Just a few notes after spending a lot of time on the upgrade from 2.04 to 2.05:
If any custom permissions have been added to the Administrator policy in 2.04, they will be completely deleted in the upgrade process to 2.05 when that policy becomes the Administrator template. It might be good to add a more specific mention of this to the documentation at
http://rtfm.modx.com/display/revolution20/Upgrading+to+Revolution+2.0.5.
Fortunately I documented the ones I had added and it was easy to re-create them. A minor point: I created several new policies that used the Administrator template. Then I added my custom permissions to the Administrator template. After that, on the Access Policies tab list, the numbers in the Active Permissions column are always wrong--reporting "137 of 141" when it should be more like "86 of 141".
It would also be very helpful to include a list of any new permissions added to the default templates at the release of each upgrade. That’s important because we need to evaluate whether a new permission should be activated in our other policies. Without this I wind up doing a manual comparison check to see what’s changed.
And I’ve said it before, but it bears repeating: the permission "access_permissions" is too generic and used in way too many places. For instance, as I will note in another posting most Form Customization rules will fail if the user group does not have the access_permission right. And if that right is granted it gives the user access to pretty much everything under Access Controls--user groups, roles, access policies, and policy templates. Even if the menu option is removed, the action is still available; that’s not a minor security concern.
So I have had to make core edits to apply new, more specific permissions for access controls, document groups, resource groups, and user groups to tighten up security. Since there were default permissions in the system specific to form customization, messaging, user profiles, roles, and users it seems odd that specific permissions weren’t created for these other areas as well.
I hope these notes are helpful to both the core team and other users.