WebSite X5Help Center

 
Thomas Turner
Thomas Turner
User

Login Security Issue ...  en

Autor: Thomas Turner
Visited 1455, Followers 1, Udostępniony 0  

I have set up a successful login and password to access some webpages. The problem is the pages are named in the main menu. If you add the menu name to the url address you can access my links to data on the locked pages.

For Example: www.fruit.com (not a real site) would open the index.html or main page. On the main page I could have menu items Apples Bananas Peaches Oranges I have set up users with logins and passwords with various access to some or all menu items with no problems. Once in the user logs in he can access various items with links to other parts of the site. If the user clicks on a menu item that he is not authorized to access he is denied.

The problem is if a user enters the menu item name into the url IE: www.fruit.com/bananas - an index page of the bananas page is opened, which allows the users to access the data, even though the user doesn't have permission to access the bananas page.

Am I missing something?  Can I change the menu links to something other then the menu item name to prevent this?  If so where and how? 

Posted on the
1 ODPOWIEDZI
Incomedia
Claudio D.
Incomedia

Hello Thomas,

You can decide to have some pages not visible in the menu by choosing in Step 2 - Page not visible in the Menu. In any case if the page is set as private with login also if you have the direct link you cannot read the content without writing the username and password. The protected pages can be visible in the menu because the content is not visible until you log in.

If you require any further information, please feel free to write back.

Czytaj więcej
Posted on the from Claudio D.