Security :: Where Is The Right Place For Admin Page In Website
		
			Mar 1, 2011
				I am currently designing an ASP.Net web site where does not required any user login on the page. However, I do need to put an Admin page up along with this web page for my client use to manage the content on the page (e.g.: Change Pictures, Updating News). For security reason, I do not want to include a separate page sit reside in the site, so nobody can even try access to the page [URL]
	
	View 6 Replies
  
    
	Similar Messages:
	
    	
    	
        Dec 3, 2010
        I have a simple online store where there are products that can be put into a cart and purchased. There is a admin page that can be logged into so that new products can be added or existing products can be removed or edited. To get to the admin area I need to put a /admin/index after the main page loads up. If I want to give my friends (from any location) the ability to add new products should I create a link to the admin area on the main page (like at the bottom) of the main page or should I just tell them to type in /admin/index after they go to the webpage? 
	View 3 Replies
   
  
    
	
    	
    	
        Jun 10, 2010
        I have a secure admin section in my website, only logged in users can gain access to this section, its controlled from the web.config file like this
[Code]....
This has all works perfectly well until now.  Ive created a page that has an accordian control on it from the ajax control toolkit, as soon as I place this control on a page and run the web page, I get this error
	View 1 Replies
   
  
    
	
    	
    	
        Mar 4, 2010
        I have a directory structure root->admin-> admin operations admin page inherited from a ase page with principla security.demand role = "Admins" i am usinf forms authantication mode. i have also put a web.config file in admin folder, restricting other users. it is working normaly with siteroot/admin. I want to setup a mechanism to admin like siteroot/username/admin I can redirect to page admin but it gives security error, it should redirect to login page instead of if user did not sign in.
	View 5 Replies
   
  
    
	
    	
    	
        Jan 9, 2010
        access the page on public section of the website from the admin section,while logged in?Or i am causing a security hole,jumping like this?all admin section pages have role based authorization and can not be accessed unless authenticated.Public of course is accessible to anyone.
	View 6 Replies
   
  
    
	
    	
    	
        Jul 19, 2010
        In my web site I have a admin login page to edit the contents. Is it necessary that the default page has to be the login page..............Because in web.config file , under Authentication of Forms am using loginurl="MyLoginPage.aspx"......So is it compulsory that the Default.aspx =MyLoginPage.aspx.i mean to ask i should not change the name of default page or what?
	View 5 Replies
   
  
    
	
    	
    	
        Jan 9, 2010
        I've set up a login control on a Login.aspx web page, which is authenticated using xml.
How do I stop people visiting my admin.aspx page when they are not logged in?
	View 2 Replies
   
  
    
	
    	
    	
        Mar 31, 2011
        i want a simpe login systemm using webconfig file and one login.aspx page.
	View 3 Replies
   
  
    
	
    	
    	
        Apr 22, 2010
        I have a problem, its completely i dont why this happening.say i have site its workign most of  places.but when i'm check some place its going to custom error pagei'm using url rewriting handler, is it may be?
	View 1 Replies
   
  
    
	
    	
    	
        Nov 9, 2010
        Can anyone point me to a sample admin page for managing users and roles (forms authentication).  Something like the security section of the WSAT, but for a finished site.
	View 3 Replies
   
  
    
	
    	
    	
        Jan 26, 2010
        Is it possible to allow an administrator to write to a readonly profile property by redefining the profile property in a web.config file used for administrators pages? 
I have a unique account number which must be assigned to each new user (using the default asp.net membership provider). After reading a couple of articles it seemed it would just be easier to define it as a profile property instead of creating a custom membership provider. When the user makes changes to their profile on a profile page I create, I want the value to be readonly. When an admin views the profile I actually want them to assign the value to the property in their page.
	View 1 Replies
   
  
    
	
    	
    	
        Mar 13, 2011
        I have a default page which has a content place holder on it...It defaults to the master.aspx page.  Anyroad  I attempt to put the loginview there but I can't seem to resize it.  Is there something I'm doing wrong?  I also put an ajax control in the loggedintemplate and I can't seem to resize that properly either.
	View 5 Replies
   
  
    
	
    	
    	
        Jan 7, 2011
        I want to put my website project and admin website under same project as I want to use session and authentication of the main site. Also I want to show the admin, the page, where he has made changes. But the problem is whenever I will change anything in admin pages, I've to build the entire website. I don't want to do that. Can I build that separately?
I don't want to choose the option of building all pages separately as well.
Is there any alternatives of doing that. Separate projects for admin and website will come up with many other challenges. So I would like to avoid that.
	View 2 Replies
   
  
    
	
    	
    	
        Jan 22, 2011
        I can't get past the "Test" link on the "Provider" tab in my Web Site Admin Tool (WSAT).
I'm running SQL Express (10.0.2531.0) and have created my "ASPNETDB" database using the version of aspnet_regsql that came with .Net 2.0.  (When that work, I re-ran the version that came with 4.0.)
I have the following in my web.config:
[Code]....
And this:
[Code]....
When I go into the WSAT, to the Provider tab, I select "AspNetSqlProvider" and click test.
The error message I get is this:
Could not establish a connection to the database.
If you have not yet created the SQL Server database, exit the Web Site Administration tool, use the aspnet_regsql command-line utility to create and configure the database, and then return to this tool to set the provider.
	View 2 Replies
   
  
    
	
    	
    	
        Mar 22, 2011
        Working on my first asp.net webpage. i have followed video tutorials and implemented asp.net membership for login/security.Using Visual Studio 2010 i can open the Asp.net configuration page for management locally.But then if I want my site admin to manage users/security online, how is this done?   Like manage through a web browser. I guess this asp.net configuration GUI is not available on the internet?
	View 4 Replies
   
  
    
	
    	
    	
        Mar 11, 2011
        I am creating an application hosted on GoDaddy.com.  The base files are kept in a folder called /sky while the Admin files and User files are kept in /sky/Admin and /sky/User respectively.   I'm having difficulty configuring the security so that when a user tries to access Admin or User files they should be redirected to the login.aspx file in the /sky folder.  I keep getting an error that its trying to access sky/sky/login.aspx instead of just sky/login.aspx.
Here are the relevant sections of my web.config file.
<?xml version="1.0"?>
<configuration>
...
<location path="sky/admin">
<system.web>
<authorization>
<allow roles="Admin" />
<deny users="*"/>
</authorization>
</system.web>
</location>
<location path="user">
<system.web>
<authorization>
<allow roles="Admin,User" />
<deny users="*"/>
</authorization>
</system.web>
</location>
<system.web>
<customErrors mode="Off" />
<authentication mode="Forms">
<forms name="login" loginUrl="login.aspx" />
</authentication>
...
</system.web>
...
</configuration>
Can someone point me to articles or provide assistance with the proper configuration?
	View 3 Replies
   
  
    
	
    	
    	
        Oct 11, 2010
        How do you create your web site data admin for your customers. Do you do them programatically or do you use any specific tool?
I have been using AspMaker and is not a bad option but I'm sure there are a few more options out there. I've seen that MS has a Web Data Administrator but for me it looks more than an sql server web admin tool rather than a frontend that has the business logic.
	View 1 Replies
   
  
    
	
    	
    	
        May 25, 2010
        I have an asp.net website for a car dealership. I wanted to create an admin site where personel from the dealership can add and delete cars to the site. how do I get started? what shall I read up on? I've read some of the security knowledge to add login and user accounts and what not, but now I am after setting up the website to allow this. do I need a sub domain to allow this? is that the only way? the web hosting company I am using (discountasp.net) will make me pay more $5 a month to use sub domain
	View 4 Replies
   
  
    
	
    	
    	
        Jun 24, 2010
        I am planning to develop around 4 product catalogue websites. The functionality of all the websites would be same. however the design, images and css would be different.
All the 4 websites will use the same admin panel, forums and database(MS Access) also.
How should I create such a system.
I dont understand what kind of folder structure should I create.
I would like to create following kind of folder structure.
(Root Folder)Admin Website  ----> Website 1 (subfolder)
----> Website 2 (subfolder)
----> Website 3 (subfolder)
----> Website 4 (subfolder)
Root folder will have the database and all the common files.
Unfortunately, when I tried to create such structure, Dot Net Didnt allow me to create one website inside another
what kind of system should I use for maximum reusability.
I am a small time freelancer and cannot afford to build seperate websites for each of my client.
	View 4 Replies
   
  
    
	
    	
    	
        Sep 3, 2010
        i wanted to give an email option to the admin of a website where he can enter multiple email id's and a costamized text etc , and the sending message must be stored with the details of the timings and date and to whom in send.
	View 4 Replies
   
  
    
	
    	
    	
        Sep 16, 2010
        I am currently developing a website for a friend of mine who is a dj. I have a login page, which works fine however i want to inplement a menu that only users with the Administrator role can view. I have done alot of research and i have found ways to stop a user from visiting a page, when they click on it it takes the to the login page. But i want to completely hide the menu from Non Admins.
	View 4 Replies
   
  
    
	
    	
    	
        Sep 18, 2013
        i have designed a website in that i have image tool but the image must change  dynamically the changes is made in admin page.. by which tool we cn obtain that......
	View 1 Replies
   
  
    
	
    	
    	
        Sep 20, 2010
        I do know there are 2 types or rewrites setup for this site.
One I can locate and is solely responsible for top level rewrites (turning .com to .co.uk)
There is another rewriter implemented somehow somewhere, very early on in a pages lifecycle and I cannot find how or where the site is doing this. It's possible it's all handled in a 3rd party DLL but I would like to know the steps I might go through to prove or disprove this.
	View 3 Replies
   
  
    
	
    	
    	
        Dec 22, 2010
        have table for users have a some attribute one of them admin attribute have a bit data type when the user is admin it is true and i have ligin page and control panal page  i want throw login page check for the user to redirect him to control panal if the user is admin the control panal will be displayed with moreoptions  any one how can i doing this with select statement
	View 2 Replies
   
  
    
	
    	
    	
        Dec 12, 2010
        if I have this code:
How can I run the cmd using and admin rights? Is it possible to run the command using an admin name and password?
[Code]....
	View 1 Replies