We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 1434
    • 23 Posts
    I’m sorry I have post the some question in another post but can’t delete or move them.

    I think this is a better place, a littel confuse with soo much forums...
    please, if some moderator can remove the post in General support, thanks.

    I’ve been playing with ACL and create a new "editor" user. Its in the admin group and can edit only resources, files and access quip moderation backend. The problem is editing profile, in ACL initialy y set change_profile and change_password then when I access profile page I get Permission Denied! in a floating windows and the profile form is blank. I have tried setting all user related permission like view_user, edit.. save... etc. but get the same result, can’t edit profile... any idea ?

    I’ve Revolution 2.0.0-pl installed and searching in jira have find two related problems (MODX-1522 and MODX-1670) that seem fixed but I have the same problem. I have tried setting access_permission too, but get the same problem.
      • 3749
      • 24,544 Posts
      An-tonio, I’m not completely clear on your problem, but I think this might help.

      Context Access ACL entries should have a policy based on the default Administrator policy.
      Resource Group Access ACL entries should have a policy based on the default Resource policy.
      Element Category ACL entries should have a policy based on the default Element policy.

      Start by duplicating the appropriate policy and assigning the duplicate in the ACL entry.

      Then remove permissions a few at a time (flush permissions) from that policy and make sure the user can still do and see what they need to.

      It might also help to know that the Administrator policy generally controls what *actions* the user can perform in the Manager itself (e.g. create a new user, alter security settings, edit resources, etc.) and the Resource and Element policies control what users can do with specific *objects* (e.g. snippets, chunks, etc.).
        Did I help you? Buy me a beer
        Get my Book: MODX:The Official Guide
        MODX info for everyone: http://bobsguides.com/modx.html
        My MODX Extras
        Bob's Guides is now hosted at A2 MODX Hosting
        • 33337
        • 3,975 Posts
        Quote from: An-tonio at Jul 29, 2010, 12:59 PM

        I think this is a better place, a littel confuse with soo much forums...
        please, if some moderator can remove the post in General support, thanks.
        Old topic removed! smiley
          Zaigham R - MODX Professional | Skype | Email | Twitter

          Digging the interwebs for #MODX gems and bringing it to you. modx.link
          • 1434
          • 23 Posts
          Thanks zi.

          Bob, I did in a similar manner as described in your security tutorial creating an adminlite Access Police from Administrator and then removing unnecesary permissions.
          Doing some proves I have resolve the problem, it need view_user permission, but to take effect not only is neccesary to flush permission, you have to logout and login again with the editor user, a cache problem ?

          Thanks.
            • 28042 ☆ A M B ☆
            • 24,524 Posts
            Sounds more like a SESSION problem... if he’s logged in and his SESSION values are set, changing the permissions won’t update his SESSION.
              Studying MODX in the desert - http://sottwell.com
              Tips and Tricks from the MODX Forums and Slack Channels - http://modxcookbook.com
              Join the Slack Community - http://modx.org
              • 1434
              • 23 Posts
              True, maybe a SESSION problem. The confusion came when some permission apply only with flush permission and seem that others need to reset sessions. If this is the case the rule should be always to logout/login when change something in ACL.

              I take note to learn de lesson smiley
                • 3749
                • 24,544 Posts
                I quite often follow these three steps when my security permission changes don’t seem to be working:

                1. Security->Flush Permissions
                2. Site->Clear Cache
                3. Security->Flush All Sessions
                  Did I help you? Buy me a beer
                  Get my Book: MODX:The Official Guide
                  MODX info for everyone: http://bobsguides.com/modx.html
                  My MODX Extras
                  Bob's Guides is now hosted at A2 MODX Hosting