Search This Blog

Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

Tuesday, June 14, 2011

Blocking access to application pages (_layouts) and Forms Pages

All the pages having _layouts before them are application pages. Pages created automatically for various views are called Form Pages. Most often with SharePoint implementation we allow users to access these pages. However we may further want to cut down access of users from the application pages and the form pages.

SharePoint allows this by enabling the feature “ViewFormPagesLockDown”. This feature is activated at the Site Collection scope. All groups / users not having the “View Application Pages” permission will not be able to navigate to pages like “_layouts/viewlsts.aspx” or “pages/forms/allitems.aspx”.
Below are the steps to block access from application pages:

  1. Identify users / group to restrict.
  2. Set their permission to "Restricted Read" or remove the "View Application Pages" from existing assigned permission level.
  3. Enable "ViewFormPagesLockDown" feature using the command - stsadm -o activatefeature -url "SiteCollectionURL" -filename ViewFormPagesLockDown\feature.xml
The above steps will block all users not having "View Application Pages" permission from accessing the application pages and form pages.

Saturday, February 26, 2011

Solution to error "Security Validation for this page is invalid"

Few days back I came across this issue. It popped up whenever the page is posted back to update content to the site. On further digging into it I found this was somewhat related to the action performed within elevated code(i.e. code within SPSecurity.RunWithElevatedPrivileges).

SharePoint keep track of the requests using the token unique to the user and his request. Whenever the code is elevated the context is changed from the user to the system account.


To ensure smooth operation without the Security Validation error we should add SPUtility.ValidateFormDigest() line just before elevating the code. This MSDN article also talks about the same.

Saturday, October 2, 2010

Learn how to make web apps more secure


Learn how to make web apps more
secure. Do the Gruyere codelab.

Deny User's access to the entire portal / Web Application

We may have a requirement to block a specific user from entire SharePoint portal. How could we achieve this? What possible solution do we have?

One of the possible solutions is to remove the user from each and every group he is member of. Also remove any direct permission given to him in any of the sub site. But this would be very tedious task if there is large number of sub sites.

Even if we manage to do the task of manually going around in each and every site, there is a catch. What if one of the groups takes all member of the domain as it member? Yes this can happen. At the time of adding users to the group there is option to add all authenticated user to the group. To be specific we will have to add "NT AUTHORITY\authenticated users" to add all users to the group.

In such a scenario, even if we remove the permission of the user from each sub site, even if we remove the user from all groups. Still the user will have access to the portal due to the above action taken in the last paragraph.

Now what?

Don't Panic! There is simple and quick solution to the problem.

  1. Open up your Central Administration
  2. Navigate to the Application Management Tab
  3. Under Application Security Section click on the "Policy for web application link"
  4. Select appropriate Web Application to which user access should be denied.
  5. Click Add Users
  6. Select appropriate zone (Default is "All Zone") from which the user should be removed. Click Next.
  7. Now in the people picker add the user(s) you may want to deny access.
  8. Under Permission section, click on "Deny All"
  9. Press Finish.

That's all folks. Now let the user access the portal. He will be greeted with a sweet message "Access Denied".