I am wondering how I can create a resource which will be visible in the menu (Wayfinder) and would show the unauthorized page when you click the item. I have (as normally) created a "Members restricted" resource group and assign it to the "Members" usergroup with all neseccary permissions. This works to hide pages totally, and let them show up when you're logged in. But now I need to show the page in the menu but don't allow anonymous users to view the content.
I can do this with a custom snippet to check if a user hasSessionContext() but I want to know if I can achieve this through the ACL system. I am curious to your replies! Thanks in advance...
I now use my snippet to send the unauthorized user to the unauthorized page.. https://gist.github.com/3957282
Works like a charm but like to know if MODX core can handle this too
I think this isn't any components fault.. As far I know, a resource is an sub-instance of modAccesibleObject and this one is checking the "load" permission. And because that's the minimal permission to view resources you're not able to make a difference between viewing and accessing the resource.
That was it!! Cool! Now it works as I would like..
I have duplicated the "load, list and view" to a new "load and list" and assigned the resource group with this policy to the anonymous group and voila (don't forget to flush permissions)!
Not necessarily. I do not believe that getResources checks list or view permissions for instance. Load permission however will affect any component that uses the API to access data via the objects (as does save and remove). That said, components could absolutely re-use these additional permissions for their own logical purposes.