We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 10534
    • 40 Posts
    Sorry for this... again a security topic!

    What I’m trying to do, is to create a Manager usergroup which has a subset of rights of the global admin group.
    This Manager (this his/her rules subset) should also have _some_ access-permission rules. When i give the usergroup the permission "access_permissions" & "view_user/save_user" the manager is able to see, edit and save _all_ users. What I want, is to be able to give the manager rights to edit/save users of their own usergroup (and a level lower: members, which are created via the login/register snippet). In other words: this group should be able to manage ’webusers’: activate/deactivate, manage userfields, send new passwords, etc.

    I’ve tried some things with the Actions Menu and custom permission keys, but this does not effect the ’user management’ system (/security/user/).

    Any ideas? Is this possible or am I stretching it too far for now; perhaps only possible with a custom module?
      • 28215
      • 4,149 Posts
      It would definitely only be possible with custom code; UserGroup-specific rights applying to targets of other Users is not yet available in MODx Revolution.
        shaun mccormick | bigcommerce mgr of software engineering, former modx co-architect | github | splittingred.com
        • 10534
        • 40 Posts
        Been busy with setting up a module to be able to do this; but I’m a bit dazzled by the MODext calls....
        For example, I’d like to be able to add an extra function to the bulk actions: "Active & send generated password to selected users".

        The "Activate selected" method uses a MODx.Ajax.request with param: "activateMultiple"; where do I find these calls, and how/where can I make my own extra methods?
        What my new call would do is: activate the user, let MODx generate a password and email it to the user (this is possible from the userdetail page).

        Furthermore, would it also be possible to send a user his old password? Passwords are stored encrypted (or hashed), and the ’login’ extension also sends out new password, so my guess would be "no", but perhaps I’m mistaken..?
        The userpanel (MODext widget: modx.panel.user.js) uses "modx-user-newpassword" together with "modx-user-password-genmethod-g" and "modx-user-password-genmethod-s" (generate / specifiy); how should I adapt these calls, where do they hook into? I can’t seem to find the proper php calls sad


        thnx for the help!


        //edit
        Hm, found out that every Ext extended function has it’s counterpart here: "core/model/modx/processors/security/user/{function}"
          • 10534
          • 40 Posts
          I’m trying to get this logic into a custom action menu and manager page(s), and I’m wondering how I could get the custom "activateMultiple" php out of the core/model folder.

          I’ve set up custom module in "core/components/ledenbeheer/", with calls to custom MODext JS files situated in "assets/components/ledenbeheer/".
          But one of these JS files is a customized "modx.grid.user.js" file wich has an extra function: "activateWithEmailSelected", wich is based on "activateSelected", with some extra code to generate a password and send an email to selected members.

          The problem is that I have to create a file in the folder "core/model/modx/processors/security/user" with name "activatemultiplewithemail.php". This should still be seen as a subpackage of processors.security.user, because I still use this system, but is there any way to get this file into "core/components/ledenbeheer"?

          I’m stil using "url: MODx.config.connectors_url+’security/user.php’" in the JS file. Am I doing it all wrong, should I create an entire ’copy’ of the user system or is it OK to hook into the user system this way?
            • 28215
            • 4,149 Posts
            You could either:

            1) Copy the files in the processors/security/user/ directory into your 3PC and add activateMultipleWithEmail there.
            2) Change the target URL of *only* activateMultipleWithEmail to your 3PC connector rather than MODx.config.connectors_url+’security/user.php’

            2 would be preferred.
              shaun mccormick | bigcommerce mgr of software engineering, former modx co-architect | github | splittingred.com
              • 10534
              • 40 Posts
              Thanks for the help! It really is something to get development going in MODx Revo (in comparison to Evo), but it is really awesome stuff; many thanks for this excellent CMF(/CMS)!!