We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 38865
    • 10 Posts
    Hi there,
    I have a site that has a member protected section. Within this section there are a couple sub sections that are available to members of a sub set of the main group.
    Member Group
    -Member Type A Group
    -Member Type B Group

    Each of these user groups are directly linked to same resource access groups where the pages are "protected". Log in as one of the users that is a member of either Member Group or Group A/B and all works as expected. However if you log in as a user that isn't a member of any groups they have complete access to all the protected pages. In theory this should never happen as my user register form adds users to "Member Group" by default, however I've had issues where the client admins go in and create a user manually in the manager and forget to add user to the group and then this issue is encountered. Any idea on what I might be missing? Is this a bug or by design? Running Revo 2.2.6.

    Thanks in advance for any tips.
    Regards,
    Phill

    Edit: So looks like Modx is functioning as it should and this was just a user issue. When my client was manually creating users they were checking the "Sudo User" option for some reason (not sure if they knew what is does as the term isn't descriptive at all). This option, as it states, overrides all security checks so when removed things are all good! [ed. note: peelay last edited this post 13 years, 7 months ago.]
      • 22840
      • 1,572 Posts
      Lol, typical user, if you don't know what it does just pick anything lol
        • 39333
        • 151 Posts
        Lol, typical user, if you don't know what it does just pick anything lol

        That's why I try to remove every possible option I don't want the managers/users to have access to in Form Customization laugh

        I haven't done it myself but I bet there's a way to remove the sudo user selector from the new user form.
          MODX...the Zen of CMS
          "Bight off more than you can chew and keep right on chewing."
          • 3749
          • 24,544 Posts
          Right, you definitely don't want to have that option available to other users. A user could make him or herself a sudo user and change your username and/or password.

          This is a good reason not to put other admin Users in the Administrator group. Putting them in another group gives you more options for using Form Customization and other methods to prevent them from doing things they shouldn't be able to do.

          BTW, I don't think there is an easy way to remove the sudo option. AFAIK, Form Customization only works on Resources. I think it would take a custom plugin. It would make a great feature request to only show the sudo checkbox to the Admin super user and other users who are already sudo users, or to only show it to people with the role of admin Super User.
            Did I help you? Buy me a beer
            Get my Book: MODX:The Official Guide
            MODX info for everyone: http://bobsguides.com/modx.html
            My MODX Extras
            Bob's Guides is now hosted at A2 MODX Hosting