We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 7455
    • 2,204 Posts
    maybe its easier to make a own function that does the whole mysql check etc
      follow me on twitter: @dimmy01
      • 7455
      • 2,204 Posts
      after the sql query I get these results:

      limit = 1 documentid=119 docgroupid=4

      that would mean that doc 119 is asigned to docgroup 4

      but in the db that is not the case...

      that is weard looks like the manager is not using that part that way

      in the manager I can (try to) edit 2 document 1 where I have permissions to and one that I do not have permissions to and both give me the same resuts (ofcourse doc id is diffrend):
      doc id 119: limit = 1 documentid=119 docgroupid=4 I am not allowed and I get an error that I am not allowed to edit.
      doc id 173: limit = 1 documentid=173 webgroupid=4 I am alowed to edit etc this page

      in both cases limit is 1 so checkPermissions() will alway’s return true, man this is weard

      Dimmy
        follow me on twitter: @dimmy01
        • 7923
        • 4,213 Posts
        Btw, here’s a post about this very same thing, I did not look into it at that time, because I thought its fixed.

        Previously maxigallery did not use the MODx user_documents_permissions.class.php and did own sql queries instead, but someone made a request to change to that.. so that’s what I did. It worked then, but seems that it has broken at somepoint. If you look previous versions of maxigallery.class.php from maxigallery trac, you should find a version where the check is done using SQL.

        But what was the exact problem that the user_documents_permissions.class.php did not work?


          "He can have a lollipop any time he wants to. That's what it means to be a programmer."
          • 7455
          • 2,204 Posts
          checkPermissions() always returns true to MG so any manager user is allowed to edit images etc. I wonder what checks are done in the manager somehow the manager uses the checkPermissions() functions but also another script I think, see above post http://modxcms.com/forums/index.php/topic,29111.msg177690.html#msg177690

          because also in the manager limit is always 1 in checkPermissions() part but as I said above it still knows if you can edit or not.
            follow me on twitter: @dimmy01
            • 7923
            • 4,213 Posts
            Here’s an example how it’s used in MODx document delete processor:

            <?php
            // check permissions on the document
            include_once "./processors/user_documents_permissions.class.php";
            $udperms = new udperms();
            $udperms->user = $modx->getLoginUserID();
            $udperms->document = $id;
            $udperms->role = $_SESSION['mgrRole'];
            
            if(!$udperms->checkPermissions()) { ...permission denied... }
            ?>

            Seems same to me..


              "He can have a lollipop any time he wants to. That's what it means to be a programmer."
              • 7455
              • 2,204 Posts
              I will look in this tomorrow again do some debugging see if we can get this somehow to work
                follow me on twitter: @dimmy01
                • 7923
                • 4,213 Posts
                Yeah, this is the topic what got me to using that udperms() class.

                And this is what the function was before in MaxiGallery, but as you can read from the linked topic, it doesn’t work perfectly either..

                <?php
                	function checkPermissions($userid,$docid){
                		global $modx;
                		if($userid) {
                			// check whether user is allowed to modify this page (-> $result1=1)
                			$rs1=$modx->db->query("SELECT * FROM (" . $modx->db->config['table_prefix'] . "member_groups LEFT JOIN " . $modx->db->config['table_prefix'] . "membergroup_access ON user_group=membergroup) LEFT JOIN " . $modx->db->config['table_prefix'] . "document_groups ON documentgroup=document_group WHERE member='" . $userid . "' and document='" . $docid . "'");
                			$result1=$modx->db->getRecordCount($rs1);
                
                			// check if user is administrator (-> $result2=1)
                			$rs2=$modx->db->query("SELECT * FROM " . $modx->db->config['table_prefix'] . "user_attributes WHERE id='" . $userid . "' AND role='1'");
                			$result2=$modx->db->getRecordCount($rs2);
                
                			if($result1>0 || $result2>0) {
                				return true;
                			}
                		}
                		
                		//check whether user is logged in and belongs to selected webgroups
                		if((count($this->mgconfig['manager_webgroups'])>0 && $modx->isMemberOfWebGroup($this->mgconfig['manager_webgroups'])) || (count($this->mgconfig['admin_webgroups'])>0 && $modx->isMemberOfWebGroup($this->mgconfig['admin_webgroups']))){
                			return true; 
                		//check whether user is logged in and is defined in manager_webusers
                		} else if (($modx->getLoginUserName()!="" && in_array($modx->getLoginUserName(), $this->mgconfig['manager_webusers'])) || ($modx->getLoginUserName()!="" && in_array($modx->getLoginUserName(), $this->mgconfig['admin_webusers']))){
                			return true;
                		} else {
                			return false;
                		}
                	}
                ?>


                Would be good to get the document permission checking working exactly like it does in MODx manager to avoid problems..


                  "He can have a lollipop any time he wants to. That's what it means to be a programmer."
                  • 7455
                  • 2,204 Posts
                  Quote from: doze at Sep 29, 2008, 10:00 AM

                  Here’s an example how it’s used in MODx document delete processor:

                  <?php
                  // check permissions on the document
                  include_once "./processors/user_documents_permissions.class.php";
                  $udperms = new udperms();
                  $udperms->user = $modx->getLoginUserID();
                  $udperms->document = $id;
                  $udperms->role = $_SESSION['mgrRole'];
                  
                  if(!$udperms->checkPermissions()) { ...permission denied... }
                  ?>

                  Seems same to me..

                  Yes but that has the same problem
                  I am alowed to delete to move to publish unpublish etc any doc i see even if I am not alowed to edit taht page (so editing is not alowed but all the other stuff thats in the contextmenu is posible without the right of that page
                  I can even copy a page (I am not able to edit the copy)

                  so I think that the checking part is somehow realy broken and the edit document must be checking something else that only that part works

                  Dimmy
                    follow me on twitter: @dimmy01
                    • 7455
                    • 2,204 Posts
                    looks like quickedit is working OK I wonder what quickedit is using to determine if someone is allowed to edit a page.
                      follow me on twitter: @dimmy01
                      • 7455
                      • 2,204 Posts
                      ok I found the bug and made a fix:

                      its not in MG but in the user_documents_permissions.class.php class in all 096x versions

                      first this line (33):
                      		if($GLOBALS['use_udperms']==0 || $GLOBALS['use_udperms']=="" || !isset($GLOBALS['use_udperms'])) {
                      			return true; // permissions aren't in use
                      		}
                      


                      this will always return true because $GLOBALS[’use_udperms’] does not exist it must be $modx->config[’use_udperms’], like this:

                      		if($modx->config['use_udperms']==0 || $modx->config['use_udperms']=="" || !isset($modx->config['use_udperms'])) {
                      			return true; // permissions aren't in use
                      		}
                      


                      these line must be changed also for the last part to work right:
                      from:
                      		if($_SESSION['mgrDocgroups']) {
                      			$docgrp = implode(",",$_SESSION['mgrDocgroups']);
                      		}
                      


                      to:
                      		if($_SESSION['mgrDocgroups']) {
                      			$docgrp = implode(" || dg.document_group = ",$_SESSION['mgrDocgroups']);
                      		}
                      

                      this comes in to play when more then one docgroup is asigned to a user

                      the last problem is the last db query that somhow always ended up being 1 also always returned true:
                      		$tblsc = $dbase.".`".$table_prefix."site_content`";
                      		$tbldg = $dbase.".`".$table_prefix."document_groups`";
                      		$tbldgn = $dbase.".`".$table_prefix."documentgroup_names`";
                      		$sql = "SELECT DISTINCT sc.id 
                      				FROM $tblsc sc 
                      				LEFT JOIN $tbldg dg on dg.document = sc.id
                      				LEFT JOIN $tbldgn dgn ON dgn.id = dg.document_group
                      				WHERE sc.id = $document 
                      				AND (1='' OR NOT(dgn.private_memgroup<=>1)".(!$docgrp ? "":" OR dg.document_group IN ($docgrp)").");";
                      				   // ^ MySQL 4.1 will not return the correct result if this statement is removed! ???
                      		$rs = mysql_query($sql);
                      		$limit = mysql_num_rows($rs);
                      

                      this should be in my opinion this:
                      		$tblsc = $dbase.".`".$table_prefix."site_content`";
                      		$tbldg = $dbase.".`".$table_prefix."document_groups`";
                      		$tbldgn = $dbase.".`".$table_prefix."documentgroup_names`";
                      		$sql = "SELECT DISTINCT sc.id 
                      				FROM $tblsc sc 
                      				LEFT JOIN $tbldg dg on dg.document = sc.id
                      				LEFT JOIN $tbldgn dgn ON dgn.id = dg.document_group
                      				WHERE sc.id = $document 
                      				AND (dg.document_group = $docgrp)";
                      				   
                      		$rs = mysql_query($sql);
                      		$limit = mysql_num_rows($rs);
                      


                      made a bug myself but that is fixed now the bug came when a user was assigned to more then one docgroup

                      This bug also made it possible for manager users that where not in the right docgroup to delete, move, copying, (un)publish (all except editing) any document.
                      so also by applying this fix those things are not possible anymore (thats a good thing)

                      greets Dimmy
                        follow me on twitter: @dimmy01