We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 15953
    • 123 Posts
    The security in Revo mystifies me. I can’t even get past first base on setting up a common user to edit resources. I created a user, assigned him to Editors group, gave Editors Group mgr context access with minimum role of "Resource Editor - 10" and Resource access policy, Resource Group Access to "Teams" which includes the pages he needs to edit.

    Can someone give me an example?
      • 3749
      • 24,544 Posts
      First of all, the policies in any Context Access ACL entry should be based on the Administrator policy (not resource).
      You’ll want to duplicate that policy, make sure everything works, then edit the policy to remove unwanted permissions.

      Policies in Resource Group Access ACL entries should be based on the Resource policy.
      Again, if you will be restricting the user, you’ll want to duplicate the policy, use the duplicate, and edit it to remove permissions.

      You also need to give your Editors group a Context Access entry for access to the ’web’ context so they can see resources in the ’web’ context in the tree.

      This may help: http://bobsguides.com/revolution-permissions.html
        Did I help you? Buy me a beer
        Get my Book: MODX:The Official Guide
        MODX info for everyone: http://bobsguides.com/modx.html
        My MODX Extras
        Bob's Guides is now hosted at A2 MODX Hosting
        • 15953
        • 123 Posts
        @BobRay
        First of all, the policies in any Context Access ACL entry should be based on the Administrator policy...
        Policies in Resource Group Access ACL entries should be based on the Resource policy...

        Very important points, both of which solved my problem. Is the Resource policy a subset of the Administrator policy (that was my assumption), and if so what is different that it doesn’t give user proper Context Access?

        Is there really any need to have user groups other than Administrator? It seems you can restrict access via resource groups, minimum roles, and access policies.
          • 15953
          • 123 Posts
          Uh-Oh! Big problem. After following BobRay’s suggestions I cleaned up permissions, etc, and have now disabled everyone’s ability to access our web site. What do I need for the general public to view the site?
            • 3749
            • 24,544 Posts
            Whatever you did with resource groups in the ’web’ context, you also need to do for the Anonymous user group, but just give them the "load only" policy (or, if that doesn’t work, "load, list, and view."
            When you connect a resource group to a user group in the ’web’ context, resources in that group are now protected. Nobody can access them in the front end (web context) without being given explicit access to them.

            BTW, if you don’t need to hide specific resources from specific users in the front end you can just delete any Resource Group Access ACL entries with a ’web’ context and they’ll be unprotected in the front end. If there’s Resource Group Access ACL entry with a context of ’mgr’, they’ll still be protected in the Manager.

            With respect to the Resource and Administrator policies, they are completely different.

            The Administrator policy governs what actions a user can perform in the Manager.
            The Resource policy governs what a user can do with specific resource objects.
            The Element policy governs what a user can do with specific element objects (e.g. snippets, plugins, chunks, etc.).

              Did I help you? Buy me a beer
              Get my Book: MODX:The Official Guide
              MODX info for everyone: http://bobsguides.com/modx.html
              My MODX Extras
              Bob's Guides is now hosted at A2 MODX Hosting