-
☆ A M B ☆
- 24,524 Posts
This is a legacy issue, originally Etomite had no web (front-end) login, and MODx was a set of modifications that, among other things, added that feature. In any case, you can in fact be logged in as both Manager user and Web user. It just adds a lot more to the SESSION.
http://www.sottwell.com/article-sessions.html
(ignore that contact form in the sidebar, that’s a work in progress!)
MODx 0.9.7.x is going to combine Web and Manager users into one group, IIRC.
-
☆ A M B ☆
- 24,524 Posts
Yes. I’ve always thought it would have been better if the front-end authentication had been a "role", instead of a separate user management base altogether. Then you could have different front-end roles, one that can only view pages, one that can use QuickEdit and edit pages, etc.
Web users and manager users serve totally different purposes and merging them creates more potential disastrous mistakes with permissions in my opinion. As far as I’m concerned the problem that needed solving is that manager users do not automatically inherit web user permissions, not that web users are placed in the same permission pool as users that can make changes within the cms.
Although the user management does need some work I personally am very happy having a distinction in user management where it is much more difficult to mistakenly (or not) elevate a web user’s permissions to that of a manager user. Merging both user types into one pool is not the answer. I know that this is the direction MODx 097+ is taking but it would not surprise me if this was revisited in some future version.
One thing that I believe that would help make the distinction more understandable would be to separate the two in the document’s ’Access permissions’ section. Since the ’public’ turns off when you select a manger user it gives the impression that you are affecting the both groups. By separating them into individual set’s of controls the difference would be more understandable.
As far as manager vs. web groups, I think it is a good safety measure and from a safety pov I think it is great. I would like to see add/delete/duplicate features included in the quickedit. I don’t understand why these are not part of quickedit, but with these additional features I don’t think that there would be a need to have any snippet based page editors. By not including these in the core we are left to use snippets that bypass these restrictions which could lead to a more serious security issue.