We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 40231
    • 16 Posts
    So this is another attempt to solve my problem from another thread. I have included screen shots and more info this time.

    We have had ModX 2.x for some time now and for some reason I cannot figure out a new users group is ignoring the security settings.

    We wanted to create a new user and group for Customer Service people to be able to edit content.

    So in Resource Groups I made two groups one called Customer Service View and Customer Service Group (which will edit). We want users to be able to edit only certain pages content. So I put the top level Resource Folder called Water Resources into the View Group. I then added one page called Opening & Closing Accounts to the group. I did that because if I don't they cannot drill down to the individual page in the manager.

    I then went into Access Controls and created a Customer Services group. Under context access I gave them member (9999) to Restricted Admin for mgr & web.

    Under Resource Access I gave Customer Services View, Member to Load, List and View role for mgr and web. I gave the Customer Services Group Engineering Access Editor which is a custom security policy.

    I also put both groups in the Administrator Group as Super User (see administrator.jpg)

    I double checked Load, List and View and its still default with only Load, List and View (see shot).

    I then made a user CS and give it member access to the Customer Service Group.

    I have flushed both sessions and permissions and cleared cache.

    However the problem I have is when I login and open the Customer Service Pages I can edit any of the child resources, when I shouldn't. I should only be able to see they are there. So it's ignoring the Load, List and View permission for some reason.

    This is a match to all the other users as far as I can see as well.

    So I am still stumped. Anyone have any ideas?
      • 3749
      • 24,544 Posts
      Resources in a Resource Group are only hidden from a user when that Resource Group is connected to a User Group (with a Resource Access ACL entry) that the user is *not* a member of.

      Generally, you don't want to put anyone with limited rights in the Administrator group.

      The usual method for what you want to do is to:

      1. Have just you in the Administrator group.

      2. Connect all the Resource Groups you want to protect in any way to the Administrator group with Resource Group Access ACL entries. That will hide them from everyone else.

      3. Create the Resource Group Access ACL entries that give the right kind of access to the various groups -- by creating ACL entries for each with the appropriate Policy.

      Note that step 3 will hide the resources from you. Either make yourself a sudo user, or add yourself to all the User Groups with a Role of admin Super User.


      Be sure to flush permission and all settings on the Security Menu before testing any change.


      ------------------------------------------------------------------------------------------
      PLEASE, PLEASE specify the version of MODX you are using.
      MODX info for everyone: http://bobsguides.com/modx.html
        Did I help you? Buy me a beer
        Get my Book: MODX:The Official Guide
        MODX info for everyone: http://bobsguides.com/modx.html
        My MODX Extras
        Bob's Guides is now hosted at A2 MODX Hosting
        • 40231
        • 16 Posts
        I sort of feel like you didn't read my post or look at my shots. The user (CS) is not in the administrator group. They are only in the Customer Services group and that's it.

        Unless I am missing something, I have already done all 3 of your steps.

        Plus I already have 5 other users setup exactly the same way that work perfectly.

        It acts like there is something on the resource group that is overriding the other policies.

        So I am at the point where I am starting to think there is bug some where. I guess I will have to try to debug it. Maybe I will make a new user and group and see what happens.
          • 40231
          • 16 Posts
          Ok so I tried a few other things.

          I removed the Water Resources Resource from the All Pages Resource Group. No difference.

          I removed the Water Resources Resource from the Customer Services Group, and I could not see any of the resources under it. So that works.

          I moved them from the Customer Services group to one of the other working groups, and it did not work. Same issue as with the customer services.

          So I deleted the old ones, remade them with new names, no difference.

          I then removed everything. Added a just a resource group to just the view. Didn't work. Then I added just one page that isn't under a resource group and it worked, I could only view it. So then I put back in the group and found that the view ONLY is working on the top of the group resource. It no longer waterfalls down to the child pages. So....I don't understand why that is all of a sudden.
            • 3749
            • 24,544 Posts
            Sorry, I answer a lot of permissions questions and don't always have time to look at all the details on the the first pass.

            I was confused by this: "I also put both groups in the Administrator Group as Super User"

            What are the permissions in your Engineering Resource Policy? It looks like the CS user would have those as well.

            Did you test the permissions from another browser where you were not ever logged in to the Manager?


            ------------------------------------------------------------------------------------------
            PLEASE, PLEASE specify the version of MODX you are using.
            MODX info for everyone: http://bobsguides.com/modx.html
              Did I help you? Buy me a beer
              Get my Book: MODX:The Official Guide
              MODX info for everyone: http://bobsguides.com/modx.html
              My MODX Extras
              Bob's Guides is now hosted at A2 MODX Hosting
              • 40231
              • 16 Posts
              Sorry if I was a bit pissy, this is frustrating the hell out of me. Couple of weeks I have been working on this when it should only have been an hour. But I appreciate your help.

              I always test my other users in another browser. I also always flush sessions and cache as well.

              So here is what seems to be the issue.

              If you look at my resource group screen shot from above. I put Water Resources (40) the resource into both the Customer Services and All Pages group. The way it used to work before is everything under Water Resources (40) used to be protected, so for example Opening & Closing an Account (42) which is under Water Resources (40). It would waterfall down. But that is no longer the case it appears (or I am missing something).

              So as it sits in the screen shot, if I login as the CS user, I cannot edit the Water Resource (40) resource but I can edit Opening & Closing an Account (42), or another resource under Water Resource (40). It doesn't matter if I remove Opening & Closing an Account (42) from the Customer Service Group resource group or not.

              So now if I take Opening & Closing an Account (42) and move it to just All Pages, I can no longer see it or anything.

              But if I take Opening & Closing an Account (42) and put it in both the All Pages and the Customer Service Group resource group, I can edit it.

              So what I have to do is put ALL my resources under the Water Resource (40) into the All Pages Resource group. Which I didn't used to have to do. So am I missing something? Did something change in v2 to v2.1 to v2.2 to change this?
                • 3749
                • 24,544 Posts
                I know that working with the permission system can be really frustrating.

                I think you may be dealing with a bug that was fixed (IOW, what you did shouldn't have worked before).

                AFAIK, children don't inherit their parents' permissions (though I think that's on the roadmap), so each resource has to be explicitly protected if you want to hide it or limit access to it. IIRC, when a parent is hidden, the children don't show up in the Resource tree, but they are not truly protected.

                I hope that makes sense, helps, and that I have it right.


                ------------------------------------------------------------------------------------------
                PLEASE, PLEASE specify the version of MODX you are using.
                MODX info for everyone: http://bobsguides.com/modx.html

                  Did I help you? Buy me a beer
                  Get my Book: MODX:The Official Guide
                  MODX info for everyone: http://bobsguides.com/modx.html
                  My MODX Extras
                  Bob's Guides is now hosted at A2 MODX Hosting
                  • 40231
                  • 16 Posts
                  Maybe I am just insane, I don't know. I swear it did it before. Oh well, I guess now I know what to do. Thanks for your help.