We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 3698
    • 57 Posts
    Hi all,

    I want to restrict users to only see the resource tree beginning with Id 16.

    I did this by editing the user settings for one user resticting his access to tree_root_id, value 16. No problem. But quite cumbersome doing this for many users. Is there a way to reuse a set of permissions?

    -Andrea
      • 3749
      • 24,544 Posts
      If you want all users except the admin Super User restricted to resource 16 (and its descendants), set a user setting for the admin Super User with tree_root_id as 0 (do this first). Then set the tree_root_id System Setting to 16.

      If you need a different tree_root_id for each user, you need to set multiple user settings.
        Did I help you? Buy me a beer
        Get my Book: MODX:The Official Guide
        MODX info for everyone: http://bobsguides.com/modx.html
        My MODX Extras
        Bob's Guides is now hosted at A2 MODX Hosting
        • 3698
        • 57 Posts
        Thanks BobRay for the description of the workflow.

        Unfortunately I need 4 different tree_root_ids and other permissions/restrictions for about 10 to 20 users ....

        -Andrea
          • 22303 MODX Staff
          • 10,725 Posts
          FWIW, please remember, using tree_root_id is not a permission or a substitute for securing access to Resources; it is simply a setting that can be applied at the system, context, and/or user levels. If users know the id’s of other Resources, they will still be able to do what they want with them if they are smart enough to figure out how to change the id in the URL.
            • 3698
            • 57 Posts
            oh, thank you for clarification - I had a wrong concept of this.

            What would be the best way to forbid access to all resources but those under a certain ID (Intranet part of the website)?

            Should I create a context for those Intranet pages and add only ACLs for mrg and the Intranet-context to the restricted users?

            -Andrea

              • 3749
              • 24,544 Posts
              In that case, you’ll probably want to create resource groups and restrict the users access to them with Resource Group Access ACL entries.

              This might help: http://bobsguides.com/revolution-permissions.html

              FWIW, it’s possible to use a relatively simple snippet to make the user’s tree_root_id act like a permission in the front end. You could probably do the same thing in the Manager with a plugin.
                Did I help you? Buy me a beer
                Get my Book: MODX:The Official Guide
                MODX info for everyone: http://bobsguides.com/modx.html
                My MODX Extras
                Bob's Guides is now hosted at A2 MODX Hosting