We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 24374
    • 322 Posts
    This is driving me nuts. I've spent all morning trying to get a handle on ACLs and Resource Groups. What a mess. Anyway, I've got everything working, except anyone logged in who is not admin can see and edit all the pages belonging to their Resource Group, and when they view the site in their browser, they can see all pages EXCEPT the home page. It's the only one without an alias, as the URL is just the domain name. The home page is assigned the same Resource Group as many other pages. When people log out, they can see the home page. Why would this be happening?

    revo 2.2.6
      • 42562
      • 1,145 Posts
      The people logged in do NOT have the complete permission to see the Resource group(s) the Homepage belongs to.
      The home page is assigned the same Resource Group as many other pages.
      Are you saying that when people log in they are able to see the other pages in the same resource group that homepage belongs to, and are unable to see the homepage? I hope not!

      Try this one:
      LoggedinMembersGroup
      --> Context Access - web - load, list view
      --> Resource Group Access (myResourceGroupWithHomapage) - web - load, list, view
      except anyone logged in who is not admin can see and edit all the pages
      Are you letting them log into the manager, the back-end?
      You'll have to add the mgr context as well
      LoggedinMembersGroup
      --> Context Access - mgr - load, list view (resource/editor/ - whatever level)
      --> Resource Group Access (myResourceGroupWithHomapage) - mgr - load, list, view (resource/editor/ - whatever level)

      When logged out, they automatically "join" the *anonymous* usergroup, which in your case has permission to view the resource group in question.
      When logged in, they leave the *anonymous* and join a usergroup that does not have the appropriate permission to view the resources in the resource group.
      SUMMARY
      If logged in the front-end (www.blahblah.com/myhome/)- they need 'web' context access + specific resource group access (web)
      If logged in the back-end (www.blahblah.com/manager/) - they need 'mgr' context access + specific resource group access (mgr)
        TinymceWrapper: Complete back/frontend content solution.
        Harden your MODX site by passwording your three main folders: core, manager, connectors and renaming your assets (thank me later!)
        5 ways to sniff / hack your own sites; even with renamed/hidden folders, burst them all up, to see how secure you are not.