We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 25315
    • 68 Posts
    Hi guys.

    I’m having trouble understanding the security system in revolution.
    I’m sure the security model is great, but it’s pretty hard to take in all the documented information on it, understand it and then do simple tasks.
    Does anyone else have this opinion, or is this just my own experience?

    My end goal is to create a user or users who have limited abilities.
    How can I do this?

    Thank.
      • 3749
      • 24,544 Posts
      It’s not you. It’s actually hard to get a grip on at first, especially if you’re not used to policy-based security systems.

      What you want to do, in a nutshell, is to duplicate the standard administrator policy. Then put users in a user group and update that user group in Security -> Access Controls. Create a Context Access ACL entry for the mgr Context with the duplicate policy you created (and a role with a higher authority number than the Admin). Then edit the duplicate policy and remove any permissions you don’t want them to have.

      That will limit what the users can do in the Manager.

      You can also put specific resources in Resource Groups and specific elements in Categories, then do something similar to the above, but duplicate the Resource policy (for resources) and the Element policy (for elements). You then create Resource Group Access ACL entries and Element Category Access ACL entries with the two respective policies and edit the policies to remove permissions as above. That will limit what users can do with the specific objects in the resource group or element category.

      You can also do a lot by just customizing the Manager. You can hide parts of the various forms using Form Customization. Hide parts of the Resource tree by setting a tree_root_id user setting. Hide parts of the File tree with a filemanager_path user setting. Hide the Element tree and File tree altogether by removing the element_tree and file_tree permissions in the duplicate admin policy. Use custom permissions to hide various Top Menu items and subitems.

      There’s more information here is you haven’t seen it already: http://bobsguides.com/revolution-permissions.html

        Did I help you? Buy me a beer
        Get my Book: MODX:The Official Guide
        MODX info for everyone: http://bobsguides.com/modx.html
        My MODX Extras
        Bob's Guides is now hosted at A2 MODX Hosting
        • 25315
        • 68 Posts
        Thanks.

        Yes, I did find the outline on bobsguide.
        It’s utterly comprehensive but way over my head. At least at the moment it is.

        So far, figuring out the security model is the hardest part of learning modx. But I’ll stick with it. I can see myself going back to the bobsguide outline.

        I found this tut in the docs, which seems to answer my question. But it could be written little more clearly:
        http://rtfm.modx.com/display/revolution20/Giving+a+User+Manager+Access

        Thanks for pointing me to form customisation.
        It looks to me like form customisation is also something I want to do.

        Cheers.