Tuesday, August 18, 2009

SPSecurity.RunWithElevatedPrivileges - while using it with SPContext.Current.Web in sharepoint

Normally we will use SPSecurity.RunWithElevatedPrivileges() to execute some code that has to be run under some higher privileges.



Whenever we use SPSecurity.RunWithElevatedPrivileges(), it will execute the code under the context of Application Pool identity. Now we can see a scenario where we will get the “Access denied” exception from the code block even if you use SPSecurity.RunWithElevatedPrivileges.



This was the code snippet that I have used initially inside a custom webpart to read XML content from of an InfoPath form which was uploaded in a document library. This code will throw an “Access denied” exception while calling the OpenBinaryStream() method whenever I execute it through an Anonymous user account.



SPSecurity.RunWithElevatedPrivileges(delegate()

{

SPWeb oWeb = SPContext.Current.Web;

SPList oList = oWeb.Lists["InfoPathLib"];

SPListItem oListItem = oList.Items[0];

Stream oStream = oListItem.File.OpenBinaryStream();

StreamReader oReader = new StreamReader(oStream);

string strLine = "";



strLine = oReader.ReadLine();



oReader.Close();

oStream.Close();



oReader.Dispose();

oStream.Dispose();



lblFileContent.Text = strLine;



this.Controls.Add(lblFileContent);

});





Here the problem was, whenever we take the SPWeb instance using

SPWeb oWeb = SPContext.Current.Web;, then SPWeb instance still running under anonymous account only , because we are taking it through the current web context in which the current user is running under anonymous account (IUSR_MachineName). That was the reason that we got that “Access Denied” exception. We need to remember this point all time whenever we use RunWithElevatedPrivileges under the web context.



So what we need to that, we have to take the current context outside the SPSecurity.RunWithElevatedPrivileges block and then create a new instance of SPSite and SPWeb inside the that block which will run under application pool identity.



SPWeb oWeb1 = SPContext.Current.Web; // taking the current SPWeb context running under the anonymous account

SPSecurity.RunWithElevatedPrivileges(delegate()

{

using (SPSite oSite = new SPSite(oWeb1.Site.Url))

{

// creating a new SPSite running under Application pool idenity

using (SPWeb oWeb = oSite.OpenWeb())

{



SPList oList = oWeb.Lists["InfoPathLib"];



SPListItem oListItem = oList.Items[0];



Stream oStream = oListItem.File.OpenBinaryStream();



StreamReader oReader = new StreamReader(oStream);



string strLine = "";



strLine = oReader.ReadLine();



oReader.Close();



oStream.Close();



oReader.Dispose();



oStream.Dispose();



lblFileContent.Text = strLine;



this.Controls.Add(lblFileContent);

}

}



});

The above code will work fine and we can read the InfoPath document. So, please do not forget to create a new instance of SPSite and SPWeb inside SPSecurity.RunWithElevatedPrivileges,while using it in a web context.



Another work-around to this paritcular requirement (read the file content) is - use GetFileAsString() method of the SPWeb directly. And here there is no need to use the SPSecurity.RunWithElevatedPrivileges. Since, I have enabled anonymous authentication on this SharePoint web application it will allow to read the file using the below method under the context of anonymous account.

string strXML = SPContext.Current.Web.GetFileAsString("/FannyDocLib/Form1.xml");

Sunday, August 16, 2009

How to print web page in sharepoint



Add the above script to the page you want to give print function.Then you are done.

Friday, August 14, 2009

System.IO.FileNotFoundException: The Web application at http://-.-.-.- could not be found. Verify that you have typed the URL correctly. solution

System.IO.FileNotFoundException: The Web application at http://203.143.39.19 could not be found. Verify that you have typed the URL correctly. If the URL should be serving existing content, the system administrator may need to add a new request URL mapping to the intended application.

You can verify this error when you type the public url as http://xxx.xxx.xxx.xxx/ you can not access your your web site.

You may access it using your intranet access or local host.

Then go to Central Administration > Operations > Alternate Access Mappings

Then Edit Default and set your public IP as default.

Then gooooooo to http://xxx.xxx.xxx.xxx/

wow! you are there

How to hide global navigation tabs in application.master in sharepoint



Find the section (in the box in the image) in application.master (C:\Program Files\Common Files\Microsoft Shared\web server extensions\12\TEMPLATE\LAYOUTS).
Then add a div tag as shown including the above mentioned section and make it
visible false.Then you are done!

How to redirect to a custom search page from OSSearchResults.aspx search page


In SharePoint MOSS 2007, when you turn on the custom scope in site collection’s “Search Settings”, most of search results will be displayed at /SearchCenter/Pages/results.aspx. The exceptions are at the contextual search (This site, This List: Documents etc) and it always displays the search result in OSSearchResults.aspx page, which you can not customize through web parts (as you can do with /SearchCenter/Pages/restuls.aspx). This trick seems works very well (original post here):

Open OSSearchResult.aspx in layout folder, and add this block:



I added right after the stylesheet block and I guess you can remove some un-used code block since this page will not be used at all.

Hide "Sign in" Link from sharepoint pages for anonymous users



Hide the sign-in link on the Sharepoint sites except admin page
Did you want to hide the sign-in link on your SharePoint sites?
All you need to do is to locate the following code in your master page and hide or remove the tag:

Step 1:


This will hide the whole Welcome Panel when the page is displayed in the web browser. Donot remove the welcome.ascx control from the Controltemplate folder.
The welcome menu is part of the link itself. Its a whole functionality which is contained in welcome.ascx. So if you remove that, you will loose the menu too.

Step 2:

Create the ASPX for a admin user called adminlogin.aspx
Place the the following code in the ASPX page
The "Sign In" link available in the top-right corner of the Sharepoint site except
the admin page.

Configure sharepoint search for anonymous users - OSSSearchResults.aspx

If you have a public Sharepoint site (MOSS 2007 or WSS 3.0) that is accessible to anonymous users and you’re not using custom scopes, you probably already noticed that every time users try to search they get a user prompt. To get pass this prompt you must enter valid username, otherwise you’ll get famous “Access Denied” page. So much for anonymous access, right?

Anyway, the problem is with OSSSearchResults.aspx page, specifically with one of the inheritance reference that ASPX page. I’m talking about the part of the code that sets the inheritance of the page from the generic application page base class, which is not really required for this page to function properly.

To allow anonymous users to search your publicly available sites you need to remove that inheritance from the code, so find part of the code inside the Page tag that states “Inherits="Microsoft.SharePoint.WebControls.LayoutsPageBase" and remove that part of the code (not the whole line, just the part that inhertis the application page base.) OSSSearchResults.aspx page is usually stored at C:\Program Files\Common Files\Microsoft Shared\web server extensions\12\TEMPLATE\LAYOUTS on your SharePoint server. Make sure you backup the file before making any changes!

Making those changes will not only allow anonymous users to search the SharePoint content, but also will keep the SharePoint search secure, meaning that anonymous users will only be able to search the part of the SharePoint they have permissions to view.