We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 16605
    • 16 Posts
    Hello guys,
    I need to restrict access to some of the pages on the site I am working on and I am having problems :-|.

    I have followed carefully the tutorials to make resources on the site restricted to logged in users

    http://rtfm.modx.com/display/revolution20/Making+Member-Only+Pages
    http://rtfm.modx.com/display/ADDON/Login.Basic+Setup

    and it is not working at all. I have flushed permissions, cleared site cache, did it a few times but it doesn't work.

    I applied the same steps on a different modx rev site just to find out if it worked and it did.

    --
    I follow all the steps, I get to this:

    "It is important to realize that as soon as you have protected a resource by (1) assigning it to one or more resource groups and (2) linking the resource group to a user group using an access control, those pages will no longer show up for users that are not linked to the resource group...."

    but nothing happens, the pages are not protected at all, it is just like I wasn't doing anything.

    I am using PageLocker 1 in the mean time to protect the resources but I will need to make this work soon,

    Has anybody else had this problem or is there a way for me to track the problem down please?


    Description of Problem: Restricted access to resources not working

    Steps to Reproduce: Follow the instructions (http://rtfm.modx.com/display/revolution20/Making+Member-Only+Pages) but at the end nothing is protected

    Expected Outcome: At the end the resources are not protected (and I test also not being loged in as a manager)


    • MODX Version: modx-2.2.7-pl
    • PHP Version: PHP Version 5.3.10-1ubuntu3.6
    • Database (MySQL, SQL Server, etc) Version: mysql server
    • Additional Server Info:
    • Installed MODX Add-ons: breadcrumb, getresources, login, MIGX, PageLocker, SimpleSearch, TinyMCE,Wayfinder
    • Error Log Contents: (attach as file if it’s too large)

    Thanks a lot for your help!!!

    Marcela [ed. note: lamarge last edited this post 13 years, 3 months ago.]
      • 22840
      • 1,572 Posts
      Make sure your not viewing the pages while still logged into the manager using the same browser, always best to test in a different browser
        • 16605
        • 16 Posts
        Yes, I test on separate browsers but not working :-(!
        Quote from: paulp at Jun 13, 2013, 08:07 AM
        Make sure your not viewing the pages while still logged into the manager using the same browser, always best to test in a different browser
          • 40553
          • 42 Posts
          There are many things to check to localize the root of the problem, yet you didn't give us much information regarding what is exactly happening when you access a page that is meant to be restricted.

          If it is normally accessible the you have most likely not assigned that particular page to a resource group.
          If you get a 503 error then it means that the page is locked down and it does not even have viewing permissions for anonymous users. Normally you should be redirected to unauthorized page which can be specified in the settings.


          1. check that your user group has a minimum role of Member 9999
          2. make sure that resources are actually added to that resource group
          3. remember about the anonymous user group, for unauthenticated users
          4. clear cache, flush sessions and permissions

          Provide us with more info and hopefully we'll be able to help you.
            • 3749
            • 24,544 Posts
            If you're trying to protect the resources in the front end, make sure your Resource Group Access ACL entries have a context of 'web'.

            To help understand the process, you might want to watch this video: http://modxpo.eu/2012/schedule/sessions/modx-revolution-security-permissions-system. It's about an hour long.

            You might also want to consider this method: http://bobsguides.com/blog.html/2013/05/22/protecting-pages-the-easy-way/
              Did I help you? Buy me a beer
              Get my Book: MODX:The Official Guide
              MODX info for everyone: http://bobsguides.com/modx.html
              My MODX Extras
              Bob's Guides is now hosted at A2 MODX Hosting
              • 16605
              • 16 Posts
              Thanks for your replies guys!
              Bob, I watched the video, it is a great way of understanding security in modx, so that was good!

              But, I am having a different kind of problem I think. I have done everything I should do and security is not working. I have done the same on a different installation of modx and it behaves the way it should, security worked there.

              Something else tells me the problem is not the way I am creating the users/groups/permissions.... I created a user and didn't assign it to a user group, when I login the user has permissions for everything, just like an admin. Isn't it wrong?

              Has anybody had this problem before?

              Thanks!!
              Marcela

                • 3749
                • 24,544 Posts
                Thanks for the kind words. It sounds wrong, but there are a lot of questions to answer.

                Is the user logging in to the front end or to the Manager?

                When you say the user "has permissions for everything" do you mean they can create and publish resources, see resources in the tree, see resources in the front end, or what?

                Did you flush permissions and flush all sessions after setting the user's permissions?

                Are you sure the user isn't designated as a sudo user?

                Are you testing from another browser where no one else is logged in.
                  Did I help you? Buy me a beer
                  Get my Book: MODX:The Official Guide
                  MODX info for everyone: http://bobsguides.com/modx.html
                  My MODX Extras
                  Bob's Guides is now hosted at A2 MODX Hosting
                  • 16605
                  • 16 Posts
                  Hello Bob,
                  Thanks for replying to this post,

                  - The user I created with no permissions at all is for the manager. Initially in this post I was creating a user for the front end and something similar happened so I left that and used a snippet called PageLocker. This time I need to create users for the manager and give specific permissions to them.

                  - Once I create the user (not doing anything else with it) I flushed permissions, flush sessions, clear cache on my browser and logged in. The user logs in and can access and edit everything, just like the admin. I understand the user shouldn't be able to login at all.

                  - The user isn't designated as a sudo user.

                  - I tried to login in a different machine (site had never been access from) and the same thing happened.

                  Any ideas? Thanks in advance for looking at this!!

                  Marcela


                  Quote from: BobRay at Jun 18, 2013, 06:27 PM
                  Thanks for the kind words. It sounds wrong, but there are a lot of questions to answer.

                  Is the user logging in to the front end or to the Manager?

                  When you say the user "has permissions for everything" do you mean they can create and publish resources, see resources in the tree, see resources in the front end, or what?

                  Did you flush permissions and flush all sessions after setting the user's permissions?

                  Are you sure the user isn't designated as a sudo user?

                  Are you testing from another browser where no one else is logged in.
                    • 3749
                    • 24,544 Posts
                    Without belonging to a user group that has a Context Access ACL entry giving access to the mgr context, the user shouldn't be able to log in at all (unless there is a Context Access ACL entry for the mgr Context for the (anonymous) user group).

                    Can you double check those possibilities?

                    Go to Security -> Manage Users
                    Right-click on the User and select "Update User"
                    See if there's anything on the "Access Permissions" tab.

                    Go to Security -> Access Controls
                    Right-click on the (anonymous) group and select "Update User Group"
                    Look on the "Context Access" tab and make sure there's only one entry and it's for the 'web' context.

                    Go to Security -> Access Controls
                    Right-click on the Administrator group and select "Update User Group"
                    Look on the "Context Access" tab and make sure there's an entry for the 'mgr' context with a Minimum Role of Super User.
                      Did I help you? Buy me a beer
                      Get my Book: MODX:The Official Guide
                      MODX info for everyone: http://bobsguides.com/modx.html
                      My MODX Extras
                      Bob's Guides is now hosted at A2 MODX Hosting
                      • 16605
                      • 16 Posts
                      Hello Bob,
                      Again, thanks so much for taking the time to look at this!
                      I have checked the 3 possibilities, they are all as you said they should. I attached screen grabs,

                      Thanks for any ideas that could help,

                      Marcela