we are using ACLs for an internal context.
There are anonymous and registered user groups.
In my understanding I assign a ressource (lets say ID 100) to a resource group.
After that the resource is only accessible for the appropriate groups (in the frontend).
All resources below that ID 100 should also be automatically inaccessible for anonymous.
Is that correct or do I have assign all childs also to a resource group?
-
☆ A M B ☆
- 24,524 Posts
You have to assign every resource to the group. I think there may have been an add-on plugin to do something like this, but I don't exactly remember what it was.
It is in the works as a core function, though
http://tracker.modx.com/issues/5203
Aha! Found it!
http://modx.com/extras/package/inheritresourcegroup
[ed. note: sottwell last edited this post 13 years, 3 months ago.]
'a bait' (omg)
many thanks
In my understanding I assign a ressource (lets say ID 100) to a resource group.
After that the resource is only accessible for the appropriate groups (in the frontend).
This is a common misconception, but putting a resource in a resource group doesn't protect it at all.
The protection comes when you connect the resource group to a user group with a Resource Group Access ACL entry. That protects the resource from people outside that user group unless they belong to another group that has access to the resources.