We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 42535
    • 52 Posts
    REVO-2.2.6

    I've created a login and logout page as well as the forgotten password functionality according to the guide here: http://rtfm.modx.com/display/ADDON/Login.Basic+Setup

    Everything works fine except that I can't seem to prohibit access to any of my pages for non-logged in users. All content is available to everyone, even when not logged in.

    What should the Anonymous User Group have as its default permissions? Maybe I overwrote something there in the past and broke it?
      • 28042 ☆ A M B ☆
      • 24,524 Posts
      Are you logged in to the Manager when checking these pages? It's a good idea to always use a different browser for checking protection on front-end pages.
        Studying MODX in the desert - http://sottwell.com
        Tips and Tricks from the MODX Forums and Slack Channels - http://modxcookbook.com
        Join the Slack Community - http://modx.org
        • 32699 ☆ A M B ☆
        • 427 Posts
        You also have to add them to Resource Groups and set the lowest level ACL allowed to access it.
          Get your copy of MODX Revolution Building the Web Your Way http://www.sanitypress.com/books/modx-revolution-building-the-web-your-way.html

          Check out my MODX || xPDO resources here: http://www.shawnwilkerson.com
          • 42535
          • 52 Posts
          Quote from: sottwell at Jun 06, 2013, 07:28 PM
          Are you logged in to the Manager when checking these pages? It's a good idea to always use a different browser for checking protection on front-end pages.

          Ugh. This is all it was. I thought I had tried access from my iPad during this, but clearly I did not. Using a different browser yields the [semi] expected results.

          I now have a different issue... I'm using Wayfinder to build my menus. If I click the page link for the protected page while not logged in, I just stay on the main page. No errors or anything.

          Is there an easy way to extend Wayfinder to simply not show the hidden pages when not logged in?
            • 32699 ☆ A M B ☆
            • 427 Posts
            Once you acl's are correct, wayfinder will not show anything they do not have access to.

            You are bounced to the front of the site as it is the default unauthorized page.
              Get your copy of MODX Revolution Building the Web Your Way http://www.sanitypress.com/books/modx-revolution-building-the-web-your-way.html

              Check out my MODX || xPDO resources here: http://www.shawnwilkerson.com
              • 42535
              • 52 Posts
              Quote from: wshawn at Jun 06, 2013, 08:29 PM
              Once you acl's are correct, wayfinder will not show anything they do not have access to.

              You are bounced to the front of the site as it is the default unauthorized page.

              From my home page, I see the restricted page in the list of pages from Wayfinder. From any other page, however, it is not there.

              UPDATE: There is a caching issue. Sometimes the page link shows up, sometimes it does not. Clearing the site cache is the only way to get it to display correctly after logging in or out. [ed. note: ember1205 last edited this post 13 years, 3 months ago.]
                • 32699 ☆ A M B ☆
                • 427 Posts
                Try running Wayfinder uncached. [[!wayfinder....

                The reason being if a authenticated user logs in first, it may cache "their" menu to the modx cache, which will cause users to hit the unauthorized page if they try to visit those pages.

                The opposite is true also, if the first served is restricted access the cached menu may reflect that restriction.
                  Get your copy of MODX Revolution Building the Web Your Way http://www.sanitypress.com/books/modx-revolution-building-the-web-your-way.html

                  Check out my MODX || xPDO resources here: http://www.shawnwilkerson.com
                  • 42535
                  • 52 Posts
                  Quote from: wshawn at Jun 06, 2013, 09:09 PM
                  Try running Wayfinder uncached. [[!wayfinder....

                  The reason being if a authenticated user logs in first, it may cache "their" menu to the modx cache, which will cause users to hit the unauthorized page if they try to visit those pages.

                  The opposite is true also, if the first served is restricted access the cached menu may reflect that restriction.

                  Thanks... That was just what I needed.

                  Now I just need to get my password change page created and everything should be working the way I wanted.
                    • 28042 ☆ A M B ☆
                    • 24,524 Posts
                    Hm. That's good to keep in mind. I've always kept my "listing" snippets uncached for performance.
                      Studying MODX in the desert - http://sottwell.com
                      Tips and Tricks from the MODX Forums and Slack Channels - http://modxcookbook.com
                      Join the Slack Community - http://modx.org
                      • 42535
                      • 52 Posts
                      Quote from: sottwell at Jun 07, 2013, 07:15 AM
                      Hm. That's good to keep in mind. I've always kept my "listing" snippets uncached for performance.

                      What sort of performance reasoning would drive the use of keeping listing snippets uncached? I would have thought CACHING them would benefit performance.