-
☆ A M B ☆
- 24,524 Posts
How does one make a page (web context only) protected? I've followed the
RTFM three times, with and without the Wizard, and I might as well have not wasted the time. Different browser, same browser logged out of the Manager, no problem viewing the supposedly protected page.
Does anybody know of reliable, up-to-date, step-by-step instructions on how to do this? Apparently I've contracted a serious case of stupidity.
1. Put the page in a Resource Group
2. Create a Resource Group Access ACL entry connecting that Resource Group to the Administrator User Group with a context of 'web'
Flush permissions
Flush all sessions
That should protect it from anyone outside of the Administrator group unless they have their own RG Access ACL entry granting them access.
BTW, if there is an AllDocs group and a Resource Group Access ACL entry giving the anonymous user group access to it, that will defeat your attempts to hide it.
-
☆ A M B ☆
- 24,524 Posts
No, this is just a bare localhost new installation with Login installed, to study working with users. For some reason I just can't get it to work.
On resource, one resource group.
One user group, definitely connected to the resource group, with "Resource" policy. At this point anonymous user shouldn't be able to view it, right?
I've given the Anonymous group load-only permissions to the Protected resource group.
-
☆ A M B ☆
- 24,524 Posts
Ok. One more time, and it's working as expected now. I must have missed something last night. Probably had a mgr context or something somewhere.