I thought that’s what I did...
Maybe this will be easier... Here’s my step-by-step, hopefully someone can tell me where I’m doing it wrong...
Set Up Resource
[list]
- 1. Create resource X (as child of resource "chapters")
- 2. Create resource group X
- 3. Assign resource X to resource group X
Set Up User(s)
- 4. Create user "Bob"
- 5. Create user group X
- 6. Create role "Chapter Editor" with value of 100
- 7. Assign user "Bob" to user group X with role of "Chapter Editor"
- 8. Assign site admin to group X with role of "Super User"
Set Up Policies
- 9. Duplicate Content Editor policy as "Chapter Editor"
- 10. Disable the following permissions in "Chapter Editor" policy:
[list]
[li]delete_document
- new_document
[/li]
[/list]
Assign Policies
- Updating user group X:
[list]
[li]11. Add context:
[list]
[li]context: web
- minimum role: Member 9999
- access policy: Load Only
[/li]
[li]12. Add context:
- context: web
- minimum role: Chapter Editor 100
- access policy: Chapter Editor
[/li]
[li]13. Add context:
- context: mgr
- minimum role: Chapter Editor 100
- access policy: Chapter Editor
[/li]
[li]14. Add resource group:
- resource group: X
- minimum role: Chapter Editor 100
- access policy: Object
- context: mgr
[/li]
[li]15. Add resource group:
- resource group: X
- minimum role: Chapter Editor 100
- access policy: Object
- context: web
[/li]
[/list]
[/li]
[/list]
With this setup, the manager shows the resources tab, but not the tree... So... I had to go turn on the "list" permission. (Odd that that’s not on by default for "Content Editor")
So, now that you can see resources... You are able to edit
any resource.
I figured that since I was setting edit_document access to the whole context that I should also try duplicating the "Chapters Editor" policy into "Lister" with the "edit_document" permission disabled. I then changed the context assignment policies for Chapter Editors to Lister. I thought that would let me see (but not modify) any records, but that the resource group policy would add the ability to edit whatever pages belonged to it. However, when I do all this, the only thing that changes is that I can no longer edit
any documents--including the one I need to.
EDIT: I had mentioned this in my draft, but deleted it before posting: When I go to add a Resource Group Policy to user group X, the only options I have for policies are "Load Only"; "Load, List, and View"; "Object"; and "Resource".
After that, I even tried manually going into the database in the table modx_access_resource_groups and changing the policy numbers to my custom "Chapter Editor" policy... In the resource group access tab, the name of my custom policy showed up just fine, but when updating the policy, it reverts to the id number, and, again, only lists the aforementioned options as selectable. I flushed permissions, and still couldn’t edit resource X (or any resource).
[/list]