# Endpoint access control not working?

**URL:** <https://forums.losant.com/t/endpoint-access-control-not-working/2560>\
**Category:** Help\
**Tags:** experience\
**Created:** [January 22, 2020, 1:32pm UTC](https://forums.losant.com/t/endpoint-access-control-not-working/2560 "2020-01-22T13:32:55Z")\
**Posts on this page:** 14\
**Page:** 1

<div class="post-metadata">

**Author:** ![Lars\_Andersson](https://avatars.discourse-cdn.com/v4/letter/l/f05b48/32.png) [@Lars\_Andersson](https://forums.losant.com/u/Lars_Andersson)\
**Post date:** [January 22, 2020, 1:32pm UTC](https://forums.losant.com/t/endpoint-access-control-not-working/2560/1 "2020-01-22T13:32:55Z")

</div>

I tried changing access control of a GET endpoint, but it doesn’t seem to work.  
A user in a group that is not defined in the Group field, still get access.

---

<div class="post-metadata">

**Author:** ![Lars\_Andersson](https://avatars.discourse-cdn.com/v4/letter/l/f05b48/32.png) [@Lars\_Andersson](https://forums.losant.com/u/Lars_Andersson)\
**Post date:** [January 22, 2020, 1:46pm UTC](https://forums.losant.com/t/endpoint-access-control-not-working/2560/2 "2020-01-22T13:46:21Z")

</div>

To add further information, this endpoint has the reply type set to an experience page.  
Maybe it has to be a “no static reply (use experience workflow to reply)” type to work?

---

<div class="post-metadata">

**Author:** ![anaptfox](https://sea1.discourse-cdn.com/flex015/user_avatar/forums.losant.com/anaptfox/32/873_2.png) [@anaptfox](https://forums.losant.com/u/anaptfox)\
**Post date:** [January 22, 2020, 2:24pm UTC](https://forums.losant.com/t/endpoint-access-control-not-working/2560/4 "2020-01-22T14:24:29Z")

</div>

@Lars_Andersson,

Unfortunately, I can’t reproduce this on my end.

However, there is an “Authorized Reply Type” and an “ **Unauthorized** Reply Type” Could you confirm that you have the correct behavior there?

Also, can you send a screenshot of your route configuration?

---

<div class="post-metadata">

**Author:** ![Lars\_Andersson](https://avatars.discourse-cdn.com/v4/letter/l/f05b48/32.png) [@Lars\_Andersson](https://forums.losant.com/u/Lars_Andersson)\
**Post date:** [January 22, 2020, 7:49pm UTC](https://forums.losant.com/t/endpoint-access-control-not-working/2560/6 "2020-01-22T19:49:10Z")

</div>

I think I do.  
will send screenshot as a PM

---

<div class="post-metadata">

**Author:** ![Lars\_Andersson](https://avatars.discourse-cdn.com/v4/letter/l/f05b48/32.png) [@Lars\_Andersson](https://forums.losant.com/u/Lars_Andersson)\
**Post date:** [January 22, 2020, 7:54pm UTC](https://forums.losant.com/t/endpoint-access-control-not-working/2560/8 "2020-01-22T19:54:32Z")

</div>

![image](https://us1.discourse-cdn.com/flex015/uploads/getstructure/original/2X/4/43665dd68149a99269b5d27e54c5a7719204f186.png)

---

<div class="post-metadata">

**Author:** ![anaptfox](https://sea1.discourse-cdn.com/flex015/user_avatar/forums.losant.com/anaptfox/32/873_2.png) [@anaptfox](https://forums.losant.com/u/anaptfox)\
**Post date:** [January 22, 2020, 8:26pm UTC](https://forums.losant.com/t/endpoint-access-control-not-working/2560/10 "2020-01-22T20:26:15Z")

</div>

@Lars_Andersson,

So, what should happen is, if a user is not apart of the groups you defined, and tries to access `/DSO`, it should redirect to `/login`.

What behavior are you seeing?

---

<div class="post-metadata">

**Author:** ![Lars\_Andersson](https://avatars.discourse-cdn.com/v4/letter/l/f05b48/32.png) [@Lars\_Andersson](https://forums.losant.com/u/Lars_Andersson)\
**Post date:** [January 22, 2020, 8:36pm UTC](https://forums.losant.com/t/endpoint-access-control-not-working/2560/11 "2020-01-22T20:36:14Z")

</div>

That’s what I was hoping it would do, but it’s taking me to the experience page anyway.

---

<div class="post-metadata">

**Author:** ![Lars\_Andersson](https://avatars.discourse-cdn.com/v4/letter/l/f05b48/32.png) [@Lars\_Andersson](https://forums.losant.com/u/Lars_Andersson)\
**Post date:** [January 22, 2020, 8:38pm UTC](https://forums.losant.com/t/endpoint-access-control-not-working/2560/13 "2020-01-22T20:38:28Z")

</div>

Correction, it does not take me to that experience page, instead it takes me to the Home page

---

<div class="post-metadata">

**Author:** ![anaptfox](https://sea1.discourse-cdn.com/flex015/user_avatar/forums.losant.com/anaptfox/32/873_2.png) [@anaptfox](https://forums.losant.com/u/anaptfox)\
**Post date:** [January 22, 2020, 8:43pm UTC](https://forums.losant.com/t/endpoint-access-control-not-working/2560/14 "2020-01-22T20:43:23Z")

</div>

@Lars_Andersson,

What is the URL of your home page?

---

<div class="post-metadata">

**Author:** ![Lars\_Andersson](https://avatars.discourse-cdn.com/v4/letter/l/f05b48/32.png) [@Lars\_Andersson](https://forums.losant.com/u/Lars_Andersson)\
**Post date:** [January 22, 2020, 8:44pm UTC](https://forums.losant.com/t/endpoint-access-control-not-working/2560/16 "2020-01-22T20:44:10Z")

</div>

[midmark.iotdiag.com](http://midmark.iotdiag.com)  
do I need to create a user for you to test?

---

<div class="post-metadata">

**Author:** ![anaptfox](https://sea1.discourse-cdn.com/flex015/user_avatar/forums.losant.com/anaptfox/32/873_2.png) [@anaptfox](https://forums.losant.com/u/anaptfox)\
**Post date:** [January 22, 2020, 8:44pm UTC](https://forums.losant.com/t/endpoint-access-control-not-working/2560/18 "2020-01-22T20:44:45Z")

</div>

@Lars_Andersson,

Yes, please do. Can you DM me with the credentials of the user?

---

<div class="post-metadata">

**Author:** ![Lars\_Andersson](https://avatars.discourse-cdn.com/v4/letter/l/f05b48/32.png) [@Lars\_Andersson](https://forums.losant.com/u/Lars_Andersson)\
**Post date:** [January 22, 2020, 8:52pm UTC](https://forums.losant.com/t/endpoint-access-control-not-working/2560/19 "2020-01-22T20:52:23Z")

</div>

I can’t seem to find how to send a DM

---

<div class="post-metadata">

**Author:** ![anaptfox](https://sea1.discourse-cdn.com/flex015/user_avatar/forums.losant.com/anaptfox/32/873_2.png) [@anaptfox](https://forums.losant.com/u/anaptfox)\
**Post date:** [January 22, 2020, 8:55pm UTC](https://forums.losant.com/t/endpoint-access-control-not-working/2560/20 "2020-01-22T20:55:42Z")

</div>

@Lars_Andersson,

No worries, I think may have what’s going on.

You’re route is redirecting to `/login` when unauthorized. However, after redirecting to `/login`, what happens?

Would you happen to be redirecting a user trying to access `/login` to `/` if they are authorized?

---

<div class="post-metadata">

**Author:** ![Lars\_Andersson](https://avatars.discourse-cdn.com/v4/letter/l/f05b48/32.png) [@Lars\_Andersson](https://forums.losant.com/u/Lars_Andersson)\
**Post date:** [January 22, 2020, 8:59pm UTC](https://forums.losant.com/t/endpoint-access-control-not-working/2560/21 "2020-01-22T20:59:33Z")

</div>

Yes, I think that’s what happening.

By the Way, I found how to send a DM, but it told me you are not accepting messages at this time.
