I’m sorry I have post the some question in another post but can’t delete or move them.
I think this is a better place, a littel confuse with soo much forums...
please, if some moderator can remove the post in General support, thanks.
I’ve been playing with ACL and create a new "editor" user. Its in the admin group and can edit only resources, files and access quip moderation backend. The problem is editing profile, in ACL initialy y set change_profile and change_password then when I access profile page I get Permission Denied! in a floating windows and the profile form is blank. I have tried setting all user related permission like view_user, edit.. save... etc. but get the same result, can’t edit profile... any idea ?
I’ve Revolution 2.0.0-pl installed and searching in jira have find two related problems (MODX-1522 and MODX-1670) that seem fixed but I have the same problem. I have tried setting access_permission too, but get the same problem.
An-tonio, I’m not completely clear on your problem, but I think this might help.
Context Access ACL entries should have a policy based on the default Administrator policy.
Resource Group Access ACL entries should have a policy based on the default Resource policy.
Element Category ACL entries should have a policy based on the default Element policy.
Start by duplicating the appropriate policy and assigning the duplicate in the ACL entry.
Then remove permissions a few at a time (flush permissions) from that policy and make sure the user can still do and see what they need to.
It might also help to know that the Administrator policy generally controls what *actions* the user can perform in the Manager itself (e.g. create a new user, alter security settings, edit resources, etc.) and the Resource and Element policies control what users can do with specific *objects* (e.g. snippets, chunks, etc.).
Thanks zi.
Bob, I did in a similar manner as described in your security tutorial creating an adminlite Access Police from Administrator and then removing unnecesary permissions.
Doing some proves I have resolve the problem, it need view_user permission, but to take effect not only is neccesary to flush permission, you have to logout and login again with the editor user, a cache problem ?
Thanks.
-
☆ A M B ☆
- 24,524 Posts
Sounds more like a SESSION problem... if he’s logged in and his SESSION values are set, changing the permissions won’t update his SESSION.
I quite often follow these three steps when my security permission changes don’t seem to be working:
1. Security->Flush Permissions
2. Site->Clear Cache
3. Security->Flush All Sessions