views:

78

answers:

2

If I wanted to make sure that AUTHENTICATED users were denied access to Enroll.aspx and UNAUTHENTICATED users had access how should my "allow/deny users" tags be set in the web.config?

<location path="Enroll.aspx">
    <system.web>
      <authorization>
        <allow users = "?" />
        <deny users = "?" />
      </authorization>
    </system.web>
</location>
+2  A: 

Did you try this?

<authorization>
<allow users = "?" />
<deny users = "*" />
</authorization> 

Allow anonymous users, deny everyone else.

Greg
Nope... seemed to obvious. I thought the deny users = "*" would deny everyone.
John H.
+2  A: 
<allow users="?" />
<deny users="*" />

Should do the trick

Biff MaGriff