We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 10999
    • 6 Posts
    I’m running 2.0.8-pl and I was experimenting with permissions. I basically was duplicating the permission set up in this video (http://rtfm.modx.com/display/revolution21/Security) and found an issue that I can’t resolve. I set my custom user group to have all admin permissions but they still see no files listed in the File Manager. They can upload files which arrive but they can’t view any files.
      • 3749
      • 24,544 Posts
      Does the user group have a Context Access ACL entry for the web context? They need to, because that context is protected by the admin group Context ACL Entry for it.
        Did I help you? Buy me a beer
        Get my Book: MODX:The Official Guide
        MODX info for everyone: http://bobsguides.com/modx.html
        My MODX Extras
        Bob's Guides is now hosted at A2 MODX Hosting
        • 10999
        • 6 Posts
        Thanks. They had one that was set up with the role of Member and the Access Policy of Object. But, I just tried adding one with the Access Policy of Administrator and now they can see the files.

        I’m really not very clear on Modx’s ACL model yet. It seems pretty confusing. I don’t understand what the web context has to do with modifying the raw files through the backend. Also I think it’s confusing to have the three tabs (Context Access, Resource Group Access, and Element Category Access) and then kind of share the Access Policies between them but some aren’t listed when adding certain entries. Is there a good tutorial on the different default Access Policies and how they’re suppose to be used?

        Also I noticed that the super-user account has an ACL entry with the Access Policy of Resource but that isn’t an option when making your own entries. I though that was strange.
          • 10999
          • 6 Posts
          After coming across the video in the docs I got side-tracked watching it and following along. After going back and reading through the rest of the section on Security it makes more sense and there is some very helpful information in the docs. But, I still think it’s confusing to have to assign an ACL entry to the web context so that the users can manipulate files in the backend.

          Anyway, I appreciate your quick response. It got me back on track minutes after I asked my question. Thanks again.
            • 3749
            • 24,544 Posts
            I’m glad you got it sorted. smiley

            There is some information here that may help if you haven’t seen it already: http://bobsguides.com/revolution-permissions.html

            The need for that web access ACL entry for non-admin users is kind of an anomaly since the web context is normally the front end. It threw me at first too. It’s necessary because without it, the user has no access to that context at all (since it’s protected by the Admin ACL entry for the web context) and therefore won’t see any of its resources.

            Each of the standard policies is only appropriate for certain kinds of ACL entries:

            Context Access ACL entries ==> Administrator policy
            Resource Group Access ACL entries ==> Resource policy
            Element Category Access ACL entries ==> Element policy

            In the current version of MODx, you’ll only see the ones that are appropriate when you create an ACL entry.

            Both of the default Administrator group Context Access ACL entries (for web and mgr) should have a policy of Administrator.

            If the admin has a policy of resource, it’s almost certainly in a Resource Group Access ACL entry that you created. If it’s in a Context Access ACL entry, it’s most likely one that you created or edited with an earlier version of MODx where all policies showed up for all ACL entries.

              Did I help you? Buy me a beer
              Get my Book: MODX:The Official Guide
              MODX info for everyone: http://bobsguides.com/modx.html
              My MODX Extras
              Bob's Guides is now hosted at A2 MODX Hosting
              • 10999
              • 6 Posts
              Thanks for the link! smiley
              I’m sure your site will be very helpful as I start exploring development using Modx.

              If the admin has a policy of resource, it’s almost certainly in a Resource Group Access ACL entry that you created. If it’s in a Context Access ACL entry, it’s most likely one that you created or edited with an earlier version of MODx where all policies showed up for all ACL entries.

              This was a fresh install and I didn’t add it myself. It’s possible it came from installing the modxss sample site.
                • 3749
                • 24,544 Posts
                Quote from: goatfish at Mar 28, 2011, 01:55 PM

                It’s possible it came from installing the modxss sample site.

                I think that’s probably it. I don’t have the sample site installed anywhere or I’d check.
                  Did I help you? Buy me a beer
                  Get my Book: MODX:The Official Guide
                  MODX info for everyone: http://bobsguides.com/modx.html
                  My MODX Extras
                  Bob's Guides is now hosted at A2 MODX Hosting