We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 27086
    • 37 Posts
    Hello, everybody.
    I’ve been troubled by documents permissions.

    I set “user groups”, “Document groups”, “User/Document group links”.
    If New option “Show protected pages” on 0.9.6 is ON, All documents appear in the contents tree when limited users login.

    Of course, Limited users cannot select the non-authorized documents (with “You don’t have enough privileges for this action!” dialog).
    So, if “Show protected pages” is OFF, users can edit/delete only authorized documents.

    When “Show protected pages” is ON, pop up the right click menu on non-authorized documents (gray title), users can edit/delete!! shocked

    On deleting, delete function check the permission for the documents.
    /manager/processors/user_documents_permissions.class.php
    Line 100:
    	$sql = "SELECT DISTINCT sc.id 
    		FROM $tblsc sc 
    		LEFT JOIN $tbldg dg on dg.document = sc.id
    		LEFT JOIN $tbldgn dgn ON dgn.id = dg.document_group
    		WHERE sc.id = $document 
    		AND (1='' OR NOT(dgn.private_memgroup<=>1)".(!$docgrp ? "":" OR dg.document_group IN ($docgrp)").");";

    MySQL table &#147;modx_documentgroup_names&#148; have document group name and private_memgroup values.
    But all private_memgroup values are 0.

    So &#147;(1=’’ OR NOT(dgn.private_memgroup<=>1)".(!$docgrp ? "":" OR dg.document_group IN ($docgrp)").")&#148; is always TRUE! This SQL check all docid and $document and always return one result($document)...

    It&#146;s my misunderstanding or set up failure? I cannot find the code changing private_memgroup value(1/0).

    thx rgds.