Installation and deployment
Version 3.x > Installation and deployment > Authentication and Access Denied View modes: 
User avatar
Member
Member
SKinley - 1/15/2009 2:37:41 PM
   
Authentication and Access Denied
I've installed the free version of CMS v3.1 and I'm having a security issue.

If I click on the My Account menu item, it redirects me to the Logon page, no problem. But, after I register and then login I get an "access denied" error message for the My Account page. Obviously, I've set the "Requires Authentication" setting to yes.

What's strange is that in the Fourms setting, I've selected "only authenticated users." If I navigate to the forums from the access denied page, I see the options to add a new thread, etc. So, this tells me that the authentication process itself seems to be working and that the issue I'm having above must be separate from this.

Any help or advice is greatly appreciated.

Thanks in advance,

Sean

User avatar
Kentico Support
Kentico Support
kentico_jurajo - 1/16/2009 4:32:30 AM
   
RE:Authentication and Access Denied
Hi,

It seems that your user account or user role has no sufficient permissions for appropriate document - http://www.kentico.com/docs/devguide/displaying_personalized_conten.htm. You need to grant with access your user account/role.

Best Regards,
Juraj Ondrus

User avatar
Member
Member
sean.kinley-techfringe - 1/16/2009 6:28:51 AM
   
RE:Authentication and Access Denied
Juraj, thanks for your reply. As I mentioned, I'm using the free version. I just double checked that feature matrix on your site and noticed that personlization doesn't appear to be available in the free version. Please confirm that this is accurate.

Sean

User avatar
Kentico Support
Kentico Support
kentico_jurajo - 1/16/2009 7:55:51 AM
   
RE:Authentication and Access Denied
Hi again,

Yes, the information is accurate. I assume that you are trying this on the sample corporate site in the partners section. If yes, please note that here is implemented the document level security as an example, but you do not have permissions to modify it so you cannot change it.

One more idea: if it is in the partners section, could you please add your user to Gold or Silver partners role?

Best Regards,
Juraj Ondrus

User avatar
Member
Member
sean.kinley-techfringe - 1/16/2009 9:50:21 AM
   
RE:Authentication and Access Denied
Ok, based on your idea, I went back and recreated the sample site from scratch. Then, I added the user to Gold Partners. When I click on Parters in the menu, I get access denied. What am I missing?

User avatar
Member
Member
sean.kinley-techfringe - 1/16/2009 9:52:50 AM
   
RE:Authentication and Access Denied
I forgot to mention that when I first clicked on the Partners link, I was prompted to login first. After I logged in, I was met with the access denied message.

User avatar
Kentico Support
Kentico Support
kentico_jurajo - 1/19/2009 8:15:57 AM
   
RE:Authentication and Access Denied
Hi again,

I am sorry for the confusion. I discussed this with our developer - this is the behavior in Free edition. The document level properties are not available so you will always get access denied since they are not checked. I am sorry for the inconvenience.


Best Regards,
Juraj Ondrus

User avatar
Member
Member
Elijah - 3/20/2009 12:01:49 PM
   
RE:Authentication and Access Denied
Juraj,
Is a fix planned? On the feature matrix, the Free edition is stated to have "User registration and secured pages."

This works for the global administrator, but not for other users. That's a bit misleading. In fact, its causing a problem in a site I'm in the middle of for a client. I'm going to have to spend $750 to get around this issue?

User avatar
Member
Member
sean.kinley-techfringe - 3/20/2009 12:10:07 PM
   
RE:Authentication and Access Denied
I implemented a work around for this...I assigned users to the CMS Editors group. In this case, I wasn't too worried about overall security of the user base. Not sure if this helps you.


User avatar
Member
Member
clarence-tomms.com - 1/17/2011 2:14:26 AM
   
RE:Authentication and Access Denied
Hi Sean,

How do you go about assigning the users to CMS Editor? I know it is done by assigning to role in administration. But the problem is when a new users login and register he gt an access error denied page which is uit confusion. By right it should say you have sucessfully register. How do you do this?
Thanks.

User avatar
Kentico Support
Kentico Support
kentico_jurajo - 1/19/2011 3:48:58 AM
   
RE:Authentication and Access Denied
Hi,

The registration form web part has a property "Assign user to roles:" where you can specify to which roles should the user be assigned to after registration.

Best regards,
Juraj Ondrus

User avatar
Kentico Support
Kentico Support
kentico_jurajo - 3/23/2009 5:24:42 AM
   
RE:Authentication and Access Denied
Hi,

The feature matrix is correct - you can set the page to require authentication, so the user have to be registered. But you cannot use the document level security to distinguish the users by roles and add appropriate permissions for different documents.

Best Regards,
Juraj Ondrus