Things to never forget
Look at it this way: a
tourist group (Usergroup) has a
pass (access) to go the
Balboa Park(Context) in San Diego (your website), which is the home of all the major museums.
Their pass might allow them to enter the Park through the
front gate (web) and
back gate (mgr) gates.
(Context Access)
But lo and behold, the
Museums (Resource Group) themselves have a further individual requirement.
To enter the
Museum of Art through its
front door (web) or
back door (mgr), with their park
pass, the tourist group will need further stamping.
(Resource Access Policy - web or and mgr)
Once you give a usergroup access to a resource group, they will hug it, thus preventing other usergroups from entering the museum, unless the other usergroups have booked and paid...
Don't confuse Context Access with Resource Access
If you give a usergroup Context Access of web or mgr, give the same usergroup a corresponding Resource web or mgr access also, if you want them to access a particular Resource Group.
If they get Context access to the Park, through the front door (web) they need Resource Access (web) too to see or enter a restricted Museum's front door. Or if they are the first to book the Museum, they then make it restricted.
To restrict, in frontend, a Resource group, at minimum level - other
levels:
(1) Give Context Access (web) - of course, and (2)Resource Access (web) to a usergroup.
Access Policy signifies what the tourist group can do when they get to the Park (the Context) - can they just see the sign post only
(load), can they do much more like see the walls
(load, list, view) or (Administrator Goddess) break exhibitions, take pictures, create exhibitions of their own etc,
if the individual Museums gave them Resource access... (Context Access does not automatically give access to a Resource Group. It opens the ground)
If you want other groups, including the public (anonymous) to see but not touch or edit a restricted Resource Group, give them, first a Context Access, Load Only, and a Resource Access of
Load, List and View.
To prevent them from seeing the page at all but not get a 404 error instead of the unauthorized page, give them
Resource Access of Load only
- I set up an editors2 group ACL (Security/Access controls), given it 'web' & 'mgr' access with 'editor' role. I gave the editor2 Resource Group Resource Group Access with 'mgr' context
make sure the users who could not see the frontend of editor2 had an editor role.....or else just remove their usergroup's Context Access (web)(editor role) altogether .
Just think about it some more, practice with it, do some trial and error, create weird scenarios of your own...above all, think about it! by my beard and whiskers there is logic in't.
This was not meant to confuse you, especially the analogy of Park and Museum....
Cheers