We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 40385
    • 75 Posts
    Hello,

    while I was creating a new resource group modx prompted me to create a new user group for this resource group automatically. I enabled this feature and reviewed the new user group. Interestingly the context access tab was empty but it was still possible to access each resource without receiving a 404 error. I was wondering if this behavior is expected/new:

    I'm referring to this rtfm article: http://rtfm.modx.com/display/revolution20/More+on+the+Anonymous+User+Group

    By default, Anonymous Users are granted Load Only permissions in every Context except the "mgr" Context. Without Load Only permissions, requests to the Context would result in a 404 Page Not Found response.

    I also deleted all context access rows for the anonymous user but I'm still able to access each resource without receiving any 404 error. I'm using modx revo 2.2.7-pl (traditional)

    Any ideas why the context access is no longer needed to access resources?

    Thanks in advance.
      • 3749
      • 24,544 Posts
      Are you testing from another browser where you're not logged into the Manager?
        Did I help you? Buy me a beer
        Get my Book: MODX:The Official Guide
        MODX info for everyone: http://bobsguides.com/modx.html
        My MODX Extras
        Bob's Guides is now hosted at A2 MODX Hosting
        • 40385
        • 75 Posts
        Quote from: BobRay at Apr 26, 2013, 11:01 PM
        Are you testing from another browser where you're not logged into the Manager?

        Yes. I'm not logged in.
          • 3749
          • 24,544 Posts
          Maybe I'm misunderstanding your setup, but it sounds to me like the Resources are not protected in any way. Putting Resources in a Resource Group does not protect them from anyone.

          They are only protected when the Resource Group is connected to a User Group with a Resource Group Access ACL entry. Then, they're protected from people outside that User Group.
            Did I help you? Buy me a beer
            Get my Book: MODX:The Official Guide
            MODX info for everyone: http://bobsguides.com/modx.html
            My MODX Extras
            Bob's Guides is now hosted at A2 MODX Hosting
            • 40385
            • 75 Posts
            Well, that is clear to me. But my question is not about the Resource Group being protected or not. It's more about understanding the meaning/behavior of the context access tab.

            Let's say I don't have any resource group at all. As far as I understood the rtfm and the setup in prior revo releases it was always necessary that the anonymous user group (an all other groups) need at least Load Only permissions in the Web Context (Context Access tab) to access a resource in this context (no matter if in a resource group or not). But that isn't the case anymore with Revo 2.2.7-pl. I deleted the context access for the anonymous user and I'm still able to access any resource without receiving a 404 error. When I understand the rtfm correctly I should now receive the 404 error page when accessing a resource of the web context anonymously, don't I? Because it says:

            By default, Anonymous Users are granted Load Only permissions in every Context except the "mgr" Context. Without Load Only permissions, requests to the Context would result in a 404 Page Not Found response.

            Maybe I simply got this wrong or this is somehow misleading, but why does the anonymous user group has a Load Only permission by default in every context when it is not necessary to view the resource? [ed. note: paul_kemp last edited this post 13 years, 5 months ago.]
              • 3749
              • 24,544 Posts
              This Context Access ACL entry is installed by default (unless that's changed):
              Context: 'web'
              Minimum Role: Super User
              Access Policy: Administrator



              In theory, it protects the web Context, so (anonymous) users need Load permission to access any resources in that Context.

              Did you remove that ACL entry?
              Did you flush permissions *and* sessions before testing?

              Maybe things have changed.
                Did I help you? Buy me a beer
                Get my Book: MODX:The Official Guide
                MODX info for everyone: http://bobsguides.com/modx.html
                My MODX Extras
                Bob's Guides is now hosted at A2 MODX Hosting
                • 40385
                • 75 Posts
                Quote from: BobRay at Apr 29, 2013, 12:46 AM
                Did you remove that ACL entry?
                No

                Quote from: BobRay at Apr 29, 2013, 12:46 AM
                Did you flush permissions *and* sessions before testing?
                Yes

                Quote from: BobRay at Apr 29, 2013, 12:46 AM
                Maybe things have changed.
                Yes, I assume that they changed something so that the context access tab is only relevant in case a user group has access to the mgr to control which context they can modify. To limit frontend access I think the only relevant tab is the resource group access tab. Maybe this change can be reflected in the rtfm as well since this makes the whole user permission management less confusing IMHO.
                  • 3749
                  • 24,544 Posts
                  That's interesting. Something else you might check (if that's changed, this might have too):

                  Create a new user who is not in the Administrator group but in another User Group that has a Context Access ACL entry giving them access the 'mgr' Context.

                  When that user logs in, can they see the resources in the 'web' Context in the Resource tree?

                  Traditionally, that would take another Context Access ACL entry giving them access to the 'web' Context.
                    Did I help you? Buy me a beer
                    Get my Book: MODX:The Official Guide
                    MODX info for everyone: http://bobsguides.com/modx.html
                    My MODX Extras
                    Bob's Guides is now hosted at A2 MODX Hosting
                    • 40385
                    • 75 Posts
                    Quote from: BobRay at Apr 29, 2013, 04:26 PM
                    That's interesting. Something else you might check (if that's changed, this might have too):

                    Create a new user who is not in the Administrator group but in another User Group that has a Context Access ACL entry giving them access the 'mgr' Context.

                    When that user logs in, can they see the resources in the 'web' Context in the Resource tree?

                    Traditionally, that would take another Context Access ACL entry giving them access to the 'web' Context.

                    No, that still doesn't work. This user group still needs Load, List and View context access to see that context in the resource tree.

                    Well, to sum it up, we could say the following:
                    - The context access tab is only relevant when giving a user group 'mgr' access and access to a certain context in the mgr.
                    - For user groups that don't have 'mgr' access the context access tab can be empty. To restrict access to a resource the only relevant tab is the resource access tab

                    Seems to be less confusing...I think a lot of users, including me, had problems understanding the meaning of the context access tab in regard to the frontend. Now we're having a clear distinction between mgr and frontend.
                      • 3749
                      • 24,544 Posts
                      That makes sense -- in fact one of my suggestions for MODX 3 was to separate Manager permissions from front-end permissions. This would be a step in that direction.
                        Did I help you? Buy me a beer
                        Get my Book: MODX:The Official Guide
                        MODX info for everyone: http://bobsguides.com/modx.html
                        My MODX Extras
                        Bob's Guides is now hosted at A2 MODX Hosting