We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 28120
    • 380 Posts
    Can someone point me to some documentation that would explain how to:


    • Limit the parent to which a user can add resources
    • Limit a user to only be able to edit/delete content they’ve created

    This functionality is in the current drupal site that I’d lke to replace.
      • 28508
      • 73 Posts
      There are smarter guys than me around here, but I think you can solve that with Resource Group Access.

      Create a folder and add it to a resource group, then give a certain user access to it.
      Others now can’t see, edit or delete any resources in that folder.
      Don’t forget: You should give yourself or the admin also access to that folder, otherwise you can’t control it any more.

      You can find more info at http://rtfm.modx.com/display/revolution20/Resource+Groups
        • 28120
        • 380 Posts
        Thanks

        This is an option although it means my folder structure will be governed by security which may conflict with how I’d like to structure it for categorization and menus.

        I’d prefer greater granularity in Access Policy Permissions

        Regards

        Mark
          • 28508
          • 73 Posts
          Yeah you’re right, you’re not absolutely free with that...
          I don’t know if the MODx-guys have any plans to improve the ACLs, but 2.0.5 was a very big step forward concerning that.

          But actually I think it’s not a big deal any more to make such restrictions you have mentioned, it’s just not as easy as it is in Drupal (yet).

          Best regards,
          stetus
            • 3749
            • 24,544 Posts
            Quote from: sparkyhd at Jan 11, 2011, 10:13 AM

            Thanks

            This is an option although it means my folder structure will be governed by security which may conflict with how I’d like to structure it for categorization and menus.

            I’d prefer greater granularity in Access Policy Permissions

            Regards

            Mark

            I’m not sure what you mean. You can protect any page or any group of pages and you can give users access to any page or group of pages. Security permissions that are in the mgr context have no effect on what appears in the front end. You can also give users the right to "see" a document, and still control individually what else you can do with it (e.g. duplicate, publish, remove, edit, save, etc.).

            It’s true that setting up individual "member" areas is not as convenient as it might be, but with some effort, you can usually do exactly what you want.

            The general strategy is to protect all the pages on the site, by putting them in a resource group and giving the Administrator group a Resource Group Access ACL entry connecting them to the resource group in the mgr context.

            Then you create a user group and resource group for each "member" and give them access to their own resources the same way.

            You often need to also give them access to parents/ancestors of their areas but, with a policy of "load, list, and view" so they can see those pages (and their descendant) in the tree, but can’t edit them.

              Did I help you? Buy me a beer
              Get my Book: MODX:The Official Guide
              MODX info for everyone: http://bobsguides.com/modx.html
              My MODX Extras
              Bob's Guides is now hosted at A2 MODX Hosting