We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 3164
    • 4 Posts
    When I define management-users that have only access to certain document groups, all seems to work fine.
    In the manager, they only see, what they are supposed to see.

    But when they manually call for example "index.php?a=6&id=xy" they may delete whatever document xy is.
    There seems to be no further check of the privileges. (I run 0.961)

    Can anybody confirm this behavior?
      • 3164
      • 4 Posts
      Just one question: can anybody reproduce this in his/her installation?
        • 33337
        • 3,975 Posts
        Hmm... not sure about it, but thanks for heads up.

        I’ll try to make sure this doesnt slip under the radar.
          Zaigham R - MODX Professional | Skype | Email | Twitter

          Digging the interwebs for #MODX gems and bringing it to you. modx.link
          • 33337
          • 3,975 Posts
          I just tried and it gives me permission error. Though I have checked with 0962 rc2.

          Can you confirm if you have proper role assigned to that person and assigned role prohibits the deletion?
            Zaigham R - MODX Professional | Skype | Email | Twitter

            Digging the interwebs for #MODX gems and bringing it to you. modx.link