Ok, I did a little more testing.
I created a RESOURCE, and placed it inside the EMPLOYEE RESOURCES resource group. Then I edited the ADMINISTRATOR user group, in the ACCESS CONTROL page, and under the RESOURCE GROUP ACCESS tab I added the following to both the web and the mgr contexts:
Resource group: Employee Resources
Minimum Role: Super User - 0
Access Policy: Administrator
Context: web/mgr
I then flushed all permissions, and cleared the cache.
But now the RESOURCE won’t appear in the front-end anymore, even though I’m logged in as Super User. And when I try to delete the RESOURCE in the manager, I get a Permission Denied error. I can still edit the resource, but not delete it.
I tried to write the URL to that RESOURCE in my browser, and then I could access it as Super User, but not as an ANONYMOUS user, so it kind of works. I can access it, but getResources won’t show it...
Anyone else had problem with permissions and getResources?
My call to getResources looks like this:
[[getResources?
&tpl=`mediaTabsTpl`
&includeTVs=`1`
&limit=`10`
&parents=`[[*id]]`
&sortby=`id`
&sortdir=`ASC`
]]