Deny web access to a directory?

From: david (david_at_discussions.microsoft.com)
Date: 09/29/04

  • Next message: Dominick Baier: "Deny web access to a directory?"
    Date: Tue, 28 Sep 2004 18:35:14 -0700
    
    

    Hi,

    I have a asp.net site running on an MS Access database this is, for better
    or worse, stored under the webroot.

    How can I lockout the database directory to prevent anyone from downloading
    it via HTTP?

    I have attached my web.config file at the end of this message.

    The problem is that the "database" directory is still viewable by anyone.
    Not sure why. Do I have a typo?

    Thanks,
    David

    ---------------------------------------------

    <configuration>

    <system.web>
     <customErrors mode="Off"/>
      
     <!-- Authentication form -->
     <authentication mode="Forms">
      <forms name=".ASPXAUTH" loginUrl="app-admin/Login.aspx" protection="All"
    timeout="999999" path="/app-admin/" />
      </authentication>
      
      <!-- Allow anon users to main site -->
      <authorization>
       <allow users="?" />
      </authorization>
     </system.web>
       
     <!-- Set up secure zone for app admin -->
     <location path="app-admin">
      <system.web>
      
       <!-- disallow anon users-->
       <authorization>
        <deny users="?" />
        </authorization>
       </system.web>
      </location>
      
     <!-- Set up secure zone for database -->
     <location path="database">
      <system.web>
      
       <!-- disallow all users-->
       <authorization>
        <deny users="*" />
       </authorization>
      </system.web>
     </location>
       
    </configuration>


  • Next message: Dominick Baier: "Deny web access to a directory?"

    Relevant Pages

    • Deny all web access to a directory? (Searched the net already...)
      ... How can I lockout the database directory to prevent anyone from downloading ... the mdb file via HTTP? ...
      (microsoft.public.dotnet.framework.aspnet)
    • Re: How to update data inside a text file in Java ?
      ... Actually I used database in the server side. ... database in client will bias the target. ... authorization of the user is ...
      (comp.lang.java.programmer)
    • Re: How to update data inside a text file in Java ?
      ... I'm not using database, ... authorized the user when the network connection is down. ... database in client will bias the target. ... authorization of the user is ...
      (comp.lang.java.programmer)
    • Re: How to update data inside a text file in Java ?
      ... I'm not using database, ... authorized the user when the network connection is down. ... database in client will bias the target. ... authorization of the user is ...
      (comp.lang.java.programmer)
    • Re: Access control
      ... At the moment I'm trying to create an Access control system (the ... the authorizations for the user and created an array of authorized ... authorization array, ... should the database look and how do I retrieve the information needed? ...
      (comp.lang.php)