We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 24865
    • 289 Posts
    Hey guys,

    I’ve recently built another MODx website for a customer and after applying the access policies, the user couldn’t access the file tree anymore. So, I tracked the problem to the processor getList.php from the browser folder and it posts a request as "web". Now, the user has all permissions enabled (Administrator Template) and yet he can’t see any files. The return is "[]" in the XHR console and when I dump the scriptProperties in the file, this is what I get:

    Array
    (
        [action] => getList
        [id] => /
        [prependPath] => 
        [hideFiles] => false
        [ctx] => web
        [node] => /
        [HTTP_MODAUTH] => modx-non-of-your-business-:)
    )
    


    So, I also tried it with my own administrator (created in the setup) user and I got this:

    Array
    (
        [action] => getList
        [id] => /
        [prependPath] => 
        [hideFiles] => false
        [ctx] => web
        [node] => /
        [HTTP_MODAUTH] => modx-non-of-your-business-:)
    )
    


    Strangely enough, this produces a perfect file list. So, I checked the rights.

    /* get permissions available */
    $canChmodDirs = $modx->hasPermission('directory_chmod');
    $canCreateDirs = $modx->hasPermission('directory_create');
    $canListDirs = $modx->hasPermission('directory_list');
    $canRemoveDirs = $modx->hasPermission('directory_remove');
    $canUpdateDirs = $modx->hasPermission('directory_update');
    $canListFiles = $modx->hasPermission('file_list');
    $canRemoveFile = $modx->hasPermission('file_remove');
    $canUpdateFile = $modx->hasPermission('file_update');
    $canUpload = $modx->hasPermission('file_upload');
    
    var_dump($canListDirs);
    exit();


    Now, my own administrator user tells me "bool(true)" and for the custom user, it tells me "bool(false)". Now, the permission I am checking is "directory_list". A quick glance at the policies template tells me that the user indeed has those rights.

    (JSON) "directory_chmod":true,"directory_create":true,"directory_list":true,"directory_remove":true,"directory_update":true


    So, what am I missing? Is it a bug? Is it a bird? Is it a plane? I don’t know where to search anymore and frankly this is costing way more time than I calculated.
      @MarkGHErnst

      Developer at Adwise Internetmarketing, the Netherlands.