Friday 26 September 2014

SharePoint 2013 | View post on anonymous blog asking for auth?

So, SharePoint 2013 has a lovely feature that is automatically enabled when a site or at-least parts of a site are set to allow anonymous access, this feature is "Limited-access user permission lockdown mode" it stops anonymous users from seeing SP system pages, it is a very useful security feature and in previous versions of SP, it is automatically disabled when the site is set to allow anonymous, 2013 being a more security conscious beast sets it by default.

Why is this an issue? a blog is just a normal site with pages in a library? not so!

A blog site consists of 

  1. a homepage (viewable with anon, perfectly fine)
  2. a Comments list (adding comments as anonymous is also fun and games!)
  3. a Posts list (all blog articles are posts, and here is where the problem lies, clicking on a post on the homepage takes the user to the "view form" for that list item, hence a system page! so it is automatically locked down

So with this you really have two options:

  1. Disable the “Limited-access user permission lockdown mode” Site Collection Feature (see the side effects below)
  2. Create a custom view and list web part, all in a pages library

Both options are valid but choose carefully, they both entail extra work, disabling the lockdown feature does the following:

Allows list pages and system pages applicable to a read user to be viewable anonymously, so a user can navigate to those pages and see the lists, all left hand nav panels will show Site Contents and any other previously restricted links, so you end up needing to hide the links and need to be wary of anonymous visitors seeing your sites lists and libraries

No comments:

Post a Comment