Hello,
With a new fresh install of modx 2.0.8-pl traditional, I’ve got trouble in building a "1 page accessible to 1 editor only".
I’m wondering if the system is buggy?
For ex. In User Groups > Update User Group > Context Access and Resource Group Access for an Add or Update action, the Access Policy dropdown does not list all the existing Access Policies.
In Context Access > Add/Update little popup window: Element and Resource and all new Access Policies I’ve created are missing.
In Resource Group Access > Add/Update little popup window: Administrator, Content Editor and Element Access Policies are missing, but my new ones (duplicate of Resource) are there.
Weird thing, when I update the Administrator User Group, the Context Access > Update > Access Policy : Resource is visible in the dropdown. For the other User groups, it isn’t.
Thanks a lot for your help.
The resource policy is only appropriate for Resource Group Access ACL entries. The Element policy is only for Element Category Access ACL entries.
In later versions of MODX, only the appropriate policies are shown when creating an ACL entry.
Quote from: twust at Jun 01, 2011, 11:32 AM
Would I read your guide http://bobsguides.com/revolution-permissions.html to the end, would I seen that information... or have you added Where’s my policy? chapter just after answering my question? ;-)
Thanks a lot for your quick answer and for your guides.
May I ask one more question about Resource/Element policies: is it possible to allow a user "supervisor" to view a resource with all its tabs (Create/Edit document, Page settings, Templates variables) but not to edit anything? Playing around with Resource and Content Editor policies gives me the possibility for my "supervisor" to click on the resource tree and get the resource in view mode only, but the usual tabs are replaced by General, Changes and Cache Output tabs; the most annoying thing is that I don’t see the resource content and the template variables.
PS: yes, this time, I’ve read http://bobsguides.com/controlling-access-to-resources-in-the-manager.html 
I did add the "Where’s my Policy" section, but it was at least several weeks ago -- maybe you had an older version in your browser cache.
I’m not sure about your other question. You might try just changing the Resource policy alone to remove the "save, create, delete, copy, and remove" permissions (this would be for the Resource Group Access ACL entry). Give them full rights to resources in the policy attached to the mgr Context Access ACL entry. That way your supervisor should see everything normally but won’t be able to change any resources.
I’m not sure because I’ve never tried what you’re attempting. It may or may not be possible.
First, you should create a new role for the supervisor with a lower authority number, because you may want to use the Members group for something else later.
I think #1 is closer to what you want, but you should try enabling edit_document and save document in the Context Access policy and control things with the Resource Group Access