This question has been answered by BobRay. See the first response.
switch($modx->event->name) {
case 'OnUserSave':
/* sudo prevention code */
break;
case 'OnDocFormPrerender': // or whatever the original even was
/* your existing code */
break;
default:
break;
}
return;Have you tested that? At one time I saw some code that restricted the conditions to set the 'sudo' field, but I can't remember where it was.
If necessary, you could add another plugin attached to onUserSave, that unset the sudo field if the current $modx->user is not qualified. You could check by user group or by User ID.
You could also refactor the current plugin to respond to both events and separate the code with:
switch($modx->event->name) { case 'OnUserSave': /* sudo prevention code */ break; case 'OnDocFormPrerender': // or whatever the original even was /* your existing code */ break; default: break; } return;
and Ditto...
#ext-gen149 {
display:none;
}switch($modx->event->name) {
case 'OnUserSave':
/* sudo prevention code - only admins can set the sudo field */
if (! $modx->user->isMember('Administrator')) {
$user->set('sudo', '0');
}
break;
case 'OnDocFormPrerender': // or whatever the original event was
/* your existing plugin code */
break;
default:
break;
}
return;
On my install, this CSS would hide the div containing the sudo field. The number might be different on yours (use Firefox ctrl-shift-i and inspect that form field to make sure).
#ext-gen149 { display:none; }
You can hide the System Settings icon the same way: http://bobsguides.com/blog.html/2016/09/15/hiding-the-system-menu/
For increased safety, as per my suggestion above - this may need to be modified to meet your needs:
switch($modx->event->name) { case 'OnUserSave': /* sudo prevention code - only admins can set the sudo field */ if (! $modx->user->isMember('Administrator')) { $user->set('sudo', '0'); } break; case 'OnDocFormPrerender': // or whatever the original event was /* your existing plugin code */ break; default: break; } return;
/* sudo prevention code - only admins can set the sudo field */
if (! $modx->user->isMember('Administrator')) {
$user->set('sudo', '0');
}
return;
/* sudo prevention code - only admins can set the sudo field */
if (! $modx->user->isMember('Administrator')) {
$user->set('sudo', '0');
$user->save();
}
return;My bad. I forgot the save.
/* sudo prevention code - only admins can set the sudo field */ if (! $modx->user->isMember('Administrator')) { $user->set('sudo', '0'); $user->save(); } return;