The traditional way would be to create a user group for each user and a resource group for each resource and connect them with a Resource Group Access ACL entry, but it's pretty tedious.
You might be able to use a plugin connected to OnDocFormPrerender. Something like this:
<?php
if ($user->get('id') != $resource->get('createdby') ){
$modx->sendUnauthorizedPage();
}
The problem is that the $user object might not be available there. Another plugin (or a "case" statement in the same plugin) could respond to the OnManagerLogin event by writing the user ID to a $_SESSION variable. In that case the code would look more like this:
<?php
if ($_SESSION['userId'] != $resource->get('createdby') ) {
$modx->sendUnauthorizedPage();
}
In either case, users would be forwarded to the unauthorized page if they tried to edit a doc they didn't create.
It might also be possible to do this in 2.2 with Media Sources, but I don't know enough about them yet to say for sure.
---------------------------------------------------------------------------------------------------------------
PLEASE, PLEASE specify the version of MODX you are using . . . PLEASE!
MODx info for everyone:
http://bobsguides.com/MODx.html
[ed. note: BobRay last edited this post 14 years, 7 months ago.]