【问题标题】:Redirect unauthorized users to a custom page error将未经授权的用户重定向到自定义页面错误
【发布时间】:2012-07-20 18:48:12
【问题描述】:

当未经授权的用户访问管理员页面时,我试图将他们重定向到自定义页面,但我遇到了错误..

管理员文件夹的Web.Config

<?xml version="1.0"?>
<configuration>
  <system.web>
    <authorization>
      <allow roles="Administrators" />
      <deny users="*"/>
    </authorization>
  </system.web>
</configuration>

登录页面代码:

protected void Page_Load(object sender, EventArgs e)
        {
            if (!Page.IsPostBack)
            {
                if (Request.IsAuthenticated && !string.IsNullOrEmpty(Request.QueryString["ReturnUrl"]))
                    Response.Redirect("~/ErrorUNTH.aspx");
            }
}

以普通用户身份登录并访问管理员页面后的错误:

Server Error in '/' Application.
Runtime Error
Description: An application error occurred on the server. The current custom error settings for this application prevent the details of the application error from being viewed remotely (for security reasons). It could, however, be viewed by browsers running on the local server machine.

Details: To enable the details of this specific error message to be viewable on remote machines, please create a <customErrors> tag within a "web.config" configuration file located in the root directory of the current web application. This <customErrors> tag should then have its "mode" attribute set to "Off".


<!-- Web.Config Configuration File -->

<configuration>
    <system.web>
        <customErrors mode="Off"/>
    </system.web>
</configuration>


Notes: The current error page you are seeing can be replaced by a custom error page by modifying the "defaultRedirect" attribute of the application's <customErrors> configuration tag to point to a custom error page URL.


<!-- Web.Config Configuration File -->

<configuration>
    <system.web>
        <customErrors mode="RemoteOnly" defaultRedirect="mycustompage.htm"/>
    </system.web>
</configuration>

【问题讨论】:

  • 您收到一般错误消息。关闭自定义错误 并将正确的错误消息附加到您的帖子中。
  • 我们无法猜测错误,您需要禁用自定义错误。在&lt;system.web&gt;下添加这个配置&lt;customErrors mode="RemoteOnly" /&gt;,让我们知道具体的错误。允许调试&lt;compilation debug="false"&gt; 也是一个好主意
  • 我这样做了,我得到了同样的错误

标签: c# asp.net


【解决方案1】:

删除&lt;deny users="*"/&gt;并添加&lt;deny users="?"/&gt;

  1. ? - 匿名用户
  2. * - 所有用户

并且还 删除 Page_Load 事件中的代码。

如果用户未登录,则会自动重定向到 login.aspx。看看根web.config 的&lt;authentication&gt; 部分。

<authentication mode="Forms">
        <forms loginUrl ="mylogin.aspx"/> <!-- You can change the url -->
</authentication>

【讨论】:

  • 是的,但我想在未经授权的情况下重定向到某个页面而不是登录页面
【解决方案2】:

您可以通过在 Global.asax.cs 的 Application_EndRequest 事件中添加以下代码来操纵“401 Access Denied”响应的内容(如果是这种情况):

protected void Application_EndRequest(Object sender, 
                                             EventArgs e)
  { 
     HttpContext context = HttpContext.Current;
     if (context.Response.Status.Substring(0,3).Equals("401"))
     {
        context.Response.ClearContent();
        context.Response.Write("<script language="javascript">" + 
                     "self.location='../login.aspx';</script>");
     } 
  }

当浏览器识别 401 并且没有凭据时,将发生客户端重定向。浏览器会显示一个自定义的 401 页面。

【讨论】:

    猜你喜欢
    • 2012-10-28
    • 1970-01-01
    • 1970-01-01
    • 2011-06-17
    • 1970-01-01
    • 1970-01-01
    • 1970-01-01
    • 1970-01-01
    • 1970-01-01
    相关资源
    最近更新 更多