We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 7455
    • 2,204 Posts
    Quote from: doze at Sep 26, 2008, 09:33 AM

    I think that’s how it should work by default.. atleast that’s how I implemented it at some point.

    Only MODx manager users that have rights to edit the MODx document can see the manage button when logged in to MODx backend.

    And all manager users that have the admin role can also see the manage button.

    So if the MODx manager user don’t have right to edit the document, he shouldn’t be seeing the manage pictures button. Did you try it?

    Yes I did and even tryed to upload images with no problems at all (well that is the problem) so maybe there is somthing wrong with the system?

    I do know and tested it that one user canot edit / see images on that page in edit mode that are uploaded by another user even if you are admin i think (the even if you are admin I am not sure of)

    Dimmy
      follow me on twitter: @dimmy01
      • 7923
      • 4,213 Posts
      So you have created a MODx manager user with roles and usergroups that do not have access to certain documents, but that user can still see the manage pictures button in front end in those documents?


        "He can have a lollipop any time he wants to. That's what it means to be a programmer."
        • 7455
        • 2,204 Posts
        YES that is exactly what I did:

        1 user: in the docgroup tieners linked only to that group
        has as role editor (so not admin)
        in the manager he is not allowed to edit page 119
        119 is only linked to another docgroup and webmaster doc group so not to the tieners docgroep.
        in the front he is allowed to add images using maxigallery in doc 119
          follow me on twitter: @dimmy01
          • 7455
          • 2,204 Posts
          some more images to clarify
            follow me on twitter: @dimmy01
            • 7923
            • 4,213 Posts
            The check in maxigallery is done in maxigallery.class.php in checkPermissions() function:

            <?php
            if($userid) {
            	//if user is logged in from backend, check user-document permissions 
            	include_once $modx->config['base_path'].'manager/processors/user_documents_permissions.class.php';
            	$udperms = new udperms();
            	$udperms->user = $userid;
            	$udperms->document = $docid;
            	$udperms->role = $_SESSION['mgrRole'];
            	if ($udperms->checkPermissions()) {
            		return true;
            	}
            }
            ?>
            

            So I guess it doesn’t work like that in the current MODx version anymore..


              "He can have a lollipop any time he wants to. That's what it means to be a programmer."
              • 7455
              • 2,204 Posts
              But did you test it yourself?

              where in the code are you calling this function?
              I use 096p2 for this site.

              I could dive into this function but maybe something else is the problem?

              Dimmy

                follow me on twitter: @dimmy01
                • 7455
                • 2,204 Posts
                looks like that function is alway’s giving "true" back.

                I am trying to get my head around it and do some tests.
                will see what it gives me
                  follow me on twitter: @dimmy01
                  • 7455
                  • 2,204 Posts
                  Somehow this line in: manager/processors/user_documents_permissions.class.php is true:

                  <?php
                  		if($GLOBALS['use_udperms']==0 || $GLOBALS['use_udperms']=="" || !isset($GLOBALS['use_udperms'])) {
                  			return true; // permissions aren't in use
                  		}
                  ?>
                  

                  use_udperms is set in $modx->config[’use_udperms’] (or it that the same as $GLOBAL[’use_udperms’]?)

                  so I think that changing $GLOBALS to $modx->config will work
                  I will test to see if thats the problem

                  edit:
                  well it goes beyond that point now but still its not good
                    follow me on twitter: @dimmy01
                    • 7923
                    • 4,213 Posts
                    Yes, I did test it just now and it didn’t work.. Needs debugging..

                    EDIT: but it has worked at some point..


                      "He can have a lollipop any time he wants to. That's what it means to be a programmer."
                      • 7455
                      • 2,204 Posts
                      ok I think i found it

                      the $user is not used anymore in the user_documents_permissions.class.php script
                      a new way is used to get the docgroup but the user is not used

                      if($_SESSION[’mgrDocgroups’]) {
                      $docgrp = implode(",",$_SESSION[’mgrDocgroups’]);
                      }
                      is the part where we get the docgroup(s) asignt to the current user

                      and in this part:

                      $tblsc = $dbase.".`".$table_prefix."site_content`";
                      		$tbldg = $dbase.".`".$table_prefix."document_groups`";
                      		$tbldgn = $dbase.".`".$table_prefix."documentgroup_names`";
                      		$sql = "SELECT DISTINCT sc.id 
                      				FROM $tblsc sc 
                      				LEFT JOIN $tbldg dg on dg.document = sc.id
                      				LEFT JOIN $tbldgn dgn ON dgn.id = dg.document_group
                      				WHERE sc.id = $document 
                      				AND (1='' OR NOT(dgn.private_memgroup<=>1)".(!$docgrp ? "":" OR dg.document_group IN ($docgrp)").");";
                      				   // ^ MySQL 4.1 will not return the correct result if this statement is removed! ???
                      		$rs = mysql_query($sql);
                      		$limit = mysql_num_rows($rs);
                      if($limit==1) $permissionsok = true;
                      


                      (I am not that good in reading mysql stuff) looks like it is searching if the current document is assignt to the docgroup of the current user (atleast that is what it should do)
                      so if there is one found then its ok to return true, somehow this query gives $limit = 1 even if the doc is not assigned to the current usergroup.


                        follow me on twitter: @dimmy01