The administrator policy template (and thus the depending policies) is (as far as I can see even in 2.3) too large to handle it in real life scenarios. Configuring it is quite unhandy and error-prone (unticking 150 settings to achieve a certain restricted policy with minimal rights?). Of course you can do it once for a "master" project and then export/import the policy into other projects to get rid of some of these problems. But the underlying AdministratorTemplate still forces you to search through all settings if you want to change just on in your policy.
To help in configuring permissions for our end users I have build (yes, manually in XML) some new policy templates, which have settings in there grouped by "purpose". As you are advised to make a duplicate of the default template and policy when you start to configure Modx ACLs (to prevent problems with updates, very important!) it is not more work to import these special templates.
I have build up the following templates so far:
- ManagerUserTemplate: a set of permissions a user needs to use the manager at all (login, user profile, menu items etc)
- ActionsTemplate: a set of permissions a user needs to act in the manager - like save resources, update resource, create new symlink etc.
- PublisherTemplate: a set of permissions a user needs to do publishing work
- FileManagerTemplate: a set of permissions a user needs to do basic file operations - like create, list, use filemanager etc.
With the help of these templates it is quite easy to set up permissions for your users, e.g. with roles for publishing and editing in a group:
- assign a ManagerUser based policy to a group with role member
- assign an ActionsTemplate based policy to editor roles
- assign a PublisherTemplate based policy to publisher roles
- add the users with the needed roles to the group
Note: by default all permissions are enabled if you create a policy based on the imported templates. Of course you will have to adjust the policies to your needs - for example by disabling access to the components menu for your users. But with the help of these smaller templates it is quite more easy to find (the permission is set in ManagerUserTemplate) and you do not have to look through all 172 settings to find it.
Of course the actual arrangement of the permissions into these templates is worth a discussion. One may find it more consequential to compose them in a different way. I am looking forward for your suggestions here. Maybe the idea behind will make its way into a future release?
Until that I hope this is useful for some other ModXers...
Jens