We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 15076
    • 43 Posts
    Hi all,

    First my specs:

    Web Server:

    * PHP version: 5.3.0 running on localhost
    * Apache or IIS version 2.2.11
    * Operating System and version windows xp sp 3

    Database:

    * MySQL version 5.1.36
    * List of any tables over 1MB in size none

    MODx:

    * Version rev 6066
    * Any changes you’ve made no changes except for adding some chunks and snippets.
    * Any snippets you’re running on the page that is not working properly none
    * Any plugins you’re running no other then those that run on install ( i guess none smiley)

    Browser/Client:

    * Browser name and version firefox 3.5.7
    * Operating System and version windows xp sp 3


    For a project I need to create a portal where users can find documentation and ask questions. It’s a must to easily search documentation and there must be an ability to grant users acces control to a file.

    I found all features are very easy to implement with modX, except for the user management part. I know i can make user groups and they work very nice, but i would like to have the ability to make exceptions for each user, without having to make a user group for each user. So for example, I have three resources: home, loggedin and exception. I have three users, first one is not logged in, second is allowed and third is allowed but without the exception.

    I would like to know if there is an already existing module/plugin that achieves this, or should i create one myself. If i have to create one myself, will someone be able to point me in the right direction?

    Thanks in advance,

    Jurrian
      • 3749
      • 24,544 Posts
      Jurrian, I’m afraid I don’t fully understand your question. First, do you mean in the front end or the Manager? Second, do you mean that you will have many users and many pages that can only be accessed by one user?

      See if anything here helps: http://bobsguides.com/permissions.html
        Did I help you? Buy me a beer
        Get my Book: MODX:The Official Guide
        MODX info for everyone: http://bobsguides.com/modx.html
        My MODX Extras
        Bob's Guides is now hosted at A2 MODX Hosting
        • 15076
        • 43 Posts
        Let me try to explain it clearer then laugh

        I read your article about permissions, and I will try to use your terminology.

        First your questions, I am talking about web-users, so the front-end. Sorry for not using right terminology in my first post. I will try to answer your second question with an example:

        Lets say I have 20 users, and three different user groups. The first group is low-permission, the second middle-permission and the last is high-permission. I will put four users in low-permission, 7 in middle-permission and 9 in high-permission. High permission will be able to see all documents, middle permission all except those tagged as high-permission and low permission only documents that are tagged low-permission.

        Following up I will create three resource groups. First is low-permission-doc, second is middle-permission-doc and last is high-permission-doc. I will create 50 documents and place 17 in low-permission-doc, 10 in middle-permission-doc abd 23 in high-permission doc.

        Next thing will be to link low-permission to low-permission-doc, middle-permission to low-permission-doc and middle-permission-doc, high-permission to low-permission-doc, middle-permission-doc and high-permission-doc.

        So far so good, everything works perfect:)

        But now I want to give user12, who is middle-permission, the exclusive right to see doc51. So he will be able to see it, but no-one else will. However it might happen, that I want to give another user the right to see this document. Since in theory this is possible for all combinations of document, creating a new user group for each user is not an option, since i will have 50! possibilities on how to divide the pages among users. And the plan is to make more resources then 50...

        I hope this is a better explanation of my post.
          • 3749
          • 24,544 Posts
          Thanks, I see what you’re trying to do now. Unfortunately, I can’t think of any easy solution.

          Once you’ve protected a page by connecting its resource group to a user group, it won’t be accessible to users not in that user group.

          The only way around that that I can think of would be to have a chunk (or a custom DB table) with a list of special users and the pages they can see and then hack the MODx security code so it parses that list and bypasses the normal security restrictions.

          Personally, I think I’d create a module that manages user groups and resource groups to accomplish your goal. Do take a look at the DocManager Module, which may do some of what you need and its code could give you some ideas about creating your own custom module.

          Maybe someone else will have a better idea.
            Did I help you? Buy me a beer
            Get my Book: MODX:The Official Guide
            MODX info for everyone: http://bobsguides.com/modx.html
            My MODX Extras
            Bob's Guides is now hosted at A2 MODX Hosting
            • 15076
            • 43 Posts
            I was thinking I would be needing a more deep solution, but hoped I oversaw something when searching through the available modules, snippets and plugins:) and googleing for a solution

            Anyway, thank you very much for your time, first I’m busy with creating some more easy snippets to get a better feeling with modx, after that I will try to create a nice plugin.

            I hope someone else has another idea
              • 15076
              • 43 Posts
              is someone having another idea??
                • 29774
                • 386 Posts
                I believe this is possible in Revo using access policies and assigning access to the user rather than a group; however, in Evo I think it would only be possible if you implemented your own scheme. Essentially you would need an additional table, let’s say ’user_document_access’, and some CRUD pages where someone in your top level admin group could log in and manage access to users on a per-document level. Then you could use a plugin, perhaps attached to OnPageUnauthorized, to allow access to documents to users cross referenced in the table.

                Perhaps someone familiar with the user management in Revo would explain how to do it using the new user management system?
                  Snippets: GoogleMap | FileDetails | Related Plugin: SSL
                  • 15076
                  • 43 Posts
                  hmm I’ll give a look to revo then, thank you very much:)
                    • 3749
                    • 24,544 Posts
                    In the present version of Revo security, I think you’d have the same problems you would in Evo. Users in a group can currently have different roles in Revo, but I don’t think that’s going to help in this case.
                      Did I help you? Buy me a beer
                      Get my Book: MODX:The Official Guide
                      MODX info for everyone: http://bobsguides.com/modx.html
                      My MODX Extras
                      Bob's Guides is now hosted at A2 MODX Hosting
                      • 15076
                      • 43 Posts
                      hmm I couldn’t find a way to disable the group security, but when it is not there it’s not that strange

                      Can someone tell me if it is planned that this will be changed in the official release of revo?

                      Thanks in advance