现在的位置: 首页 > 综合 > 正文

How to restrict access to the CMS Desk for non-authenticated users

2013年08月01日 ⁄ 综合 ⁄ 共 1144字 ⁄ 字号 评论关闭

原帖地址:http://devnet.kentico.com/Knowledge-Base/Security-and-Permissions/How-to-restrict-access-to-the-CMS-Desk-for-non-aut.aspx

This article gives you instructions on how to restrict access to the CMS Desk (or to any other area within Kentico CMS) for non-authenticated users:

This article is based on our documentation and it takes advantage of the approach mentioned in following article in point 4 -> Securing
the CMSHelp folder
.

So, please edit your web.config file as described in the mentioned article and update as below:

1
2
3
<authentication
mode=
"Forms">
     <forms
loginUrl=
"~/"

defaultUrl=
"Default.aspx"

name=
".ASPXFORMSAUTH"

timeout=
"60000"

slidingExpiration=
"true"

/>
</authentication>



As the loginUrl you can use the landing page or the 404 page as you need.

1
2
3
4
5
6
7
8
<location
path=
"CMSDesk">
        <system.web>
            <authorization>
                <allow
roles=
"_authenticated_"/>
                <deny
users=
"*"/>
            </authorization>
        </system.web>
</location>



With this configuration, only authenticated users will be able to access the CMS Desk including the CMS Desk logon page.  So obviously you will need to create your own logon page (or use the one you have probably already added on your page) and
let your editors sign in using this logon page instead. 

抱歉!评论已关闭.