Access Denied Redirect

Syntax

{
    "Key": "redirect:on:access-denied:<frontend|backend|api>",
    "Value": {
        "Type": "page_redirect|url_redirect|trigger_callback|default|custom_message|login_redirect",
        "Slug": "string",
        "Id": "numeric",
        "Url": "string",
        "Callback": "string",
        "Message": "string",
        "StatusCode": "numeric"
    }
}

The properties Slug, Id, Url, Callback, Message are required depending on the selected Type. For instance, if trigger_callback type is chosen, then the Callback property must also be provided.

For the Code property, these are the accepted HTTP status codes, depending on the Type:

Examples

This parameter defines the default behavior for redirecting access denied situations and displays a custom message “Sorry, this is a paid content” with HTTP status code 402.

{
    "Param": [
        {
            "Key": "redirect:on:access-denied:frontend",
            "Value": {
                "Type": "custom_message",
                "Message": "Sorry, this is a paid content",
                "StatusCode": 402
            }
        }
    ]
}

Definition

The access denied redirect behavior enables the customization of actions to take when a user’s request is denied access to a particular resource or action. This customization can be done separately for frontend and backend.

The Type attribute determines the type of redirect to apply and can take one of the following values:

Depending on the Type, additional information may be required to customize the redirect as follows:

Here is another example of the access denied redirect parameter for the backend area:

{
    "Param": [
        {
            "Key": "redirect:on:access-denied:backend",
            "Value": {
                "Type": "url_redirect",
                "Url": "/unauthorized-notification"
            }
        }
    ]
}