We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 9710
    • 24 Posts
    Hello,

    is it possible to stop the modx in OnDocFormPrerender and send an error message, so that I can forbid the access of certain resources via a plugin?

    I tried $modx->error->output and returning $modx->error->failure but this doesn’t work? Is there any other solution?

    thanks
      • 33968
      • 863 Posts
      Any reason you can’t just use form customisation?
        • 9710
        • 24 Posts
        I think you mean Resource Group Access.
        That would do the job perfectly, but unfortunately it’s quite complicated if you have a lot of users in the system and
        do not want them to edit another user’s resource.
          • 33968
          • 863 Posts
          Yes that’s what I meant smiley

          How are you associating each user with their resource?

          Also - have you found a way to hide the other users’ resources in the doc tree? I have a rough idea of how this ’might’ be done using a plugin and and a general access policy (inspired by this post).
            • 9710
            • 24 Posts
            Until now, I made a Resource Group for each User.
            Pretty odd, if you’ve a lot of them. Because each user only had access to their Resource Group, they could only edit and see their own documents. The administrator had access to all groups and could drag the resources into his own Resource group and publish it there.

            The post you referred to doesn’t really solve the problem, but it would make sense in combination with the thing I need (users shall just be able to edit resources the own AND - that’s the part you brought in - not see any other resources).
              • 33968
              • 863 Posts
              Yeah that’s what I meant with the doc tree.

              I take it that the Resource Group allocation is becoming cumbersome as your user numbers grow. But I don’t really understand how you will be allocating resources to individual users. Will this always be done by an administrator? Could you perhaps create a ’User Id’ TV which would link each resource with a user (or multiple users), and then use that value to allow or deny access via your plugin?
                • 9710
                • 24 Posts
                "Will this always be done by an administrator?"
                With the modx permission system: yes

                There is a createdby field in the database. So you could just check if $resource->get(’createdby’) matches the current user id;
                So what I need now is a method to create a permission-like system with a plugin -> I need to cancel the open-resource-operation if the user is not allowed,

                  • 3749
                  • 24,544 Posts
                  You can also create a tree_root_id setting for each user that allows them to see only their part of the tree. It’s not completely secure, because a savvy user can edit other resources by guessing the URL to type in the Manager, but it does quickly simplify the tree for those users.

                  One secure solution is a plugin that creates the user’s resource and tree_root_id setting when the user registers combined with another plugin tied to OnDocFormPrerender that checks the users’s tree_root_id setting and forwards the user somewhere else (with $modx->sendRedirect() ) if they try to edit someone else’s resource.
                    Did I help you? Buy me a beer
                    Get my Book: MODX:The Official Guide
                    MODX info for everyone: http://bobsguides.com/modx.html
                    My MODX Extras
                    Bob's Guides is now hosted at A2 MODX Hosting
                    • 33968
                    • 863 Posts
                    Sure you can use the createdby field - I guess I had assumed that users wouldn’t be able to create their own resource. I don’t know if it would accept multiple values though, which would make using a TV useful if you wanted to allow more than one user to edit a particular resource. Depends on what you need, really.

                    The beauty of Bob’s solution is that you will only really need the plugin as a ’backup’ to prevent unauthorised access, as users will only be able to select their own documents from the tree.

                    But for those who might try to manipulate the url or somehow end up on someone else’s page, I found this example in the docs:
                    if (!$modx->hasPermission('edit_chunk')) die('Access Denied!');
                    


                    Does die() work for you? If not, you could have a look through the core files to do with manager access and see how ’access denied’ is handled there.
                      • 9710
                      • 24 Posts
                      Quote from: BobRay at Jun 16, 2011, 12:53 AM

                      One secure solution is a plugin that creates the user’s resource and tree_root_id setting when the user registers combined with another plugin tied to OnDocFormPrerender that checks the users’s tree_root_id setting and forwards the user somewhere else (with $modx->sendRedirect() ) if they try to edit someone else’s resource.

                      Quote from: lucas

                      Does die() work for you? If not, you could have a look through the core files to do with manager access and see how ’access denied’ is handled there.

                      Good idea - it’s working. Thank you very much!