I’m trying to restrict the editor user to only see/edit and add to only certain resources, while allowing all the resources to be visible from the web.
I’ve set up a resource group(AdminOnly) and added all the resources that I don’t want the editor to see in it
then I added the resource group to the (anonymous) user group under Resource Group Access
AdminOnly Member - 9999 Load Only web
and it’s not working, any idea what I’m doing wrong?
Add-On to easily manage your multilingual sites:
Babel
I just tried it again, and it works, but I feel like it’s a really odd way of doing it, or that I don’t understand why it worked.
I added all the resources that I want hidden to my hideFromEditor resource group
then I changed the access control for the Administrator group:
hideFromEditor Member - 9999 Administrator mgr
that’s all, and now editor doesn’t see it in the manager, and everyone sees everything in web context
My problem, stemming from not understanding how exactly this system works, is that editing one user group(Admins) effected another user group(Editors). Anyhow, I’m glad it works.
Every time you create an ACL entry that ties a a particular context or resource group to a particular user group, that "protects" it from all other users.
BTW, you might look into the tree_root_id user setting, which is much simpler and limits users to a particular part of the Resource tree.