We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 52804
    • 36 Posts
    I'm trying to create an access policy which will allow a user permissions to add/edit/delete users from a different user group. The scenario is a customer registers in the front end and is added to User Group A. Then an editor logs in to review the customers profile and activate it.

    The trouble is I don't want the editor to be able to view or edit any users apart from the ones in User Group A. Whatever combination of permissions I've tried it seems to list all users from all groups including the admin...

    Could anyone point me in the right direction please?

    This question has been answered by BobRay. See the first response.

      • 3749
      • 24,544 Posts
      Sadly, users either have access_permissions permission or they don't. If they do, they can modify any user (including you), potentially changing usernames, passwords, and even sudo status.

      Depending on the details of your situation, this blog article on a very cleve technique created by Bruno Perner (Bruno17) might help.
        Did I help you? Buy me a beer
        Get my Book: MODX:The Official Guide
        MODX info for everyone: http://bobsguides.com/modx.html
        My MODX Extras
        Bob's Guides is now hosted at A2 MODX Hosting
        • 52804
        • 36 Posts
        Thanks Bob... I tried it and it's very clever and a great step in the right direction. Only problem is, it doesn't seem possible to allow an Editor to activate or deacativate a user in their primary group without checking "save_user" in the ACL. This in turn gives the editor permission to make themselves or anyone else in their primary group a SUDO user - Unless I'm missing something?
          • 3749
          • 24,544 Posts
          Have you tested that? At one time I saw some code that restricted the conditions to set the 'sudo' field, but I can't remember where it was.

          If necessary, you could add another plugin attached to onUserSave, that unset the sudo field if the current $modx->user is not qualified. You could check by user group or by User ID.

          You could also refactor the current plugin to respond to both events and separate the code with:

          switch($modx->event->name) {
              case 'OnUserSave':
                /* sudo prevention code */
                break;
          
              case 'OnDocFormPrerender':  // or whatever the original even was
                /* your existing code */
                break;
              
              default:
                break;
          }
          
          return;


          [ed. note: BobRay last edited this post 9 years, 9 months ago.]
            Did I help you? Buy me a beer
            Get my Book: MODX:The Official Guide
            MODX info for everyone: http://bobsguides.com/modx.html
            My MODX Extras
            Bob's Guides is now hosted at A2 MODX Hosting
            • 52804
            • 36 Posts
            Quote from: BobRay at Dec 05, 2016, 01:29 PM
            Have you tested that? At one time I saw some code that restricted the conditions to set the 'sudo' field, but I can't remember where it was.

            If necessary, you could add another plugin attached to onUserSave, that unset the sudo field if the current $modx->user is not qualified. You could check by user group or by User ID.

            You could also refactor the current plugin to respond to both events and separate the code with:

            switch($modx->event->name) {
                case 'OnUserSave':
                  /* sudo prevention code */
                  break;
            
                case 'OnDocFormPrerender':  // or whatever the original even was
                  /* your existing code */
                  break;
                
                default:
                  break;
            }
            
            return;



            Thanks Bob, I did test it and couldn't find any code to restrict the Sudo field, although I did see an old post from Jason Coward suggesting that this wasn't possible and the way to go would be CMPs but I can't find that post again.

            I think I'm either going to have to trust my Editor usergroup to leave the Sudo option alone or just stop them from saving any changes in the ACL.

            I discovered some other unfortunate weird behaviour though... If I give my Editor usergroup access to view and/or save a user profile in the Manager it throws up a Code:200 Error when the profile is viewed. Although this can just be dismissed and doesn't cause any other problems, it's a bit annoying so I went through the ACL and by trial and error found that if both "namespaces" & "settings" are checked then the error message goes away. The problem now of course is,the Editor usergroup can also access the "System Settings"!!

            I guess I just have to take all this on board and find the right compromise for my situation...





              • 32507
              • 142 Posts
              Hi,

              I have exactly the same "problem". If you find some good solution, let us know smiley and Ditto...
              • discuss.answer
                • 3749
                • 24,544 Posts
                On my install, this CSS would hide the div containing the sudo field. The number might be different on yours (use Firefox ctrl-shift-i and inspect that form field to make sure).

                #ext-gen149 {
                   display:none;
                }


                You can hide the System Settings icon the same way: http://bobsguides.com/blog.html/2016/09/15/hiding-the-system-menu/

                For increased safety, as per my suggestion above - this may need to be modified to meet your needs:

                switch($modx->event->name) {
                    case 'OnUserSave':
                      /* sudo prevention code - only admins can set the sudo field */
                      if (! $modx->user->isMember('Administrator')) {
                          $user->set('sudo', '0');
                      }
                
                      break;
                 
                    case 'OnDocFormPrerender':  // or whatever the original event was
                      /* your existing plugin code */
                      break;
                     
                    default:
                      break;
                }
                 
                return;
                

                  Did I help you? Buy me a beer
                  Get my Book: MODX:The Official Guide
                  MODX info for everyone: http://bobsguides.com/modx.html
                  My MODX Extras
                  Bob's Guides is now hosted at A2 MODX Hosting
                  • 52804
                  • 36 Posts
                  Quote from: BobRay at Dec 07, 2016, 04:17 PM
                  On my install, this CSS would hide the div containing the sudo field. The number might be different on yours (use Firefox ctrl-shift-i and inspect that form field to make sure).

                  #ext-gen149 {
                     display:none;
                  }


                  You can hide the System Settings icon the same way: http://bobsguides.com/blog.html/2016/09/15/hiding-the-system-menu/

                  For increased safety, as per my suggestion above - this may need to be modified to meet your needs:

                  switch($modx->event->name) {
                      case 'OnUserSave':
                        /* sudo prevention code - only admins can set the sudo field */
                        if (! $modx->user->isMember('Administrator')) {
                            $user->set('sudo', '0');
                        }
                  
                        break;
                   
                      case 'OnDocFormPrerender':  // or whatever the original event was
                        /* your existing plugin code */
                        break;
                       
                      default:
                        break;
                  }
                   
                  return;
                  


                  I managed to hide the system settings icon and the Sudo user field using your method. For me the Sudo checkbox ID was #ext-gen135, so I guess it is different for everyone.

                  The only part I couldn't get to work was to prevent non admins from setting the Sudo option for other non admins. I tried attaching this directly to the OnUserSave system event but still wouldn't work...

                  /* sudo prevention code - only admins can set the sudo field */
                        if (! $modx->user->isMember('Administrator')) {
                            $user->set('sudo', '0');
                        }
                  return;
                  
                  


                  But hey, I have a working solution to my problem.. Thanks Bob
                    • 3749
                    • 24,544 Posts
                    My bad. I forgot the save.

                    /* sudo prevention code - only admins can set the sudo field */
                          if (! $modx->user->isMember('Administrator')) {
                              $user->set('sudo', '0');
                              $user->save();
                          }
                    return;


                      Did I help you? Buy me a beer
                      Get my Book: MODX:The Official Guide
                      MODX info for everyone: http://bobsguides.com/modx.html
                      My MODX Extras
                      Bob's Guides is now hosted at A2 MODX Hosting
                      • 52804
                      • 36 Posts
                      Quote from: BobRay at Dec 09, 2016, 01:42 PM
                      My bad. I forgot the save.

                      /* sudo prevention code - only admins can set the sudo field */
                            if (! $modx->user->isMember('Administrator')) {
                                $user->set('sudo', '0');
                                $user->save();
                            }
                      return;



                      Still not working for some reason. Just to confirm attached to OnUserSave event. Cleared cache, flushed permissions. Modx 2.5.2