Donald Hessing

How to disable access for anonymous users on forms and application pages - ViewFormPagesLockDown

Recently I did a couple of projects on building public facing internet sites with MOSS 2007. I’ve noticed that for one specific project the application pages and the forms pages were accessible for anonymous users. Because of the fact that anonymous users have by default no rights on lists other than read, they can't do any harm to the site. But I didn't like the idea that anyone could read my reusable content or pages list just by requesting the url  http://myserver/pages/forms/allitems.aspx. In my search for an explanation, I found this excellent article from the SharePoint team blog. Public internet sites build on the publishing portal site definition have by default a feature called ViewFormPagesLockDown activated. The feature disables anonymous users to forms pages and most of the application pages. If you build your own site definition, this feature is not enabled by default. You still can disable anonymous access to these pages by activating the ViewFormPagesLockDown feature to the site collection of the public website. You can do this by running the following command on the site collection of the public site:

stsadm.exe –o activatefeature –url <site collection url> -filename ViewFormPagesLockdown\feature.xml
 

Comments

Mirjam's blog said:

If you are creating public web sites and anonymous users have access to the site all anonymous users

# December 27, 2007 4:08 PM

SHAREPOINTBlogs.com Mirror said:

If you are creating public web sites and anonymous users have access to the site all anonymous users

# December 27, 2007 4:09 PM

Links (12/27/2007) « Steve Pietrek’s SharePoint Stuff said:

Pingback from  Links (12/27/2007) &laquo; Steve Pietrek&#8217;s SharePoint Stuff

# December 28, 2007 2:41 AM

Jaap Steinvoorte said:

Hi Donald,

Finally started blogging! Congrats! I subscribed to your  rss already

# January 7, 2008 1:49 PM

lrfmdut said:

aytlqw  <a href="mitmmccptqrg.com/.../a>, [url=http://ocvtqotiheou.com/]ocvtqotiheou[/url], [link=http://pmrhdetvjsyl.com/]pmrhdetvjsyl[/link], http://mepfiwfjfxyg.com/

# May 1, 2008 4:34 PM

ubqqwuv said:

AieNya  <a href="vypvagjfvsmi.com/.../a>, [url=http://lbcfrahclvzj.com/]lbcfrahclvzj[/url], [link=http://ttyjrfdhfdkn.com/]ttyjrfdhfdkn[/link], http://xqvtgkwuyuxe.com/

# June 9, 2008 9:12 PM
Leave a Comment

(required) 

(required) 

(optional)

(required)