We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 30524
    • 22 Posts
    Hello,

    I’m trying to set up a new Website with Modx 2.0.2-pl Revo. Everythink works fine but now I’m getting to a point where it won’t get any further.

    This Website I’m working on has two contexts. One is the default web and the other should be the sandbox. In this sandbox everyone can edit, delete, create and view but the Web-Context should be READONLY! That means all manageruser can read and view the resources but only a small group has the right to edit that context.


    I tried to give a user group the Load, List and View policy but then the User in this groups (with a high enough roll) can edit the content within the context.

    I read all the tutorials and watched the security screencast but i can’t find any clear answer.

    Is it posibile to give a usergroup only read access for a context?

    matic
      • 3749
      • 24,544 Posts
      There may be a simpler way, but I think you could create a resource group with all the resources in the sandbox context and a users group for just those users (plus the admin). Then create a Resource Group Access ACL for that user group/resource group/context with a policy that’s a duplicate of the Resource policy, but without save_resource or edit_resource.
        Did I help you? Buy me a beer
        Get my Book: MODX:The Official Guide
        MODX info for everyone: http://bobsguides.com/modx.html
        My MODX Extras
        Bob's Guides is now hosted at A2 MODX Hosting
        • 30524
        • 22 Posts
        Hey,

        I found following points out:

        The Context ACL ONLY effects the Context, but not the Resource Files within the Context. That means:

        If I have the Policy "Load, List and View" set to the "Web" - Context for the "Stuff" Group the users in the "Stuff" - Group cannot edit the context, but they all can add, delete, alter and view ALL files in the "Web" context. (If they generaly can do this action in the mgr)

        The Resource ACL acts almost the same. One difference is that I can choose whether the resource group should affect the Frontend - Area or the Manager (by chooceing Context "Mgr" or "Web").

        It is right that i can create a resource group for all my files in the Web-Context but that wont disable adding files to the Web Context. I believe the problem is that the mgr context acl with the a altered version of the admin policy will always enable this function in the manager and so i have no chance to disable "create resource" in a special context for a speciel usergroup.

        Am I right or do i only misuse the security component of modx revo? Did I make my point clear enough?
          • 3749
          • 24,544 Posts
          Restricting access for the same users in the front end and back end is always tricky and hard to explain. It’s not clear

          See if this helps:

          Context Access ACLs set to mgr control what the person can do, in general, in the Manager.
          Context Access ACLs set to web control what the person can do, in general, in the front end.

          Resource Group Access ACLs control what users can do *with specific resources* in a context (assuming that they have the above permissions for that context).

          § Policies assigned on the Context Access tab should be based on the standard Administrator policy.
          § Policies assigned on the Resource Group Access tab should be based on the standard Resource policy.
          § Policies assigned on the Element Category Access tab should be based on the standard Element policy.

          If a user doesn’t have the save_resource permission in the Resource Group Access ACL entry, they won’t be able to save a resource even if they have permission in the Context Access ACL entry. Same with the other resource-specific permissions.

          Creating a tree_root_id user setting, can prevent users from seeing any resources at all outside the context in the Manager. A snippet in your template could make that apply in the front end as well.

          How, exactly are your users creating, editing, and saving resources in the front end?

          There is another approach you might consider. Go ahead and let the users modify the sandbox resources, but periodically restore them all with a snippet or plugin that copies them over from the other context.
            Did I help you? Buy me a beer
            Get my Book: MODX:The Official Guide
            MODX info for everyone: http://bobsguides.com/modx.html
            My MODX Extras
            Bob's Guides is now hosted at A2 MODX Hosting
            • 30524
            • 22 Posts
            Hey,

            sorry for the late reply.

            I think I was not clear enough. The Users don’t edit the resource in frontend and backend. They only edit the pages in the manager. The thing what I’m trying to do is following:

            There are two contexts: web and sandbox (both in the manager)
            I have two groups of User "Admins" and "Stuff"
            Admin can edit any Context (web and sandbox) in the manager
            The Stuff group should only be able to edit the sandbox context and see/view the web context (not edit) (all in the manager)

            What i did:

            I created to more policies by duplicate the admin policy then I removed some core features like packages, system setting, flush_session etc in the policy i called "standard_mgr". In the second one I removed more permissions like save_document, save, edit_document, remove and so on. (All permissions that have something to do with the resources) and i called this one "read_context".

            Now I went to Staff-Group -> Context ACL Tab and edit the ACLs:

            1. mgr - lowest role in group - standard_mgr
            2. web - lowest role in group - read_context
            3. sandbox - lowest role in group - standard_mgr

            Surely, I put the users in this group and they have the right role.

            Result:

            A stuff user can create,edit,remove any document in both context. I looks like that the mgr context policy just overwrites all other.

            thank you for your help. smiley
              • 3749
              • 24,544 Posts
              Let me say that I’ve never done what you’re trying to do, but I think what you need to do (in addition to what you have) is:

              1. Put all the resources in the sandbox context in a resource group
              2. Duplicate the standard resource policy.
              3. Update the Admin group with a Resource Group Access ACL entry to give admins access to that resource group in the sandbox context with a policy of Resource.
              4. Update the staff users group and add a Resource Group Access ACL entry to give the staff users access to the resource group with a context of sandbox and a policy of -- the duplicate resource policy.
              5. Edit the duplicate resource policy to remove unwanted permissions.

              Hope this helps.
                Did I help you? Buy me a beer
                Get my Book: MODX:The Official Guide
                MODX info for everyone: http://bobsguides.com/modx.html
                My MODX Extras
                Bob's Guides is now hosted at A2 MODX Hosting