We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 3749
    • 24,544 Posts
    Hmm . . . this is interesting. This is what gets called in $resource->checkPolicy() (in core\model\modx\modaccessibleobject.class.php):

    public function checkPolicy($criteria, $targets = null) {
      // ...
     $policy = $this->findPolicy();  // I wonder if this should be $this->getPolicies();
     if (!empty($policy)) {
       // ...
     }
     return true;
    }
    
    public function findPolicy($context = '') {
       return array();
    }



    You might try $resource->getPolicies(), which actually returns something.
      Did I help you? Buy me a beer
      Get my Book: MODX:The Official Guide
      MODX info for everyone: http://bobsguides.com/modx.html
      My MODX Extras
      Bob's Guides is now hosted at A2 MODX Hosting
      • 26503
      • 620 Posts
      Nope - neither work in API mode, both fine normally, the only difference appears that getPolicies may look through multiple contexts while findPolicy only the current context? '

      here is what we get in API mode:

      <pre>Array
      (
      )
      </pre><pre>Array
      (
          [web] => Array
              (
              )
      
      )
      </pre>


      getPolicies is returning part of the 'web' array ~ but no policy info, so it does work ~ just not in API mode.

      if we run getPolicies in a script loading modx externally but NOT in API mode, we get something a little more sensible.

      Array
      (
          [web] => Array
              (
                  [modAccessResourceGroup] => Array
                      (
                          [3] => Array
                              (
                                  [0] => Array
                                      (
                                          [principal] => 0
                                          [authority] => 9999
                                          [policy] => Array
                                              (
                                                  [load] => 1
                                              )
      
                                      )
      
                                  [1] => Array
                                      (
                                          [principal] => 2
                                          [authority] => 10
                                          [policy] => Array
                                              (
                                                  [add_children] => 1
                                                  [create] => 1
                                                  [copy] => 1
                                                  [delete] => 1
                                                  [list] => 1
                                                  [load] => 1
                                                  [move] => 1
                                                  [publish] => 1
                                                  [remove] => 1
                                                  [save] => 1
                                                  [steal_lock] => 1
                                                  [undelete] => 1
                                                  [unpublish] => 1
                                                  [view] => 1
                                              )
      
                                      )
      
                                  
                         /// many many many more items ------------------------>
      
                                  [2] => Array
                                      (
                                          [principal] => 22
                                          [authority] => 9999
                                          [policy] => Array
                                              (
                                                  [add_children] => 1
                                                  [create] => 1
                                                  [copy] => 1
                                                  [delete] => 1
                                                  [list] => 1
                                                  [load] => 1
                                                  [move] => 1
                                                  [publish] => 1
                                                  [remove] => 1
                                                  [save] => 1
                                                  [steal_lock] => 1
                                                  [undelete] => 1
                                                  [unpublish] => 1
                                                  [view] => 1
                                              )
      
                                      )
      
                              )
      
                      )
      
              )
      
      )
        *** Not just websites, we also create signage, banners, print, trade show displays and more! ***

        Sean Kimball CLP, CLS.
        Technical Director / Sr. Developer | BigBlock Studios
        ._______________________________________________.
        Bigblock Studios http://www.bigblockstudios.ca Web site design & development.
        27-1300 King Street East. Box 167 Oshawa, Ontario L1H8J4 Canada.
        phone/fax: 905-426-5525
        • 3749
        • 24,544 Posts
        I wonder if calling $resource->loadAttributes($target) before $resource->checkPolicy or $resource-getAttributes would help.
          Did I help you? Buy me a beer
          Get my Book: MODX:The Official Guide
          MODX info for everyone: http://bobsguides.com/modx.html
          My MODX Extras
          Bob's Guides is now hosted at A2 MODX Hosting
          • 26503
          • 620 Posts
          well, I think maybe I am zeroing in finally, it appears that I must have been running findPolicies & getPolicy on a non-restriced resource ~ hence they returned empty arrays. Also getPolicies seems to return an empty array if you don't run findPolicies first...? not sure what is up with that.

          So now I can get the permissions set on a $resource object with find/get policies & also from the user:

          $groups = $this->modx->user->getMany('UserGroupMembers');
          
          if($groups){
          
          	$membership = array();
          	
          	foreach ($groups as $group){
          		
          		$membership[] = array(
          		'principal' =>  $group->get('user_group'),
          		'member' =>  $group->get('member'),
          		'role' =>  $group->get('role'),
          		'rank' =>  $group->get('rank')
          		);
          		
          	}
          	
          }



          which gives me a nice little array which I can check against the permissions I retrieve with getPolicy.

          So to check to see if a user has access to a given resource in the API, we need to:

          - find out if the user is anonymous [user id = 0 or name = (anonymous)]
          - find out if the resource has access controls set [if getPolicy returns a populated array.]

          - if the user is anonymous & the resource has an empty permissions array = grant access
          - if the resources has an empty permissions array = grant access
          - if the user is logged in and the resource has an empty array = grant access
          - if the user is anonymous and the resource has a populated array = deny access
          - if the user is logged in and the resource has a populated array;
          > cross check the users group memberships for a match in the resource permissions array
          - if a match is found, check the policy key of that match for the 'view' key ( [view]=>1)
          - if the view key checks out = grant access
          - if the view key is not present = deny access


          Seems essentially correct to me, however in the UserGroupMembers I see a 'role' & 'rank' fields & in the getPolicy array there is an authority field. Should I be doing something else with those as well?
            *** Not just websites, we also create signage, banners, print, trade show displays and more! ***

            Sean Kimball CLP, CLS.
            Technical Director / Sr. Developer | BigBlock Studios
            ._______________________________________________.
            Bigblock Studios http://www.bigblockstudios.ca Web site design & development.
            27-1300 King Street East. Box 167 Oshawa, Ontario L1H8J4 Canada.
            phone/fax: 905-426-5525
            • 3749
            • 24,544 Posts
            You can forget about role and rank. The Role should already have had its effect on the user's permissions and I think rank is only for display purposes.

            I'm glad you're getting it to work. I think it was difficult because there was no request handled for the resource you're referring to, but I'm not sure of that.
              Did I help you? Buy me a beer
              Get my Book: MODX:The Official Guide
              MODX info for everyone: http://bobsguides.com/modx.html
              My MODX Extras
              Bob's Guides is now hosted at A2 MODX Hosting
              • 26503
              • 620 Posts
              ok - looks like it is finally done & working... I would up with this:

              	private function hasAccess($array, &$values) {
              		
              		global $parentKey;
              		global $thisOutput;
              		
              		foreach ($array as $key => $element) {
              						
              			if (is_array($element)) {
              				
              				$parentKey = $element;
              				
              				$this->hasAccess($element, $values);
              				
              			}elseif ($key == 'principal') {
              				
              				foreach ($values as $value) {
              					
              					if ($element == $value && $parentKey['policy']['view'] == 1){
              							
              							$thisOutput = 'true';
              	
              					}
              				}
              			}
              		}
              		
              		return $thisOutput;		
              	}


              and calling like this:

              	$resource = $this->modx->getObject('modResource',$id);
              		
              	$membership = $this->getUserGroups();
              		
              	$policies = $resource->findPolicy();
              		
              	if(count($policies) != 0){
              		
              		$checkPolicy = $this->hasAccess($policies,$membership);
              					
              		if(!$checkPolicy){
              				
              			return '{"error":"Access is denied"}';
              				
              		}
              		
              	}



              testing but it's looking pretty good.
                *** Not just websites, we also create signage, banners, print, trade show displays and more! ***

                Sean Kimball CLP, CLS.
                Technical Director / Sr. Developer | BigBlock Studios
                ._______________________________________________.
                Bigblock Studios http://www.bigblockstudios.ca Web site design & development.
                27-1300 King Street East. Box 167 Oshawa, Ontario L1H8J4 Canada.
                phone/fax: 905-426-5525
                • 51852
                • 2 Posts
                Quote from: sottwell at Apr 03, 2013, 01:32 AM
                You may have "load" or "list" permission, which you need in order to check if the resource exists or is published or a lot of other checks that get made on resources, but if you can't "view" it then you'll get permission denied if you try to actually access it.[...]

                Quote from: sean69 at Apr 01, 2013, 03:27 PM
                I tried 'load' and 'view_document' - bot came back true on the restricted resource.[...]

                Anonymous users should be able to "load" a resource (e.g. for redirection) while logged in users should have permissions to "view" the resource. I can't confirm that $resource->checkPolicy('view_document') returns true but $resource->checkPolicy('view') returns true only for logged in users, in contrast to $resource->checkPolicy('load') which returns true for anonymous and logged in users.

                I restricted a REST interface to all users having access to a resource which is protected by a resource group like this:
                <?php
                define('MODX_API_MODE', true);
                require_once dirname(dirname(dirname(__FILE__))) . '/index.php';
                
                $modx->switchContext('TEST');
                $resource = $modx->getObject('modResource', 1205); // Resource protected by resource group
                
                if (!$resource->checkPolicy('view')) {
                	die ('Unauthorized Access');
                } else {
                	...
                }
                


                P.S.: Please excuse me to answer an old thread but I like to propose this simple solution to everyone searching for a way to restrict a REST interface since google directed me here.