We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 16815
    • 49 Posts
    I have a site where I would like some of the resources only to be accessible by members of that site.

    I display several resources inside a parent resource using a tabbed interface generated by jQuery. To generate all the tabs and the content divs I use getResources snippet. Some of the resources are accessible to everyone, but some are just to members (using Resource Groups and edit the Resource Group Access in a User Group). But getResources shows every resource all the time, even if I’m logged in or out.

    So my question is, does the snippet respect the permissions to each resource, or is this something I have to define in a property?

    Thanks
      • 3749
      • 24,544 Posts
      If you’ve set proper ACL entries to protect the resources in the front end, getResources should honor them.

      If you’ve protected them in some other way (e.g. with a custom snippet or plugin), getResources won’t know about that.
        Did I help you? Buy me a beer
        Get my Book: MODX:The Official Guide
        MODX info for everyone: http://bobsguides.com/modx.html
        My MODX Extras
        Bob's Guides is now hosted at A2 MODX Hosting
        • 16815
        • 49 Posts
        Ok, I did a little more testing.

        I created a RESOURCE, and placed it inside the EMPLOYEE RESOURCES resource group. Then I edited the ADMINISTRATOR user group, in the ACCESS CONTROL page, and under the RESOURCE GROUP ACCESS tab I added the following to both the web and the mgr contexts:

        Resource group: Employee Resources
        Minimum Role: Super User - 0
        Access Policy: Administrator
        Context: web/mgr

        I then flushed all permissions, and cleared the cache.

        But now the RESOURCE won’t appear in the front-end anymore, even though I’m logged in as Super User. And when I try to delete the RESOURCE in the manager, I get a Permission Denied error. I can still edit the resource, but not delete it.

        I tried to write the URL to that RESOURCE in my browser, and then I could access it as Super User, but not as an ANONYMOUS user, so it kind of works. I can access it, but getResources won’t show it...

        Anyone else had problem with permissions and getResources?

        My call to getResources looks like this:
        [[getResources? 
          &tpl=`mediaTabsTpl`
          &includeTVs=`1`
          &limit=`10` 
          &parents=`[[*id]]`
          &sortby=`id`
          &sortdir=`ASC`
        ]]
          • 16815
          • 49 Posts
          Quote from: BobRay at Jul 29, 2010, 06:21 PM

          If you’ve protected them in some other way (e.g. with a custom snippet or plugin), getResources won’t know about that.

          I have no snippet or plugin that controls permission as far as I can tell smiley
            • 16815
            • 49 Posts
            I think I have found a solution, at least to the front-end problem. My getResources call was cached, so I now call getResources without caching, and the behavior is normal.

            But I still don’t understand why I can’t delete the resource as long as it is in the Employee Group, even if I have all permissions...
              • 3749
              • 24,544 Posts
              Is your Resource Group Access ACL entry for it based on the the Resource policy (it should be)?
                Did I help you? Buy me a beer
                Get my Book: MODX:The Official Guide
                MODX info for everyone: http://bobsguides.com/modx.html
                My MODX Extras
                Bob's Guides is now hosted at A2 MODX Hosting
                • 16815
                • 49 Posts
                Quote from: BobRay at Jul 30, 2010, 03:57 PM

                Is your Resource Group Access ACL entry for it based on the the Resource policy (it should be)?

                No it wasn’t. But I just changed it, and now it works. Why can I delete the resource with the Resource Policy, but not with the Administrator Policy? I thought the Administrator policy had all permissions...

                Thanks for the help BobRay smiley
                  • 3749
                  • 24,544 Posts
                  It’s a common misunderstanding (I had it for a long time). The Administrator policy gives you the right to perform all *actions* in the manager. But for protected *objects* (e.g. resources and elements), you also need a policy that gives you rights to do things with those *objects* themselves -- a Resource or Element policy. For protected resources and elements, neither one will work without the other.

                  IOW, your user had the right to delete resources in the Manager, but not the "object" policy that would let them delete those specific objects.

                  You can avoid this problem with the following general rules:

                  § Policies assigned on the Context Access tab should be based on the standard Administrator policy.
                  § Policies assigned on the Resource Group Access tab should be based on the standard Resource policy.
                  § Policies assigned on the Element Category Access tab should be based on the standard Element policy.
                    Did I help you? Buy me a beer
                    Get my Book: MODX:The Official Guide
                    MODX info for everyone: http://bobsguides.com/modx.html
                    My MODX Extras
                    Bob's Guides is now hosted at A2 MODX Hosting
                    • 16815
                    • 49 Posts
                    Thanks again.

                    I must admit that the whole security/permission system in Revo is complicated. But as I’m understanding more and more I see how powerfull it is.
                      • 38155
                      • 1 Posts
                      I have same query for getPage. I an listing all resources with the help of getPage using getResources as &element property, inorder to paginate list of items. There are certain resources which do not have view rpermission for all users. But getPage is making page links ( first << 1 2 3 .. >> last) as if it is counting all the items though the items are not rendered.