Forms Authentication Ignoring Default Document

Viewed 23142

I have spent a day and a half trying to resolve this issue. Bascially have an ASP.net website with Forms Authentication on IIS7 using Framework 4.0.

The Authorization stuff seems to be working perfectly for every scenario with the exception of hitting it with no document specifed (Should resolve to Default Doc).

For example (Please don't be harsh on site its still be developed ;) ), http://www.rewardroster.com/Default.aspx works perfectly, this page should allow anon access as specified in the web.config.

but if I hit www.rewardroster.com Directly it redirects to the login page with Return URL set to "/" or Login.aspx?ReturnUrl=%2f

Some things I have tried:

1) Set Authentication to None and then the Default document worked so thats not the issue.

2) Added DefaultDocument attribute to Web.config

3) Deleted all entries for in Default Document list in IIS except for Default.aspx

4) Added MachineKey entry in Config

5) Toggled from Integrated to Classic pipeline in IIS

Here is what's in my config:

  <authentication mode="Forms">
    <forms name="appNameAuth" loginUrl="Login.aspx" protection="All" timeout="60" slidingExpiration="true" defaultUrl="Default.aspx" path="/">
    </forms>
  </authentication>
  </authentication>

 <location path="Default.aspx">

Thanks so much for your time and hope someone knows what is going on here.

8 Answers

I had a similar problem today. I was trying use the integrated pipeline to secure non-asp.net resources (static files, php, etc.).

I had a rule in my root web.config that had , then I was allowing access to specific resources on a case by case basis.

This worked except that requests to "/" could never be authenticated (endlessly redirecting to the login page), while requests to "/Default.aspx" were fine.

My problem was because the Asp.Net UrlAuthentication module was enabled for all resource types, and apparently this doesn't work for my scenario. Instead I had to change that module to work for managed resources only and install IIS7's non-managed url authentication. I then had to configure that (since it uses different authentication settings), and make sure that the RoleManager was enabled for non-managed resources (since I was authenticating on roles). This URL might be helpful: http://learn.iis.net/page.aspx/142/understanding-iis-70-url-authorization/

I solved this by add read, Read & Execute, List Folder Contents permissions to IUSR user in windows server 2019 and IIS 10

Related