I've got 2 front end contexts: web and persoonlijk.
Web is for non-logged users, and when they login they are sent to the context persoonlijk.
Now I want to make persoonlijk only available to logged in users, and not by means of a redirect snippet in the head or something.
I've tried removing the context access to persoonlijk from the Anonymous user group settings. This doesn't seem to work, (anonymous) still have access to the context.
What am I doing wrong?
-
☆ A M B ☆
- 894 Posts
The easiest way to do this is to make a new user role and give them access to that context, that should block anyone that does not have this role.
Good Luck.
[ed. note: benmarte last edited this post 13 years, 8 months ago.]
Don't forget to throw the things you want to protect, first, into a resource group (persoonlijkResources); this can help organize things.
At this stage resources will still be up for grabs until they are linked to a usergroup.
Create a usergroup (loggedmembers) and give them load-list-view access to the "persoonlijk" context and load-list-view to the "persoonlijkResources" resource group.
Give the anonymous group load-only access to the "persoonlijk" context and load-only access to "persoonlijkResources" resource group. This will prevent the infamous 404 doc.
TinymceWrapper: Complete back/frontend content solution.
Harden your MODX site by
passwording your three main folders:
core, manager, connectors and renaming your
assets (thank me later!)
5 ways to sniff / hack your own sites; even with renamed/hidden folders, burst them all up, to see how secure you are not.
The Context is not protected unless you create a Context Access ACL entry connecting it to a User Group (e.g. Administrator) that the users are not members of.
I'm trying to accomplish a similar thing but not sure how to solve it.
I have 3 environments on ModX Cloud. Dev, Stage and Production. I'd like to block public access to Dev and Stage environments.
I've accomplished this by removing any type of access to the web context for the anonymous user. Alright, so far so good.
Now the question is, can I make an Unauthorized Page available for the anonymous users trying to load pages within the web context?
Thank you in advance.
I think if you don't put the Unauthorized page in any Resource Groups and it will be unprotected for everyone in the front end.