I’m having trouble getting my head around permissions and resource policies and access controls and God knows what it’s called...
I’ve made a blog where I want three different bloggers to have access only to their own blog. So, what I want to do is this:
Give one user access to only one folder in the resource tree - to be able to create new resources in that folder etc.
Can anyone give simple step-by-step instructions to how this is done in MODx 2.0.6?
It’s pretty urgent so a fast response would be much appreciated. Thanks in advance!
If you’re in a hurry, you can just create a tree_root_id User Setting for each user with the ID of their container page. That will hide everything else in the Resource tree.
Note that it’s not real security, however, because they can still edit the other resources from the Manager if they can guess the correct Manager URL to enter, though the resources will be invisible to them until then.
I don’t have time to break it down in the neatest steps and this is untested, but:
1. You’ll need three different resource groups - one for each blog - but only one access policy (Content Editor). Add each blog to a resource group.
2. Create three different user groups of Blog A Editor, Blog B Editor, Blog C Editor (whatever)
3. Add the appropriate user to the appropriate group as role = Member
4. Add the same contexts (mgr and web) for each user with the same role
5. Add specific resource groups to each user group (ie Blog A Editor gets Resource Group Blog A, Blog B Editor Blog B etc). Make sure admin still has access to all resource groups.
6. Flush permissions and clear cache
I think that’s everything. There may be a cleverer way to do it using User settings (as effectively only one parameter changes per user), but I can’t say for sure. (ie what @BobRay said)
Writer > E-consultant > MODx developer || Salesforce || modx 2.x || PHP 5.2.13 || MySQL client 5.0.86
The process odeclass has listed is a good one. Let me just add a couple of reminders to it.
1. When you create the user groups, add the admin to them right away with a role of admin Super User to make sure that you don’t lose access to any resources during the process.
2. If there are resources outside of the blog groups that you want to protect, you’ll have to put them in a fourth resources group and connect that resource group to the Administrator user group with a Resource Group Access ACL entry (with a context of mgr).
3. When creating the Resource Group Access ACL entries, don’t assign ’web’ as the context unless you also want to restrict access in the front end.