Hi
I’m baffled by the security model in Revo.
The tutorials I find seem to start with setting a list of resources that a user can edit. But I want to create a user with access to all resources – who can also create new ones – but who can’t alter the elements I’ve locked for editing.
Can someone point me in the right direction?
Thanks.
It don't mean nuffink.
Hi Jeff
I’m on the forums for the very same reason - could not find anything that made sequential sense. Let me now if you solve the challenge...
Just to add my voice to this request - some sequential guides about a small number of simple, specific security examples would be exceptionally useful.
To limit the users’ actions in the Manager, you don’t need any resource groups. You just need to assign them a policy in the mgr context that has fewer permissions.
Go to Security->Access Controls->Roles tab
Create a role called Editor with an authority level of 5.
If you have the current dev. version:
Click on the Policy Templates tab
Duplicate the AdministratorTemplate Policy Template; call it AdminEditorTemplate
Create a new policy called AdminEditor based on that template
If you don’t:
Click on the Access Policies tab.
Duplicate the Administrator Policy; Call it AdminEditor
Click on the User Groups tab; right-click on the Administrator user group and select Update User Group.
Click on the Context Access tab
Click on Add Context
You’re creating a Context Access ACL entry; use the following settings:
Context: mgr
Minimum Role: Editor
Access Policy: AdminEditor
Save it.
Click on the Users tab
Add the user(s) to the Administrator user group with a role of Editor.
Click on the Access Policies tab
Right-click on the AdminEditor policy and select Update Policy.
If you have the current dev. version, there will be checkboxes next to each permission; just uncheck the ones you don’t want them to have.
If you don’t, you need to right-click on the permissions and select "remove permission" -- you might want to make a list of the ones you removed in case you decide to add them back.
If you need to give different permissions to different users, create a new role with a different authority number and a new policy for each group of users that will share a set of permissions and add them to the Administrator group with those roles and repeat the steps above to create a Context Access ACL entry for each group with the appropriate policy.
Remember that users will inherit the permissions of policies in the Context Access list with minimum roles that have a higher number than they have in the group.
Don’t forget to clear the site cache, flush all permissions, (and sometimes) flush all sessions before testing any changes.
Note that removing the file_tree and element_tree permissions will hide those trees completely.
You can hide specific TVs and Manager form fields using File Customization ruled.
You can also hide specific menu choices in the Top Menu using custom permissions, but that’s another tutorial.
:)
I dont know. been setting up windows NT domains and AD s. One way the Modx security/user account model seems so much more complex. I must admit I have been and still am a houseman/free lance whatever for the last 9 years and lots has changed (concerning AD/Domain user policy etc). But this solution does not really feel intuitive. Always had my thoughts with the EVO model too. Admittedly I certainly could not provide you with a better solution so thanks for the info.
Thanks Bob.
This helps.
I have managed to customise the forms as I wanted.
One of the problems with the interface is that you have to right click to update a user. Took me a while just to figure that out.
It don't mean nuffink.
Me too.
Bobray, anyone, is there some document that desribes this, I am trying and trying on Revo 2.2 RC1 and 2.1.3. No matter what I try, content tree is empty. Would like to see some flowchart that shows how things are attached. I now have a local install where even the admin logon has all but the resource tree ;(
I finally have my first site in revo, and I love it all except for that usermanagement.
Bobray, anyone, is there some document that desribes this, I am trying and trying on Revo 2.2 RC1 and 2.1.3. No matter what I try, content tree is empty. Would like to see some flowchart that shows how things are attached. I now have a local install where even the admin logon has all but the resource tree ;(
I finally have my first site in revo, and I love it all except for that usermanagement.
franklos, you need to create another Context Access ACL entry for the Editors with a context of 'web' so they can see the resources in that context in the tree. You should be able to use the same policy you did for the other ACL entry ('mgr'). (Sorry, I should have mentioned that.)
Be sure to add the admin to the Editors user group with a role of admin Super User.
Also, be sure that the resource_tree policy is checked and load, list, and view.