Hi all,
I want to restrict users to only see the resource tree beginning with Id 16.
I did this by editing the user settings for one user resticting his access to tree_root_id, value 16. No problem. But quite cumbersome doing this for many users. Is there a way to reuse a set of permissions?
-Andrea
If you want all users except the admin Super User restricted to resource 16 (and its descendants), set a user setting for the admin Super User with tree_root_id as 0 (do this first). Then set the tree_root_id System Setting to 16.
If you need a different tree_root_id for each user, you need to set multiple user settings.
Thanks BobRay for the description of the workflow.
Unfortunately I need 4 different tree_root_ids and other permissions/restrictions for about 10 to 20 users ....
-Andrea
-
MODX Staff
- 10,725 Posts
FWIW, please remember, using tree_root_id is not a permission or a substitute for securing access to Resources; it is simply a setting that can be applied at the system, context, and/or user levels. If users know the id’s of other Resources, they will still be able to do what they want with them if they are smart enough to figure out how to change the id in the URL.
oh, thank you for clarification - I had a wrong concept of this.
What would be the best way to forbid access to all resources but those under a certain ID (Intranet part of the website)?
Should I create a context for those Intranet pages and add only ACLs for mrg and the Intranet-context to the restricted users?
-Andrea
In that case, you’ll probably want to create resource groups and restrict the users access to them with Resource Group Access ACL entries.
This might help:
http://bobsguides.com/revolution-permissions.html
FWIW, it’s possible to use a relatively simple snippet to make the user’s tree_root_id act like a permission in the front end. You could probably do the same thing in the Manager with a plugin.