I believe you may be right. getLoginUserID validates Managers based on isBackEnd() and the $_SESSION[’mgrInternalKey’] variable.
I’ve had a quick check through the bug tracker and can’t find a report for this, so can you log it please?
As for a fix, I think line 1794 of manager/includes/document.parser.class.inc.php has the answer
I would be inclined to agree; while we may want to keep web users out of the backend altogether, there are many occasions when we might want a manager user to be working throught the front-end.
Is this why only web users can see my restricted documents? I log in as admin with Manager Login but cannot access the restricted document. Shouldn’t admin have access to ALL documents whatever restrictions it might have?
Ok, so logging in from the ManagerLogin snippet would be rather useless if I would access restricted documents?
here’s my story (if interested)..
i’ve recently released my first major MODx website for a client *applause*. It works damn fine (for the visitor, that is) with it’s bells and whistles. I love making websites with MODx, really. However, it is this crucial issue i cannot figure out. I use ManagerLogin to let my client get access to QuickEdit. Works perfectly. But being a manager user he cannot access restricted documents which contain some custom scripts I made for him. The only way to access these secret pages is by being a web user. so I have to create a web user group in order to prevent the document being public. But since QuickEdit only works with manager users I must ditch the whole idea of web users.
To access these restricted documents at all I’ve set the documents access permissions to public. In other words, you don’t have to be Kevin Mitnick to hack this one. I’ve been messing around with manager permission and web users and vice versa, tried every combination and even tried to merge manager WebLogin with ManagerLogin without success (noob).
Is this a bug or am I? lol.
hehe, that wasn’t so hard after all. I had no idea that unpublishing was the solution. I thought if I’d unpublish them, they would not be accessable at all. Thanks for clearing that up! This CMS is just getting better and better, awesome.
regarding the synchronization, the plugin is called Web2Manager.