Access Denied Redirect
Syntax
{
"Key": "redirect:on:access-denied:<frontend|backend|api>",
"Value": {
"Type": "page_redirect|url_redirect|trigger_callback|default|custom_message|login_redirect",
"Slug": "string",
"Id": "numeric",
"Url": "string",
"Callback": "string",
"Message": "string",
"StatusCode": "numeric"
}
}
The properties Slug, Id, Url, Callback, Message are required depending on the selected Type. For instance, if trigger_callback type is chosen, then the Callback property must also be provided.
For the Code property, these are the accepted HTTP status codes, depending on the Type:
default: 4xx, 5xxcustom_message: 4xx, 5xxpage_redirect: 3xxurl_redirect: 3xxlogin_redirect: does not accept codestrigger_callback: 3xx, 4xx, 5xx
Examples
This parameter defines the default behavior for redirecting access denied situations and displays a custom message “Sorry, this is a paid content” with HTTP status code 402.
{
"Param": [
{
"Key": "redirect:on:access-denied:frontend",
"Value": {
"Type": "custom_message",
"Message": "Sorry, this is a paid content",
"StatusCode": 402
}
}
]
}
Definition
The access denied redirect behavior enables the customization of actions to take when a user’s request is denied access to a particular resource or action. This customization can be done separately for frontend and backend.
The Type attribute determines the type of redirect to apply and can take one of the following values:
page_redirect: Redirect to an existing page.url_redirect: Safely redirect to a URL.custom_message: Display a custom plain or HTML message.login_redirect: If the user is not authenticated, redirect them to the login page, and upon successful authentication, redirect them back to the original location.trigger_callback: Invoke a custom PHP function that handles redirects.default: Show the “Access Denied” message.
Depending on the Type, additional information may be required to customize the redirect as follows:
- For
page_redirect, provide either the page slug or page ID for the destination page. It is recommended to use page slugs for readability. - For
url_redirect, provide a valid URL. However, AAM utilizes WordPress core safe redirect for security and compliance reasons. You can find more information about this in the blog post “What is a safe redirect in WordPress?”. - For
trigger_callback, a valid PHP callback function is required. AAM does not validate if the provided function exists. - For
custom_message, provide either plain text or valid HTML.
Here is another example of the access denied redirect parameter for the backend area:
{
"Param": [
{
"Key": "redirect:on:access-denied:backend",
"Value": {
"Type": "url_redirect",
"Url": "/unauthorized-notification"
}
}
]
}