We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 46584
    • 29 Posts
    Hi,

    I have sucessfully created 3 user groups

    Administrator - users have access to everything mgr and web
    This user group is for me, and other members in my web development team to have full access.

    Editor- users have restricted access to mgr actions controlled by a specific access policy, and everything web
    This user group is for the client's access to the backend - restricted to only allow them to edit resources, create users and keep them away from anything they can break.

    Member - no mgr access and restricted web


    Now everything is working fine...
    The client can only see the resources I want them to.
    Members can login and see private areas of the website

    However I have one serious problem
    I have found that an Editor user can add a user to the Administrator user group.
    I need an Editor to ONLY be able to add users to Editor or Member (not Administrator)
    There doesn't appear to be any way to set any kind of heirarchy on the user groups.

    And indeed worse still I've found that they can tick the "Sudo User" box too.


    Is there something fundamental I have missed about how to set up ACLs in MODx Revolution.
    It seems impossible to lock this down.

    Can anyone advise?

    many thanks

    Ian.
      • 3749
      • 24,544 Posts
      No, you haven't missed anything -- either users can create other users or they can't. There's no easy way to restrict what kind of users they create or what user groups they put them in.

      There are a couple of workarounds. You can essentially duplicate the whole user management system for low-level users, making some groups not show up in the groups drop-down and removing the sudo checkbox. Then you can use custom permissions to hide the regular user management menu from them and show them the duplicate. Needless to say, this is not a trivial job.

      Another approach is to write a plugin attached to OnUserFormPrerender and OnUserFormSave. It only acts for certain, low-level users. On the first event, it hides the sudo checkbox. On the second event, it refuses to save the user if any illegal user groups have been assigned. This is much easier, but a little clunky.

      It's also theoretically possible to hide forbidden user groups in the user group dropdown in the form. IIRC, there is an 'exclude' term in the JavaScript, but I've never figured out how to set it without hacking the JS code. There's probably a way.





        Did I help you? Buy me a beer
        Get my Book: MODX:The Official Guide
        MODX info for everyone: http://bobsguides.com/modx.html
        My MODX Extras
        Bob's Guides is now hosted at A2 MODX Hosting
        • 46584
        • 29 Posts
        Many thanks Bob

        It's 'good' to know that it's a limitation of the system rather than me getting it wrong smiley

        I will look into the workaround solution you suggest and let you know how I get on.

        TBH, I had expected the manager permissions system on Revolution to allow restrictions similar to the ones I have been able to set on numerous Evolution websites. On Evolution I was able to set up restricted users that can not add admin users.

        Actually for the particular website we are making in Revolution it's not too much of a concern since there will be a small set of CMS users that can be trusted, but I can see this being an issue if we have another client with a larger pool of CMS users.

        Ah well, another wee MODx hack type thingie to add to my to-do list.

        regards

        Ian.