What can users find on your public-facing SharePoint site?
I recently found a blog post by Rich Finn that discussed activating the ViewFormPagesLockDown feature when using SharePoint as a public-facing Internet site. This feature is only available in MOSS and blocks anonymous access users from seeing form pages such as EditForm.aspx and DispForm.aspx and also blocks anonymous access to any pages residing in the _layouts folders that inherit from LayoutsPageBase.
By default, a publishing portal site will have this feature activated but the collaboration portal site definition does not. Rich's post contains a nice link that does a live search of the many sites that do not have this feature activated.
It is definitely something you will want to double check to make sure that your pubic-facing site is locked down so anonymouse users can't access pages they shouldn't.
Labels: blocking anonymous access to layouts pages, ViewFormPagesLockDown feature
0 Comments:
Post a Comment
Subscribe to Post Comments [Atom]
<< Home