Hi,
I need to set up limited access for one specific user (user1) with rights only to documents on second level of documents tree (news). I created AllDocs group with access to all documents and to administrators, then say group LimitedAccess with access to LimitedAccess resources - just one document on the second level (news). Assigned user1 to group LimitedAccess, cleared cache, flushed permissions and after login - user cannot see anything. If I add parent doc. to LimitedAccess resources, user1 can see all. Is it possible to limit its access only to subdirectory resources without parent doc.?
home
parent
news
news1
news2
Without the permission, MODX can't load the parent to show its children. I think it will solve it if you can put the parent in a separate Resource Group and connect that Resource Group to the User's group with a Resource Group Access ACL entry with a policy of "LoadOnly".
Thanks, "LoadOnly" policy was not enough, nothing changed, I had to set up "Load List and View". So it is not possible for some manager user to see only subfolders without its parent? Problem is if I set up parent as recommended I can see all possible subfolders on the same level.
You could put the other subfolders in another resource group and protect it by connecting the group to the Administrator user group with a Resource Group Access ACL entry (context of 'mgr'). You wouldn't have to protect the children, just the parent folders.
-
☆ A M B ☆
- 279 Posts
Shouldn't you use some "root_id" system setting? (don't know the exact name right now)
[edit]
you can use this setting on user-level for each single user (unfortunate there aren't usergroup settings yet)
'tree_root_id'
I don't think it will work for the OP, though because the intent is to hide some sibling folders and not others.
It works. Actually I have it set up this way. But it is very laborious to do it this way for a lot of users. There are not any user groups settings.
The problem is it seems that settings via tree_root_id and ACL cannot be combined. When I set tree_root_id for user I can see resources which he should not see according ACL.
So if I use tree_root_id is it possible someway to limit user actions using specified policies rights?
That definitely shouldn't happen. The ACL restrictions should be applied no matter what they can see. Did you have the ACL entries working properly before you set the tree_root_id setting?
If you remove the tree_root_id setting, do the forbidden docs disappear from the tree?
(Be sure you're flushing both permissions and "all sessions" after making any changes.)