We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 40231
    • 16 Posts
    We have had ModX 2.x for some time now and for some reason I cannot figure out a new users group is ignoring the security settings.

    We wanted to create a new user and group for Customer Service people to be able to edit content.

    So in Resource Groups I made two groups one called Customer Service View and Customer Service Edit. We want users to be able to edit only certain pages content. So I put the top level Resource Folder called Customer Services Pages into the View Group. I then added one page called Outages to the Edit group. I did that because if I don't they cannot drill down to the individual page in the manager.

    I then went into Access Controls and created a Customer Service Group. Under context access I gave them member (9999) to Restricted Admin for mgr & web. Under Resource Access I gave Customer Services View, Member to Load, List and View role for mgr and web. That is all that is there right now. I know I left off the Edit but that's not the issue at the moment.

    I double checked Load, List and View and its still default with only Load, List and View.

    I then made a user CS and give it member access to the Customer Service Group.

    I have flushed both sessions and permissions and cleared cache.

    However the problem I have is when I login and open the Customer Service Pages I can edit any of the child resources, when I shouldn't. I should only be able to see they are there. So it's ignoring the Load, List and View permission for some reason.

    This is a match to all the other users as far as I can see as well.

    So I am stumped. Anyone have any ideas?
      • 3109 ☆ A M B ☆
      • 894 Posts
      Have tried using my ACL tutorial? It might help solve your issue. Security in MODX is one of the hardest things to learn but when you do it's very powerful.

      http://bmv-interactive.com/home/modx-acl-tutorial.html

      Good Luck.
        Benjamin Marte
        Interactive Media Developer
        Follow Me on Twitter | Visit my site | Learn MODX
        • 40231
        • 16 Posts
        I agree it is tough, and that is a nice tutorial. I wish I had it when I was first creating the accounts. However that's not really helpful. I would like some help understanding why a user with only Load, List and view permissions can still edit/save resources.
          • 3749
          • 24,544 Posts
          It sounds like you have not protected the resources you don't want the users to see/edit. Those Resources have to go in another Resource Group and that Resource Groups needs to be connected to another User Group (e.g., Administrator) with a Resource Group Access ACL entry. Then they'll be protected from anyone outside that User Group.


          ------------------------------------------------------------------------------------------
          PLEASE, PLEASE specify the version of MODX you are using.
          MODX info for everyone: http://bobsguides.com/modx.html
            Did I help you? Buy me a beer
            Get my Book: MODX:The Official Guide
            MODX info for everyone: http://bobsguides.com/modx.html
            My MODX Extras
            Bob's Guides is now hosted at A2 MODX Hosting
            • 40231
            • 16 Posts
            Ok so I missed that step and I added those two Resource groups to the administrator group with a level of Super Users. Cleared permissions, cache and sessions, no difference.

            I feel like I am missing something minor
              • 3749
              • 24,544 Posts
              Did you use a context of 'mgr' in the policy for the ACL entries connecting the resources to the Administrator group?

              Are the limited users members of the Administrator Group? I'd recommend moving them out to another User Group because it will give you more flexibility with Form Customization down the road.


              ------------------------------------------------------------------------------------------
              PLEASE, PLEASE specify the version of MODX you are using.
              MODX info for everyone: http://bobsguides.com/modx.html
                Did I help you? Buy me a beer
                Get my Book: MODX:The Official Guide
                MODX info for everyone: http://bobsguides.com/modx.html
                My MODX Extras
                Bob's Guides is now hosted at A2 MODX Hosting
                • 40231
                • 16 Posts
                Yes both web and mgr are in there for both groups

                Yes two account mine and the other web admin.

                I am so stumped right now
                  • 40231
                  • 16 Posts
                  I am even more confused now.

                  So I removed that res group from every where except the All pages group which sets the security for all the resource groups. Its in no other groups.

                  I then login as the eng account since its the oldest non-admin account we have. We have had Modx for over a year and this account has been around for awhile. It also works perfectly as expected. Can't view the res group as expected. They can only view and edit the pages they should be able to.

                  Go back in add that res group to the eng view group, and only that group. In theory I should now see it but not be able to do anything. Its still in the all pages group.

                  Clear everything, login as eng, and I can edit all the pages under that group.

                  It's like something else is causing that res group to ignore everything else.
                    • 40231
                    • 16 Posts
                    So just for fun I added a different res group that eng don't have access to. And it worked as expected. I just don't get it.
                      • 3749
                      • 24,544 Posts
                      It's hard to know without seeing your actual setup, but I usually don't put users in the Administrator group if I want to hide resources from them. It helps prevent permission problems and it gives you more options for Form Customization.

                      If I had to guess, I'd say that you had a problem with the minimum role for those users versus the minimum role for the ACL entries. The authority level works backwards -- the lower the number, the higher the authority. So if you put users in the Administrator group that should have limited rights, their role in the group needs to have a higher authority level (bigger number) than the one required in any ACL entry that applies to you
                      .


                      ------------------------------------------------------------------------------------------
                      PLEASE, PLEASE specify the version of MODX you are using.
                      MODX info for everyone: http://bobsguides.com/modx.html
                        Did I help you? Buy me a beer
                        Get my Book: MODX:The Official Guide
                        MODX info for everyone: http://bobsguides.com/modx.html
                        My MODX Extras
                        Bob's Guides is now hosted at A2 MODX Hosting