We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 3647
    • 177 Posts
    Hi

    I followed the tutorial for members only pages and thought everything was working OK, but have just realised that all the members also have full admin access to the manager as well!

    I also created some manager users that could access front and back end,also using the rtfm tutorial but didn't expect the members to have any access.

    Could anyone point me in the right direction to shut that off - all the different places, roles, policies, templates etc still doing my head in

    Thanks

      • 3749
      • 24,544 Posts
      Access to the Manager is controlled by Context Access ACL entries. If there is at least one ACL entry of that type connecting a user group (e.g., Administrator) to the 'mgr' context, that context is "protected."

      The default ACL entries should cover that unless you've deleted one.

      Once that condition exist, the only users who can log in to the Manager are users who belong to a user group that has been given access to the 'mgr' context with a Context Access ACL entry.

      IOW, you have a Context Access ACL entry with a context of 'mgr' that shouldn't be there.

      Tip: Forget about roles. Put users with different rights in different user groups and put nobody but admin Super Users in the Administrator group. A user can belong to more than one user group.

      If you have the time, here's an hour's worth of info on MODX security permissions: http://modxpo.eu/2012/schedule/sessions/modx-revolution-security-permissions-system
        Did I help you? Buy me a beer
        Get my Book: MODX:The Official Guide
        MODX info for everyone: http://bobsguides.com/modx.html
        My MODX Extras
        Bob's Guides is now hosted at A2 MODX Hosting