This is driving me mad.
I’ve got a couple of MODx sites in development at the moment and am experiencing the same issue on both.
Using just one as an example, this is a site for a business. I’ve created a staff-only area accessible only by staff logging in to the site. This is in a resource group called "staff". I’ve created a corresponding user group called "staff", with the idea being that members of the group can see the staff area on the site, and superusers in the group can log on to the Manager and edit the staff area (and only the staff area, not the rest of the website).
So I’ve set up the ACL listings for that resource group like this:
[table][tr]
[td]User Group[/td]
[td]Minimum auth[/td]
[td]Policy[/td]
[td]Context[/td]
[/tr]
[tr]
[td]Administrator[/td]
[td]0 - Super User[/td]
[td]Administrator[/td]
[td]mgr[/td]
[/tr]
[tr]
[td]Staff[/td]
[td]0 - Super User[/td]
[td]Administrator[/td]
[td]mgr[/td]
[/tr]
[tr]
[td]Staff[/td]
[td]9999 - Member[/td]
[td]Resource[/td]
[td]web[/td]
[/tr]
[/table]
The web context stuff works fine. But what I’m finding is that as soon as I add any mgr context access to the resource group, even to my own user group (my account is the only one in the Administrator group, and is a member of only that group and no others), I lose the ability to create 2nd-level resources in that resource group. What I mean is, the main resource in that group is a container/page called Staff Area. It already has some subpages from before I set up the resource access,but I can’t create any more - I just get a "You don’t have permission to create a resource in this location" error. I can, however, create subpages underneath the existing subpages without difficulty. I can also edit any of the pages to my heart’s content.
I should also mention that I have not made any changes to the default Administrator policy.
Can anyone see where I’m going wrong?
If those are Context Access ACLs, the policy should always be Administrator (or a duplicate policy with fewer permissions).
If they are Resource Group Access ACLs, the policy should always be Resource (or a duplicate policy with fewer permissions).
FYI, it’s often simpler to control access to stuff in the manager by creating a tree_root_id user setting for each user. Then they’ll only be able to see resources in or below that ID.
Thanks, changing the Resource ACL policy to Resource fixed it!
The tree_root_id idea sounds good, though due to time contraints on my part I’m trying to gear this site to be self-managed by staff at the business, and as simply as possible - not sure how we’ll they’ll handle adding custom settings. But I’ll definitely keep it in mind for future.
Thanks again!