We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 31178
    • 128 Posts
    I’ve been using MaxiGallery for a while now and it is a great snippet. Recently some of my sites have become more involved and I now have a small issue with the "Manage pictures" button.
    I have checked various posts, but have not really come to a conclusion about exactly how the security works with MaxiGallery.


    I have backend managers that are members of certain Manager Access groups, say GroupA or GroupB.

    I then have a gallery call on a page (say PageA) and grant the page access permission of GroupA. Another page (PageB) has a gallery and has access permission set to GroupB.

    It does no seem to matter which access group the managers are in they can all see a "Manage pictures" button for all the galleries. I have verified other MODx security is working so, for example if a manager is not in GroupA they will not see the Quickedit "Edit Content" button when viewing the frontend PageA and cannot edit PageA in the backend manager.

    So basically all my backend managers have access to the "Manager Pictures" button for all galleries on the site.

    I have looked at the "admin_webgroups" parameter, but I think this is for "Web Users" and not relevant to "Manager Users" huh

    In the documentation is says "note that you must be logged into the manager and have rights to edit the document ". These managers are logged in, but do not have rights to edit the document, and still see the "Manager pictures" button.

    Deep in the MaxiGallery code it seems to be using ’manager/processors/user_documents_permissions.class.php’ to check permissions, but this always seems to be returning true (for me at least).

    How can I lock this down so only certain backend managers can see the "Manage Pictures" button? This is purely for backend manager logins and not frontend web user accounts.
      • 7923
      • 4,213 Posts
      Hmm.. don’t know why it would have been broken.. I don’t have time to test it right now.. anyone else want to check?


        "He can have a lollipop any time he wants to. That's what it means to be a programmer."
        • 31178
        • 128 Posts
        Well for now I’ve created a plugin to remove the manage pictures button when it should not be there. It is a bit of a hack, but it works. I didn’t want to start messing with the gallery code as it makes upgrading the snippet easier.

        I’d be very interested if anyone else can get manager accounts to have access to the Manage Pictures button only for specific galleries in the system.
          • 31178
          • 128 Posts
          as a followup there seems to be a bug in 0.9.6.1 which has a fix for the next release http://svn.modxcms.com/jira/browse/MODX-35 . This reletes to "Make use of private_*group in {PREFIX}documentgroup_names table". It so happens that ’manager/processors/user_documents_permissions.class.php’ uses this table and I think this may be part of the reason why the security is not working in MaxiGallery.
          Though I also seem to get $GLOBALS[’use_udperms’] returning null so it never gets right trought the script as it returns true at about line 32 in ’manager/processors/user_documents_permissions.class.php’.