We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 38470
    • 2 Posts
    Hello!

    The question. Is it possible to allow site managers to create, publish and save documents in container, but to forbid possibility to edit-change-delete any documents of other authors in the same container? I mean some kind of adjustment in Joomla "allow to edit article only to it's author".

    I don't see the way to realise this adjustment via ACL. It's very usefull possibility for news portals based on MODx, where a lot of managers who must just create docs without necessity to change resourse's group and so on.


    Thank you for your answer.
      • 3749
      • 24,544 Posts
      The traditional way would be to create a user group for each user and a resource group for each resource and connect them with a Resource Group Access ACL entry, but it's pretty tedious.

      You might be able to use a plugin connected to OnDocFormPrerender. Something like this:

      <?php
      if ($user->get('id') != $resource->get('createdby') ){
          $modx->sendUnauthorizedPage();
      }


      The problem is that the $user object might not be available there. Another plugin (or a "case" statement in the same plugin) could respond to the OnManagerLogin event by writing the user ID to a $_SESSION variable. In that case the code would look more like this:


      <?php
      if ($_SESSION['userId'] != $resource->get('createdby') ) {
          $modx->sendUnauthorizedPage();
      }



      In either case, users would be forwarded to the unauthorized page if they tried to edit a doc they didn't create.

      It might also be possible to do this in 2.2 with Media Sources, but I don't know enough about them yet to say for sure.


      ---------------------------------------------------------------------------------------------------------------
      PLEASE, PLEASE specify the version of MODX you are using . . . PLEASE!
      MODx info for everyone: http://bobsguides.com/MODx.html [ed. note: BobRay last edited this post 14 years, 7 months ago.]
        Did I help you? Buy me a beer
        Get my Book: MODX:The Official Guide
        MODX info for everyone: http://bobsguides.com/modx.html
        My MODX Extras
        Bob's Guides is now hosted at A2 MODX Hosting
        • 38407
        • 8 Posts
        BobRay, I'm interesting in regreg's question too. Thank You for Your answer, but the second variant doesn't work:

        Parse error: syntax error, unexpected '{' in /public_html/core/cache/includes/elements/modplugin/4.include.cache.php on line 7


        Maybe You have some thoughts about the reason of the error? ( I don't know PHP :-( )
          • 3749
          • 24,544 Posts
          The example was missing a closing parenthesis. Fixed above.


          ---------------------------------------------------------------------------------------------------------------
          PLEASE, PLEASE specify the version of MODX you are using . . . PLEASE!
          MODX info for everyone: http://bobsguides.com/modx.html
            Did I help you? Buy me a beer
            Get my Book: MODX:The Official Guide
            MODX info for everyone: http://bobsguides.com/modx.html
            My MODX Extras
            Bob's Guides is now hosted at A2 MODX Hosting
            • 38407
            • 8 Posts
            BobRay, there is one more problem: after adding this plugin all users lose the opportunity to edit any documents, even those which were created by them. Even admin can't edit any pages, he see Unauthorized page.

            And the second problem - nobody can create documents:

            Fatal error: Call to a member function get() on a non-object in /home/solovets/public_html/core/cache/includes/elements/modplugin/5.include.cache.php on line 7


            The situation is similar in the 1 and 2 variant of plugin. [ed. note: denissolo last edited this post 14 years, 7 months ago.]
              • 3749
              • 24,544 Posts
              I did say it "might" work. wink I guess not.

              I think the second method I described would work, though you'd have to add a test that would allow the admin Super User to bypass the test. Note that you'd have to write the session variable correctly when the user logs in or it won't work.


              A better solution, though, would be a plugin tied to OnUserFormSave that created the user group and put the user in it, created a resource and resource group and put the resource in the group, and created a Resource Group Access ACL entry that connected the user group and the resource group, but that would be a *much* more complicated plugin.
                Did I help you? Buy me a beer
                Get my Book: MODX:The Official Guide
                MODX info for everyone: http://bobsguides.com/modx.html
                My MODX Extras
                Bob's Guides is now hosted at A2 MODX Hosting