close ad
 
Important WebAssist Announcement
open ad
View Menu

Technical Support Forums

Free, outstanding support from WebAssist and your colleagues

rating

URGENT! Problem with user authentication

Thread began 9/17/2012 5:41 am by richard402207 | Last modified 9/17/2012 1:48 pm by Jason Byrnes | 4167 views | 11 replies |

richard402207

URGENT! Problem with user authentication

I have recently purchased DataBridge and have created a site with a login page that then configures the users access based on their permissions (I have 3 different levels). This all works fine if you login and navigate to the pages. However if you know the url of a page and navigate to it directly you are able to gain access without logging in??? The user should be taken to the failed.php page. I obviously don't want to put the URL of the site on here as it would make it vunerable.

This is very urgent as there is sensitive information on the site.

Thanks

Sign in to reply to this post

Willi Schneider

Hi Richard

You say you've used Data Brdige to create the login pages.

Did you run the wizard "Security Assist --> Manage Site Access --> Access Pages Manager" from the Dreamweaver "Webassist" menu?

Did you check the "Remember my information" and/or "Log me in automatically" checkboxes on the login page?

Sign in to reply to this post

richard402207

Yes that is correct, no I removed the options to automatically login and remember me. The only field surfaced are email and password.

Sign in to reply to this post

richard402207

I have also delete my cache, removed cookies and session cookies. As well as testing on different machines

Sign in to reply to this post

Willi Schneider

Originally Said By: richard402207
  Yes that is correct, no I removed the options to automatically login and remember me. The only field surfaced are email and password.  



o.k., but did you also run the wizard, I mentioned above, to protect your admin pages?

Sign in to reply to this post

richard402207

Yes, I have also reviewed them using the pages manager and removed then re-applied them to see if that resolved the issue and I get nothing.

Sign in to reply to this post

Willi Schneider

Hi

You've posted your issue in the "User Registration Solution Pack"-Forum, so that's why I asked if you were using Data Bridge, as there might be a difference.

However, I've never used the "User Reg. Sol. Pack". So, there could be a different approach for this WA product.
I've found this link:

ursp_restricting_access.pdf

Maybe this helps you a bit.

P.S.: With Data Bridge I've never run into such an issue, except when checking the "log me in automatically" checkbox. Of course that wouldn't be a problem with the extension, but my own error, just forgetting about the cookies to log in automatically...

Sign in to reply to this post

Jason ByrnesWebAssist

Did you add the Access rule to protect the page?

Go to WebAssist -> Security Assist -> Mage Site Access -> Access Pages Manager. in the access pages manager, you can select the pages to protect and apply access rules.

if you have already applied the access rule to the page, what access rule are you using, and how was it defined?

Sign in to reply to this post

richard402207

Hi Jason,

Yes that is how I applied the rules. Please see the attached for more info.

Attached Files
BIDS_Detail.php.zip
Sign in to reply to this post

Jason ByrnesWebAssist

so your admin rule is using a Group as the comparison.


double check in the Admin group that you have not accidentally add an empty value.

Open the access groups manager to edit the Admin Group. try to click in the empty space at the bottom of the group participant list to make sure there is no an empty member of the group.

Sign in to reply to this post
loading

Build websites with a little help from your friends

Your friends over here at WebAssist! These Dreamweaver extensions will assist you in building unlimited, custom websites.

Build websites from already-built web applications

These out-of-the-box solutions provide you proven, tested applications that can be up and running now.  Build a store, a gallery, or a web-based email solution.

Want your website pre-built and hosted?

Close Windowclose

Rate your experience or provide feedback on this page

Account or customer service questions?
Please user our contact form.

Need technical support?
Please visit support to ask a question

Content

rating

Layout

rating

Ease of use

rating

security code refresh image

We do not respond to comments submitted from this page directly, but we do read and analyze any feedback and will use it to help make your experience better in the future.

Close Windowclose

We were unable to retrieve the attached file

Close Windowclose

Attach and remove files

add attachmentAdd attachment
Close Windowclose

Enter the URL you would like to link to in your post

Close Windowclose

This is how you use right click RTF editing

Enable right click RTF editing option allows you to add html markup into your tutorial such as images, bulleted lists, files and more...

-- click to close --

Uploading file...