We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 53524
    • 6 Posts
    I tried googling this endlessly and I couldn't find any up to date information that was helpful at all. I want to make it so that a select group of members can create, publish and edit new resources, but only in a specific parent resource (which is automatically set as the parent resource upon creation of a new resource) and not be able to do anything else except send private messages and update their profile. I would have just made a compromise and just manually locked editing on all but a few resources, but the check box for that in the edit resource manager page is conveniently missing in this version. I've used MODx in the past but I guess I'm a bit rusty because this is all greek to me now and it doesn't help that the documentation isn't completely up to date.
      • 3749
      • 24,544 Posts
      Here's the short version - off the top of my head:

      Put all the resources on the site in a Resource Group called AllDocs and create a Resource Group Access ACL entry connecting that Resource Group to the Administrator User Group (which the users in question are not members of but you are). Use a Policy of Resource and a Context of 'mgr'. You can use a utility snippet to put the resources in the Resource Group (create the Resource Group first!):

      $count = 0;
      $docs = $modx->getCollection('modResource');
      foreach($docs as $doc) {
          $resource->joinGroup('AllDocs');
          $resource->save(); // probably not necessary, but can't hurt
          $count++;
      }
      return "Added ' . $count . 'Resources to AllDocs Group';
      

      Install the DefaultResourceGroup extra to put all future resources in the AllDocs group.

      That will "protect" all resources from anyone outside the Administrator group.

      Once that's done,

      Put the users in a User Group Called AllowedDocs
      Put the parent resource and it's children in a Resource Group called AllowedDocs
      Connect that Resource Group to the AllowedDocs User Group with a Resource Group Access ACL entry with a context of 'mgr' and whatever Policy you want them to have (the Resource policy if you want them to have full rights).

      Flush permissions and Sessions before testing any changes.

      More info here: https://bobsguides.com/revolution-permissions.html.

      If you want to understand why you're doing it, watch this 50-minute video.
        Did I help you? Buy me a beer
        Get my Book: MODX:The Official Guide
        MODX info for everyone: http://bobsguides.com/modx.html
        My MODX Extras
        Bob's Guides is now hosted at A2 MODX Hosting
        • 53524
        • 6 Posts
        I still must be doing something wrong because with the test user I made and gave the "content editor" access policy to it gave me the following error message when I went to edit a resource in the appropriate resource group:

        Code: 200 OK
        {"success":false,"message":"Permission denied!","total":0,"data":[],"object":[]}

        Also, the other resources are still showing up in the resource tree, and I want them hidden from anyone without access.
          • 3749
          • 24,544 Posts
          It's really frustrating when you see "Permission denied!" and can't find out why.

          Does that user's User Group also have a Context Access ACL policy with a context of 'web'? (they should)

          The ContentEditor policy is for *Context* Access ACL entries. It's not appropriate for a Resource Group ACL entry.

          Try changing it to 'Resource' and flushing everything.



            Did I help you? Buy me a beer
            Get my Book: MODX:The Official Guide
            MODX info for everyone: http://bobsguides.com/modx.html
            My MODX Extras
            Bob's Guides is now hosted at A2 MODX Hosting
            • 53524
            • 6 Posts
            I did that and I'm still getting the same message.
              • 3749
              • 24,544 Posts
              What is the Context Access policy for that group for the 'mgr' context?
                Did I help you? Buy me a beer
                Get my Book: MODX:The Official Guide
                MODX info for everyone: http://bobsguides.com/modx.html
                My MODX Extras
                Bob's Guides is now hosted at A2 MODX Hosting
                • 53524
                • 6 Posts
                Context access is content editor, for both web and mgr.

                permissions are: change_profile, class_map, countries, edit_document, frames, help, home, load, list, logout, menu_reports, menu_site, menu_support, menu_tools, menu_user, resource_duplicate, resource_tree, save_document, source_view, tree_show_resource_ids, view, view_document, new_document, delete_document
                  • 3749
                  • 24,544 Posts
                  Switch that Context Access policy to Administror (temporarily), flush permissions and sessions, and test. If that fixes the problem, there's a permission missing from the Content Editor Policy. If not, we need to look further.
                    Did I help you? Buy me a beer
                    Get my Book: MODX:The Official Guide
                    MODX info for everyone: http://bobsguides.com/modx.html
                    My MODX Extras
                    Bob's Guides is now hosted at A2 MODX Hosting
                    • 53524
                    • 6 Posts
                    Yeah that did it.
                      • 3749
                      • 24,544 Posts
                      Ok, now (if you haven't already), switch back to the Content Editor policy and start adding permissions until it starts working.

                      'new_document_in_root', and 'save' come to mind.
                        Did I help you? Buy me a beer
                        Get my Book: MODX:The Official Guide
                        MODX info for everyone: http://bobsguides.com/modx.html
                        My MODX Extras
                        Bob's Guides is now hosted at A2 MODX Hosting