locking down external access to a database or component and feeling like we’ve done all we need to do to secure company data. But that feeling is fleeting. Attacks these days can happen in many w…
In a question here at Experts Exchange (https://www.experts-exchange.com/questions/29062564/Adobe-acrobat-reader-DC.html), a member asked how to create a signature in Adobe Acrobat Reader DC (the free Reader product, not the paid, full Acrobat produ…
Suggested Courses

963 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question