OK, I've got the site back. I started all the way from scratch, deleting all resource groups and user groups and add things one by one. How painful this is. And still, I don't think this works 100% correctly. The amount of times I've deleted the cache and flushed permissions I don't know. I really really do think this is the weakest part of ModX as it seems unpredictable and also unnecessarily complex.
I think this is one of MODx' strongest points. I did projects in other CMSs, even in WebsiteBaker. But I was ever restless with them. Never could get my community permissions right. It was this finely-tuned feature of MODx I was looking for.
I think once you've toiled through it, and persevere, you might come to appreciate it.
[ed. note: donshakespeare last edited this post 13 years, 7 months ago.]
TinymceWrapper: Complete back/frontend content solution.
Harden your MODX site by
passwording your three main folders:
core, manager, connectors and renaming your
assets (thank me later!)
5 ways to sniff / hack your own sites; even with renamed/hidden folders, burst them all up, to see how secure you are not.
well, I would think it is a good point if it wasn't so complicated. I have calmed down a little now so here are my thoughts on this
- thanks to all who have looked and patiently replied!
- I can't quite lay my finger on it, but I think the system is a little buggy or at least temperamental. Although everything looks OK, things don't work as expected. Maybe that's because I have forgotten something somewhere, but it feels that way. I noticed, for example, that the 'save' button when updating user groups in Access Controls doesn't seem to have any effect, i.e. the changes take place during the update of a group, not on save
- the interface is complex and cumbersome - things can easily get missed. Having to use dropdowns here, dropdowns there, tabs and popups everywhere doesn't really help in trying to track down what's what and where the problem might be
- if permissions need to be flushed and if the cache needs to be cleared, it should happen when you make the appropriate change. I cleared permissions and the cache manually so many times and I never really knew if it was necessary or if it had any effect
- I do like flexibility, but I feel that it needs more support being clearer on the effects a simple change may have. A recent update of the interface has gone some way towards this by offering default options when creating new resource groups, but I am not sure if this works properly, as it didn't seem to have the expected effect - as with the rest, it doesn't feel 100% consistent and working
Phew, let's move on and thanks again for reading
@xdom12: You make some very good points. In my experience, the permissions work as they should if you get them right and there are no extra contexts involved beyond 'web' and 'mgr'.
You might find this video helpful (warning -- it's about an hour long):
http://modxpo.eu/schedule/sessions/modx-revolution-security-permissions-system
Thanks for the kind words.