We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 21884
    • 57 Posts
    I’m using Mamp Pro on my mac for testing purposes, since the security features of Revo are quite advanced i figured i’d get the hang of it on my local copy first and then copy whatever I’d setup to my online setup.

    I setup 2 user groups besides the built-in Administrator, as well as 2 roles and ACLs

    when testing the Element Category access permissions I found that setting for one user-group was hiding that category from other groups. I couldn’t even create a setting to allow another user-group as the administrator account couldn’t see that Element Category anymore (tho since Admin should inherit all permissions, does that make sense?).

    On my local setup I first added all the categories to the Administrator user-group and then worked backwards from there, this worked fine for me, i’ve flushed permissions, cleared the cache, shutdown my browser, logged out and then back in, no problems.

    now proceeding to do exactly the same thing on my server setup, as soon as I’d set the Category Access rules for the Admin group, I was blocked from doing anything in the manager, logged out and then back in, first of all I could no longer see anything, no resources/elements/files, and clicking on anything in the menu would log me out. this meant i couldn’t even undo what I’d just done.

    I got access back by clearing the table in the database using phpmyadmin, but this seems to be a bug of sorts?

    both my Mamp Pro install and my online server use Apache 2+, PHP 5+ and while not 100% identical, are configured almost the same.

    besides, all the permissions settings are database entries so that shouldn’t matter from server to server, or not?
      • 3749
      • 24,544 Posts
      It’s easy to make a mistake in setting up the rules. Picking the wrong policy, authority level, or making the wrong kind of ACL entry can lock you out. I suspect that you slipped up somewhere (it’s happened to me plenty of times). As you say, there’s no disk access involved so the rules should have the same effect no matter what server you’re on.

      Is it possible that you were setting a Context Access ACL rather than an Element Category ACL? I don’t see any way that a Category Access ACL could lock you out of the Manager. At worst, it would hide some elements.

      I spent about three weeks banging on the permission system and it always did what it was supposed to (though not always what I wanted wink ).
        Did I help you? Buy me a beer
        Get my Book: MODX:The Official Guide
        MODX info for everyone: http://bobsguides.com/modx.html
        My MODX Extras
        Bob's Guides is now hosted at A2 MODX Hosting
        • 21884
        • 57 Posts
        thanks Bob,

        I’m fairly certain the error is mine, I’m not sure how I did it though laugh

        but for certain, the identical settings that work on one server don’t work on another server, i took my "offline" install, uploaded it, cleared the cache made changes in config and all that, load the manager and same bug.

        basically i’ve allocated permissions to every category there is, and it seems that while the Admin has access offline, on my online server he doesn’t.

        I found that elements should use the Element ACL so I corrected my errors there.

        Would anyone know if it’s normal behaviour that once a category has been assigned to a higher level user group that the lower levels including the SuperUser would no longer have access to that category?

        example: (user/usergroup/role/acl)

        admin/Administrator/Super User/Administrator

        if i set category access for the admin user group, and add all categories, when i flush permissions/clear cache/log out and back in everything is blocked, i can’t see the resources/files/elements trees on the left, nothing on the right, and any menu item I click on logs me out.

        only way to fix is to manually delete the entries from the database using phpMyAdmin
          • 3749
          • 24,544 Posts
          Is is possible that you have the authority numbers for the roles backwards? The admin Super User should always have a policy with an authority level of 0. The term "minimum role" can be confusing. Lower numbers have more authority. And users do inherit the permissions of other roles in the ACL for that group with *higher* numbers.
            Did I help you? Buy me a beer
            Get my Book: MODX:The Official Guide
            MODX info for everyone: http://bobsguides.com/modx.html
            My MODX Extras
            Bob's Guides is now hosted at A2 MODX Hosting