I stumbled across this, so I thought it might be helpful to put here. In short, when previewing "member only" pages, WayFinder obeys the permissions of the user logged into the front end (ie. web context), but
it will fall back to the permissions of the manager user if nobody is logged into the web context.
We have a site with multiple users logging in via the front end. Each user group gets access to a corresponding resource group, e.g. clientA logs in and gains access to oursite.com/clienta/ and all docs there (in a Resource Group dedicated to Client A).
We put a WayFinder call on the portal page so after logging in, it properly displays any client sites that the user has permissions to view. Great! Works perfectly!
HOWEVER... we discovered that WayFinder falls back to the manager context if there isn’t a user logged into the web context. Let me explain the setup a bit more: all the clients’ pages on the front end are in a dedicated Resource Group for each client, AND all client pages are in an "Admin Visible" resource group so if an admin user logs into the front end, they can see all the client sites. If you are logged in ONLY to the manager and you are editing pages, and you preview the portal page, WayFinder will display all the pages that your admin user would have permissions to see if you had logged into the front-end. BUT, if you actually DO login to the front end, say with a less powerful user, WayFinder will use THOSE permissions instead. WayFinder is looking for a user logged into the current context (web), and if it doesn’t find one, it falls back to the user logged into the manager context. It makes sense when I think about it, but I wasn’t expecting that. Or is this a MODx thing built to handle the special case of previewing documents from within the manager? The context of the page is "web", but you instigated it from the "mgr", so it’s kinda a special case, no?
Thought I’d share. Seems similar to
http://modxcms.com/forums/index.php/topic,58566.0.html