Search code examples

ASP.NET Role based access

I have the following site structure:

enter image description here

What I'd expect this to do was to deny anyone who isn't a logged-in user with the RegisteredUser role, except on Reset.aspx and Validation.aspx, where it would allow anyone (logged-in or not) to access, but this isn't the case right now.

Everyone who isn't a RegisteredUser isn't able to access these two pages, what am I doing wrong?

Update Even this won't work:

<?xml version="1.0"?>

  <location path="Reset.aspx">
        <allow users="*" />

  <location path="Validation.aspx">
        <allow users="*" />

It doesn't make any sense, isn't this supposed to be the system default?


  • You do not need to map paths, only file names:

    <?xml version="1.0"?>
      <location path="Reset.aspx">
            <allow users="*" />
            <deny />
      <location path="Validation.aspx">
            <allow users="*" />
          <allow roles="RegisteredUser" />
          <deny users="*" />