public function checkPolicy($criteria, $targets = null) {
// ...
$policy = $this->findPolicy(); // I wonder if this should be $this->getPolicies();
if (!empty($policy)) {
// ...
}
return true;
}
public function findPolicy($context = '') {
return array();
}<pre>Array
(
)
</pre><pre>Array
(
[web] => Array
(
)
)
</pre>Array
(
[web] => Array
(
[modAccessResourceGroup] => Array
(
[3] => Array
(
[0] => Array
(
[principal] => 0
[authority] => 9999
[policy] => Array
(
[load] => 1
)
)
[1] => Array
(
[principal] => 2
[authority] => 10
[policy] => Array
(
[add_children] => 1
[create] => 1
[copy] => 1
[delete] => 1
[list] => 1
[load] => 1
[move] => 1
[publish] => 1
[remove] => 1
[save] => 1
[steal_lock] => 1
[undelete] => 1
[unpublish] => 1
[view] => 1
)
)
/// many many many more items ------------------------>
[2] => Array
(
[principal] => 22
[authority] => 9999
[policy] => Array
(
[add_children] => 1
[create] => 1
[copy] => 1
[delete] => 1
[list] => 1
[load] => 1
[move] => 1
[publish] => 1
[remove] => 1
[save] => 1
[steal_lock] => 1
[undelete] => 1
[unpublish] => 1
[view] => 1
)
)
)
)
)
)$groups = $this->modx->user->getMany('UserGroupMembers');
if($groups){
$membership = array();
foreach ($groups as $group){
$membership[] = array(
'principal' => $group->get('user_group'),
'member' => $group->get('member'),
'role' => $group->get('role'),
'rank' => $group->get('rank')
);
}
} private function hasAccess($array, &$values) {
global $parentKey;
global $thisOutput;
foreach ($array as $key => $element) {
if (is_array($element)) {
$parentKey = $element;
$this->hasAccess($element, $values);
}elseif ($key == 'principal') {
foreach ($values as $value) {
if ($element == $value && $parentKey['policy']['view'] == 1){
$thisOutput = 'true';
}
}
}
}
return $thisOutput;
} $resource = $this->modx->getObject('modResource',$id);
$membership = $this->getUserGroups();
$policies = $resource->findPolicy();
if(count($policies) != 0){
$checkPolicy = $this->hasAccess($policies,$membership);
if(!$checkPolicy){
return '{"error":"Access is denied"}';
}
}You may have "load" or "list" permission, which you need in order to check if the resource exists or is published or a lot of other checks that get made on resources, but if you can't "view" it then you'll get permission denied if you try to actually access it.[...]
I tried 'load' and 'view_document' - bot came back true on the restricted resource.[...]
<?php
define('MODX_API_MODE', true);
require_once dirname(dirname(dirname(__FILE__))) . '/index.php';
$modx->switchContext('TEST');
$resource = $modx->getObject('modResource', 1205); // Resource protected by resource group
if (!$resource->checkPolicy('view')) {
die ('Unauthorized Access');
} else {
...
}