We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 38007
    • 1 Posts
    Hello,

    I've tried everything (official docs, Bob's Guides, other guides, tutorials, this forum, google...) and I still can't get revo permissions to work.
    I also clear site cache, flush all permissions and relogin in different browser every time I change something.

    What I'm going to do, is to make 2 types of manager users. First is admin - full access, second is event editor, let's call him 'user1', that has access but only to a part of resources tree.

    For ex.:

    Home Page (1)
    News (2)
    City info (3)
    -General Info (4)
    -Events (5)
    --event 1 (6)
    --event 2 (7)

    I need 'user1' to be able to view, load, edit, create, delete (standard Resource Policy is ok for me) everything under 'Events (5)' container only.

    What I did is:

    -created user 'user1'
    -created role 'EventEditor - 1000'
    -created user group 'EventEditors' and assigned 'user1' to that group with role 'Event Editor - 1000'
    -added Context Access entry for user group 'EventEditors': web/Member 9999/Content Editor (tried 'Load,List and View' also) - to be able to see 'web' context in manager
    -added Context Access entry for user group 'EventEditors': mgr/Member 9999/Content Editor - to be able to use manager at all
    -created Resource Group 'AllPages' and put all root resources to it (1,2,3)
    -created Resource Group 'Events' and put 'Events (5)' resource to it
    -added user 'admin' to user group 'EventEditors' to also be able to see 'Events (5)' subtree
    -added Resource Group Access entry in 'Administarators' user group: 'AllPages'/SuperUser/Resource/mgr
    -added Resource Group Access entry in 'EventEditors' user group, 'Events'/EventEditor/Resource/mgr

    After login as 'user1' I didn't see any resources in manager, so I thought that is because 'Events (5)' is under 'City info(3)', so I added tree_root_id setting to user1 with value of 5.

    From now on everything seems to work for user1, BUT when I change URL from manager/?a=30&id=5 to manager/?a=30&id=2 I can edit 'News (2)' !!!

    Please help...
      • 38142
      • 91 Posts
      You don't mention Access Policies. Modifying and assigning one of them is crucial.

      It took me about three days to work out how to do this, and in the end I wrote my own step-by-step guide just so I didn't forget. Let me just paste it in here (I hope it helps):

      Okay, let’s imagine you have a client called Doreen who needs to take the reins of her website. She needs access to most of the resources and she needs to be able to create new resources (because there is a little news or reviews feature that needs each snippet of news or each review to go on its own resource). How to set it up? Here’s one way (for MODX Revolution).

      1. Just so Doreen can create new resources go to System -> System Settings. In the settings for Authentication and Security find Allow root. Set it to Yes.

      2. Create a User identity for Doreen. Security -> Manage Users. Click New User and
      create and set name, password, email, active status.

      3. Next we need to create a role for Doreen to play. Security -> Access Controls -> Roles. Create a new role (say, Editor) with an authority of, say, 10.

      4. Don’t ask me why, but users with roles also have to belong to groups, so create a group for Doreen. Security -> Access Controls -> User Groups. Create new group called Editors Group.

      5. Doreen needs to be in that group (she isn’t yet), so (with the list of user groups visible) right-click the Editors Group and select the option to add a user to the group. Choose Doreen’s id and give her the role of Editor.

      6. The problem with the MODx role that you created is that so far it is just a name. No permissions or prohibitions have been specified to define what Doreen can and can’t do as an Editor in the Editors Group. So we have to create a Policy. Two tabs along from the User Groups tab (Security -> Access Controls) is a tab that says Access Policies. Click it. There is already a Content Editor policy but you will probably find it is not permissive enough, so select it and right click it to choose the option to update it. Go down the list of permissions selecting the ones you want Doreen to have. (I’m going to add

      directory_create + _list + _remove + _update
      file permissions (all)
      new_document_in_root,
      publish_document,
      purge_deleted,
      save,
      undelete_document,
      unpublish_document,
      view_tv
      view_unpublished).

      Click Save.

      7. Now we have to tie the access policy and the role to the group. Get back to the list of user groups: Security -> Access Controls -> User Groups. Right click on the Editors Group and select "Update Group." Then click the Context Access tab. Click Add Context, and select the mgr (manager) context, select the Minimum Role: Editor, and choose the Access Policy: Content Editor.
      If you leave it there, for some reason Doreen won’t see any resources in the Manager area when she logs in, so repeat the previous procedure by clicking Add Context and select the web context this time together with the same role and policy as before.

      Click Save.

      We could leave it there, but there are a few resources that we don’t want Doreen messing with, so lets create a Resource Group for those and deny her access to them. Security -> Resource Groups. Click Create Resource Group. Call it Super Admin Only. Drag the resources to be hidden into that group.

      To give yourself sole access to those resources go back to Security -> Access Controls to see the list of user groups (again). Right Click the Administrator group (of which you will be a member by default) and select the option to update the group. Click the Resource Group Access tab and then click Add Resource Group. Choose the SuperAdmin Only group, and then choose Minimum Role: Super User, Access Policy: Resource, and Context: mgr.

      Click Save.

      Chances are, if you refresh the resource tree now the resource you wanted to give yourself privileged access to disappears. Fear not, get it back by clicking Security -> Flush Permissions. Phew!

      Okay, click Security -> Flush Sessions just to log out and trash any bureaucratic dross that might have accumulated.

      Log in with Doreen’s id and password to check that everything is as it ought to be.