Crystal Reports 2021 Public Folder: Mixed‑Mode Anonymous Access Uncertainty
25K reputation · 28 Apr 2021, 05:12 UTC
Goal
Determine how the Public folder’s Allow Anonymous Access setting behaves when a Crystal Reports Server is configured for both HTTP and HTTPS access.
Context
Crystal Reports 2021 introduced a dedicated Public folder for web‑exposed reports. The folder’s default configuration permits anonymous access unless the Allow Anonymous Access toggle is explicitly disabled in the Server Administration console. In mixed‑mode deployments, the server may serve HTTP requests without prompting for credentials even when HTTPS requests are secured, raising the risk of accidental public exposure. Server logs do not clearly differentiate when anonymous access is bypassed, and there is no built‑in per‑report authentication enforcement within the Public folder.
Questions
- In a mixed‑mode deployment, does the Public folder’s
Allow Anonymous Accesssetting apply uniformly to both HTTP and HTTPS endpoints? - What server log entries indicate that anonymous access is being served for a report located in the Public folder?
- Is there a recommended configuration or workaround to enforce authentication on a per‑report basis within the Public folder in Crystal Reports 2021?