We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 28215
    • 4,149 Posts
    Okay, so I know none of us are very crazy about the userperms right now.

    An issue that’s seeming to come up is regarding the default setting of pages in the manager to "allow all unless deny" (as Ryan puts it nicely in packets terminology laugh). The question that’s been asked is, "On the manager side, shouldn’t it be ’deny all unless allowed’?"

    So, what do you all think? If so, then this might take some work - completely getting rid of the "Public" setting might take some time and be difficult to "gracefully transition" from 095 implementations and so forth.



      shaun mccormick | bigcommerce mgr of software engineering, former modx co-architect | github | splittingred.com
      • 27376
      • 576 Posts
      I’ve worked around this by creating a Manager User Group and Document Group and linked the two, then put all my pages in that group, with no users assigned to it. Puts a lot of rows in the DB but it works...

      I agree though that on the manager side, it should be "deny all unless allowed" but the "public" feature should still be available so that IF you want all managers to edit a page, it’s still possible.
        • 28042 ☆ A M B ☆
        • 24,524 Posts
        My thinking exactly. Most small sites don’t need extensive permissions, just a basic login for one or two people.

        I’m hoping that eventually the user management part will become a pluggable module, much like the rich text editor is now, and you can plug in whichever one you want to use.
          Studying MODX in the desert - http://sottwell.com
          Tips and Tricks from the MODX Forums and Slack Channels - http://modxcookbook.com
          Join the Slack Community - http://modx.org
          • 28215
          • 4,149 Posts
          Quote from: sirlancelot at Feb 22, 2007, 11:38 AM

          I agree though that on the manager side, it should be "deny all unless allowed" but the "public" feature should still be available so that IF you want all managers to edit a page, it’s still possible.

          Good idea - OpenGeek and I talked a bit about this...what about:
          1. Creating a static user+docgroup link that is created upon MODx installation called ’Public’ that cant be deleted
          2. The Public group makes documents globally accessible
          3. Making new documents NOT default to being assigned to that group
          4. Having a configuration setting that can override #2 and set them to that group upon new document creation

          Sound good?
            shaun mccormick | bigcommerce mgr of software engineering, former modx co-architect | github | splittingred.com
            • 25663 MODX Staff
            • 12,272 Posts
            This ties in quite well with some exploration that Jared did earlier today:
            http://modxcms.com/forums/index.php/topic,12372.new.html#new

              Ryan Thrash, MODX Co-Founder
              Follow me on Twitter at @rthrash or catch my occasional unofficial thoughts at thrash.me
              • 30223
              • 1,010 Posts
              I’m assuming the default permission would be the permissions of the owner at the time of creating a new document? i.e. the document group of the current logged in manager user? What if he/she is connected to more than one document group?

              Or would there be no default and the user would be forced to make a choice before saving? To me this would be less ideal.


              Come to think of this I don’t really see what’s wrong with the ’allow unless deny’ system. In the majority of cases this is perfectly ok as there is one, perhaps 2 manager users who will be creating/editing pages. I really dislike systems that have global restrictions to satisfy the needs of a small group of users. At the least this should be a configuration option.
                • 27376
                • 576 Posts
                Quote from: TobyL at Feb 22, 2007, 04:46 PM

                I’m assuming the default permission would be the permissions of the owner at the time of creating a new document? i.e. the document group of the current logged in manager user? What if he/she is connected to more than one document group?
                As the system is right now, new documents inherit the parent document’s permissions, which I have no complaint about.

                The reason I like splittingred’s proposal is that I have at least 8 - 10 managers that edit completely different sections of the site (with me needing to have control of the whole site). So the "deny all unless allowed" system would be ideal.

                Making document permissions a plugin would satisfy both scenarios but I don’t see that happening for a while, at least not until after MODx 1.0. I would certainly be more than happy to help code and test such a plugin wink
                  • 25663 MODX Staff
                  • 12,272 Posts
                  Deny all unless allowed is a much more mature and generally accepted way to handle things I think. Maybe we just have a toggle that sets the base rule, though. I like that really. And honestly at some point things have to break in order to make progress. Our goofy split web/manager permission system seems like as good a place as any to me... tongue
                    Ryan Thrash, MODX Co-Founder
                    Follow me on Twitter at @rthrash or catch my occasional unofficial thoughts at thrash.me
                    • 27376
                    • 576 Posts
                    Quote from: rthrash at Feb 22, 2007, 05:59 PM

                    Our goofy split web/manager permission system seems like as good a place as any to me... tongue
                    lol! So is it a better idea to break a whole bunch of features at once or to break incrementally throughout multiple versions?
                      • 6726
                      • 7,075 Posts
                      The inheritance issue aside (I don’t complain but I sure would use in some case to give access to a document children without giving access to the parent document), I never used sirlancelot’s empty user group.

                      As far as I am concerned, I have systematically build a user group for editors, and made all manager document private. Some are into the admin document group and others into the editors document group (managing this has really been made easier by DocManager !). I confess I never tested if this made those documents unavailable to any other user with no permissions but assumed it did.

                      Anyway, the user perms are not perfect but should work for you 95% of the case if you juggle with document and user groups properly (which, to some, is not natural at all... support request is proof there).

                      Now what has been mentionned time and again is merging manager and web users. I always agreed with that but I wonder now if it won’t make the permission system even more complex... maybe syncrhonizing both user groups is the way (never managed to make Raymond’s plugin Web2Manager by the way.. neither did people who posted on the support thread, it would seem. I’d love to see this plugin updated !)
                        .: COO - Commerce Guys - Community Driven Innovation :.


                        MODx est l'outil id