We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 26799
    • 177 Posts
    I’m just getting into PHP and I’m not sure there is an adequate event in modx to really pull this off very well. but for what it’s worth this will deny access of a specific role ID to the manager and redirect them back to their "startID" (set in user configuration).

    
    
    /////////////////////////////////////////////////
    //  M.A.D. "Manager Access Denial" v.5
    //
    // serves to deny access to manager based on a Role ID
    //
    //  Written By: Sandra Brooks, Gary Hussey
    /////////////////////////////////////////////////
    
    
    // Deny Role
    
    $madRole ='4'; // set this to the id of the Role you want to Deny
    
    include_once("config.inc.php");
    
    global $modx;
    global $action;
    
    
    $documentListing_array=array();
    $documentListing_array=$modx->documentListing;
    
    $REQUEST_URI=$_SERVER["REQUEST_URI"];
    
    if ($action == 1  || $madRole == '0'){return;} //keeps script from running more than once due to frames and makes sure that the admin isn't blocked from manager
    	
    
    	if($_SESSION["mgrRole"]==$madRole && $_REQUEST["a"]!="112"){		
    		
    		$user=$_SESSION["mgrInternalKey"];
    		
    		$page_query="select setting_value from $dbase.modx_user_settings where user=\"$user\" and setting_name=\"manager_login_startup\"";
    		$page_result = $modx->db->query($page_query);
    		$page_row = $modx->db->getRow($page_result);
    		$ID=$page_row["setting_value"];
    		
    		$alias=array_search($ID,$documentListing_array); 
    		$location="http://www.nbwconline.com/$alias";							
    		//$modx->sendRedirect($location);
    		//header("Location: http://www.nbwconline.com/$alias\n\n");
    		print "<script>window.open('".$location."','_top','',true)</script>"; 		
    		exit;
    	}
    
    
    



    Installation/configuration:

    install:
    #1. Copy and paste code into a new plugin
    #2. Set the plugin to listen to OnManagerPageInit

    Config:
    #1. set $madRole == ’Numeric role id’ <-- this is the numeric value of a role



    Planned Updates:

    #1. automatically get numeric value from role name
    #2. develop a better method for redirection (M.A.D. uses javascript in order to replace the frameset with the redirection url, making the whole thing do nothing if the client has js disabled)
      • 16610
      • 634 Posts
      Needed something like this because my recent client really needs users who only have permissions to front-end editing (QuickEdit).

      So, here is a little improvement to this plugin in case someone else may find it useful too:

      // deny role id
      $denyRole = 2;
      
      // keep script from running more than once due to frames
      if ($action == 1) return;
      
      // deny manager access but allow logout (a = 8) and quickedit (a = 112)
      if($_SESSION['mgrRole'] == $denyRole && $_REQUEST['a'] != '8' && $_REQUEST['a'] != '112') {
      
          // get base url
          $url = $modx->config['base_url'];
      
          // redirect to base url, requires javascript support
          print "<script>window.open(".$url.",'_top')</script>";
      
          // logout url
          $url = $modx->getManagerPath().'index.php?a=8';
      
          // if no javascript support logout automatically (very ugly outcome due to frames)
          $modx->sendRedirect($url, 0, 'REDIRECT_REFRESH');
      }


        Mikko Lammi, Owner at Maagit