We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 18373 ☆ A M B ☆
    • 3,141 Posts
    Heya,

    I finally managed to set up my member pages to only show up for the members. However, now I want to change the behaviour of returning a 404 error instead of not authorized if users are not logged in.

    (So it should return the not authorized page)

    Bob’s post (http://bobsguides.com/revolution-permissions.html) got me on the right track for the member-only pages, however I’m still stuck with returning "not authorized"...

    Bob says:
    Unauthorized Versus Error Page

    This is a change from MODx Evolution. In Revolution, if a web page is protected in the front end so that only logged-in users can see it, the default behavior is for anonymous users to be redirected to the Error (page not found) page rather than the Unauthorized page when they try to access the resource. In Revolution, if Users don’t have the "load" permission for a resource, it’s as if it doesn’t exist — thus the "page not found" response. If you would like them to be sent to the Unauthorized page instead, you can do the following:
    * Create a new Access Policy called "Load" and add a single Permission: Load.
    * Create a new Context Access ACL entry for the anonymous User Group with a Context of "web," a Role of "member" and an Access Policy of "Load."

    There already was a "load only" ACL, so I’ve tried using that instead of making a new one.

    In the attachment you will find a screenshot of how I set up the context access ACL.

    I’ve tried clearing site cache and flushing permissions after changing things, but so far I couldn’t get it working yet.

    Any help greatly appreciated!
      Mark Hamstra • Developer spending his days working on Premium Extras and a MODX Site Dashboard with the ability to remotely upgrade MODX and extras to make the MODX world a little better.

      Tweet me @mark_hamstra, check my infrequent blog at markhamstra.com, my slightly more frequent ramblings at MODX.today or see code at Github.
      • 28215
      • 4,149 Posts
      Change the minimum role to have an authority of 9999.
        shaun mccormick | bigcommerce mgr of software engineering, former modx co-architect | github | splittingred.com
        • 18373 ☆ A M B ☆
        • 3,141 Posts
        That’s also something I had wondered...

        Made another role "Default role" with 9999 as authority. Still doesn’t work.

        ( Flushed permissions and cleared cache )
          Mark Hamstra • Developer spending his days working on Premium Extras and a MODX Site Dashboard with the ability to remotely upgrade MODX and extras to make the MODX world a little better.

          Tweet me @mark_hamstra, check my infrequent blog at markhamstra.com, my slightly more frequent ramblings at MODX.today or see code at Github.
          • 22303 MODX Staff
          • 10,725 Posts
          Do not change the Member role from 9999; that might be the problem, but I’ll have to look deeper.
            • 22303 MODX Staff
            • 10,725 Posts
            You simply neglected to assign a Load Only policy to the Resource Group Access to the Artist Only Resource Group in the web context for anonymous users. If you logout of the manager and try to access the page, you will see that it is now returning the 403 response.
              • 18373 ☆ A M B ☆
              • 3,141 Posts
              Ah... Thanks a lot!

              I wonder why I didn’t think of that.
                Mark Hamstra • Developer spending his days working on Premium Extras and a MODX Site Dashboard with the ability to remotely upgrade MODX and extras to make the MODX world a little better.

                Tweet me @mark_hamstra, check my infrequent blog at markhamstra.com, my slightly more frequent ramblings at MODX.today or see code at Github.
                • 3749
                • 24,544 Posts
                This is working for me with truly anonymous users. For a user who is logged in in the front end but is not a member of any user groups, however, the user is still getting the error page.

                Shouldn’t a user who is not a member of any user group be anonymous user with a 9999 authority level and be redirected to the unauthorized page?

                Or do I need to add the user to the anonymous group with an access policy that just has the load permission?

                [Update] The anonymous user group won’t accept any new members. The error message is somewhat confusing: "User Group Not Specified."

                So, how can a logged in user be redirected to the unauthorized page when trying to access a resource he or she is not authorized to see?

                [Update]
                Got it. They have to be added to the user groups authorized to see the pages with a role of "Member." Then Update each group to add another Resource Group Access ACL for the protected resource group with the Role set to "Member," and the Policy set to "Load."
                  Did I help you? Buy me a beer
                  Get my Book: MODX:The Official Guide
                  MODX info for everyone: http://bobsguides.com/modx.html
                  My MODX Extras
                  Bob's Guides is now hosted at A2 MODX Hosting
                  • 18373 ☆ A M B ☆
                  • 3,141 Posts
                  I also had some trouble with being logged in on the manager at the same time... even when you use a different browser window (but the same browser, in this case Firefox 3.6.3) it’s recognizing me as being a logged in manager user (without permission for that resource group).

                  Opening another browser (eg Internet Explorer) to check the behaviour works fine.
                    Mark Hamstra • Developer spending his days working on Premium Extras and a MODX Site Dashboard with the ability to remotely upgrade MODX and extras to make the MODX world a little better.

                    Tweet me @mark_hamstra, check my infrequent blog at markhamstra.com, my slightly more frequent ramblings at MODX.today or see code at Github.
                    • 22303 MODX Staff
                    • 10,725 Posts
                    Quote from: Mark at Jun 25, 2010, 05:37 AM

                    I also had some trouble with being logged in on the manager at the same time... even when you use a different browser window (but the same browser, in this case Firefox 3.6.3) it’s recognizing me as being a logged in manager user (without permission for that resource group).

                    Opening another browser (eg Internet Explorer) to check the behaviour works fine.
                    Correct; a session is related to a browser session, not a browser window.