We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 34193
    • 330 Posts
    OK i’m trying to create a context that is a subdomain to the main site, I got this set up so the page will load np.

    I am now trying to set it up so that it is only visible to someone who is logged in.

    So this is what I did.

    1) On the context it’s self I left Access Permissions as the default which is
    Administrator group authority 9999 policy Resource
    Administrator group authority 9999 policy Administrator

    As there is no policy allocated for anon uses I assumed this would mean that if some one is not logged in they would not be able to access any of the pages in the context.

    I then flushed cache, permissions and sessions. even closed the browser and tried a different one to make sure. but anon uses still seem to be able to access the pages in this context.


    Any help appriciated.

    Using MODx Revolution 2.0.3-pl
    viewing in both Chrome and Firefox
      • 34193
      • 330 Posts
      Bump Posted before the weekend, bumping incase people missed it with being out of working hours.
        • 3698
        • 57 Posts
        I think that a resource in a resource group is protected only when this resource group is added to at least one user group.

        That said, I too have difficulties to get resource groups in other contexts as the web context to behave as they should. They are blocked in the front end even when the resource group is added to the user group. I’ll post on this issues in an extra thread in detail.

        -Andrea
          • 44234
          • 219 Posts
          Quote from: peteedley at Oct 02, 2010, 04:40 AM

          OK i’m trying to create a context that is a subdomain to the main site, I got this set up so the page will load np.

          I am now trying to set it up so that it is only visible to someone who is logged in.

          So this is what I did.

          1) On the context it’s self I left Access Permissions as the default which is
          Administrator group authority 9999 policy Resource
          Administrator group authority 9999 policy Administrator

          As there is no policy allocated for anon uses I assumed this would mean that if some one is not logged in they would not be able to access any of the pages in the context.

          I then flushed cache, permissions and sessions. even closed the browser and tried a different one to make sure. but anon uses still seem to be able to access the pages in this context.


          Any help appriciated.

          Using MODx Revolution 2.0.3-pl
          viewing in both Chrome and Firefox


          This is exactly what I am trying to achieve, does anyone have any idea how to do this?

          I have followed the same steps as peteedley but I am using Revo 2.0.8
            Find me on Twitter, GitHub or Google+
            • 22303 MODX Staff
            • 10,725 Posts
            I assume everyone experiencing this is using the plugin method to switchContext() based on the domain? I can confirm that this method is bypassing the security policy check on the Context, and so if cached, any user will be able to access it when it is switched to. This does not affect users using a custom index.php to initialize() the proper Context or those using separate index.php files per virtual host.

            You can track progress on this issue via bug #4605.
              • 22303 MODX Staff
              • 10,725 Posts
              Quote from: OpenGeek at May 04, 2011, 10:14 AM

              You can track progress on this issue via bug #4605.
              This is now fixed in the release-2.1.0 branch and will be in the 2.1.0-pl release, expected next week.
                • 34193
                • 330 Posts
                I can’t remember what the situation was with my initial post, and I did find a way around it (Can’t remember how), but I do know I wasn’t using the plugin I was using a custom index since this is the route I always use.
                  • 44234
                  • 219 Posts
                  I am also using a custom index.php, not the plugin method.

                  I have found another problem with my extra ’dev’ context. I have setup an ’admin only’ resource group that, in the frontend of the website, only allows administrators to view the documents it contains. This works perfectly in the ’web’ context but when I try and use it in my ’dev’ context, the documents are hidden in the frontend from the administrators group and the anonymous group. In the backend administrators can still see the docs.

                  I am certain I have the ACL’s and permissions etc all setup correctly as it works fine in the ’web’ context and I have mirrored the settings for the ’dev’. I have tested this clearing the cache, flushing permissions, clearing the browser cache, in different browsers, logged in and logged out to no avail.

                  Are the two problems related? Has anyone else experienced this or have a possible solution?

                  Any advice would be gratefully received
                    Find me on Twitter, GitHub or Google+
                    • 22303 MODX Staff
                    • 10,725 Posts
                    Quote from: romanum at May 05, 2011, 03:41 AM

                    I am also using a custom index.php, not the plugin method.

                    I have found another problem with my extra ’dev’ context. I have setup an ’admin only’ resource group that, in the frontend of the website, only allows administrators to view the documents it contains. This works perfectly in the ’web’ context but when I try and use it in my ’dev’ context, the documents are hidden in the frontend from the administrators group and the anonymous group. In the backend administrators can still see the docs.

                    I am certain I have the ACL’s and permissions etc all setup correctly as it works fine in the ’web’ context and I have mirrored the settings for the ’dev’. I have tested this clearing the cache, flushing permissions, clearing the browser cache, in different browsers, logged in and logged out to no avail.

                    Are the two problems related? Has anyone else experienced this or have a possible solution?

                    Any advice would be gratefully received

                    Are the other Contexts on different domains? If so, you have to login to those separately, since the PHP session cookies cannot be shared across domains. They will also not be shared across subdomains unless you configure the session_cookie_domain to specifically allow subdomains, e.g. .domain.tld to allow sharing of the session across all subdomains of domain.tld.