Improve company productivity with a Business Account.Sign Up

x
  • Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 281
  • Last Modified:

IIs block files web.config

Via web.config we entered this to protect all the files:

	    <authorization>
      <deny users="?" />
      <allow users="*" />
    </authorization>

Open in new window


That thing works excellent blocking from all directories the anonymous users and allowing access to logged users but just for files like aspx if we try to access a jpg without login it can be accessed. How can make work that script to block all kind of files?

And we added a virtual a directory outside the webapp but the question here is how can we protect everything there also but configuring from  webapp not the real directory we don't want to protect from the real directory outside the webapp just we want to protect when the user tries to access via the webapp for example webapp/virualdir/pdf.pdf there protect the pdf if user is not logged.
0
Alex E.
Asked:
Alex E.
  • 3
  • 2
1 Solution
 
KarenAnalyst programmerCommented:
Delete the
<allow users="*" />
line. You only need

        <authorization>
            <deny users="?" />
        </authorization>
0
 
Dan McFaddenSystems EngineerCommented:
Here is a nice article that explains the <authorization> element.

Link:  https://weblogs.asp.net/gurusarkar/setting-authorization-rules-for-a-particular-page-or-folder-in-web-config

Here is the MSDN reference:  https://msdn.microsoft.com/en-us/library/wce3kxhd.aspx

An IIS Forum thread over issues with Authorization:  https://forums.iis.net/p/1173012/1961218.aspx

Dan
0
 
Alex E.Author Commented:
I removed:


<allow users="*" />

And we continue looking pdf, jpg files the rest fo the files are protected like aspx

What could be?
0
Creating Active Directory Users from a Text File

If your organization has a need to mass-create AD user accounts, watch this video to see how its done without the need for scripting or other unnecessary complexities.

 
Dan McFaddenSystems EngineerCommented:
How is your Application Pool configured?  What is the Managed Pipeline Mode?

Dan
0
 
Dan McFaddenSystems EngineerCommented:
I would also read thru this article, it discusses your issue in detail.

Link:  http://www.4guysfromrolla.com/articles/122408-1.aspx

Dan
0
 
Alex E.Author Commented:
Thank you
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

Featured Post

Free Tool: IP Lookup

Get more info about an IP address or domain name, such as organization, abuse contacts and geolocation.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

  • 3
  • 2
Tackle projects and never again get stuck behind a technical roadblock.
Join Now