I’ve been using MaxiGallery for a while now and it is a great snippet. Recently some of my sites have become more involved and I now have a small issue with the "Manage pictures" button.
I have checked various posts, but have not really come to a conclusion about exactly how the security works with MaxiGallery.
I have backend managers that are members of certain Manager Access groups, say GroupA or GroupB.
I then have a gallery call on a page (say PageA) and grant the page access permission of GroupA. Another page (PageB) has a gallery and has access permission set to GroupB.
It does no seem to matter which access group the managers are in they can all see a "Manage pictures" button for all the galleries. I have verified other MODx security is working so, for example if a manager is not in GroupA they will not see the Quickedit "Edit Content" button when viewing the frontend PageA and cannot edit PageA in the backend manager.
So basically all my backend managers have access to the "Manager Pictures" button for all galleries on the site.
I have looked at the "admin_webgroups" parameter, but I think this is for "Web Users" and not relevant to "Manager Users"
In the documentation is says "note that you must be logged into the manager and have rights to edit the document ". These managers are logged in, but do not have rights to edit the document, and still see the "Manager pictures" button.
Deep in the MaxiGallery code it seems to be using ’manager/processors/user_documents_permissions.class.php’ to check permissions, but this always seems to be returning true (for me at least).
How can I lock this down so only certain backend managers can see the "Manage Pictures" button? This is purely for backend manager logins and not frontend web user accounts.