Is there a trick to using the unauthorized page on non-web contexts? On the 'web' context, I've used the following model successfully to display links to restricted pages, and display the "unauthorized" page when the anonymous user tries to view them:
- Grant "load/list" permissions to the anonymous user for the restricted Resource Group
- Anonymous user can see links to those resources, and sees the Unauthorized page (as defined by unauthorized_page when he/she clicks on them.
Is there something different I need to be doing on an alternative context? I've given the anonymous user load/list perms on the RG *for the new context*, but the resource in question isn't showing up in my nav menus for the anonymous user. Also, I have a plugin that runs on OnPageUnauthorized, and it isn't firing properly for requests from the new context - it is supposed to write a message to the error log that it is running, and I'm not seeing it for requests from this context.
What I do see for these pages, instead of seeing the unauthorized page, is "503 Error Page not found" in the content, and a 404 status.