<system.web> <authentication mode="Forms"> <forms loginUrl="login.aspx" /> </authentication> <authorization> <deny users="?" /> </authorization> </system.web> 上面代码中deny uses="?"是根据哪里判断用户类型的? cookie?session?