I don't know what I mean! I'm kinda confused at the moment. Deal with ACLs all day long at work but for some reason the lightbulb isn't going off. I remember when I first started using ModX I couldn't figure out for the life of me the use or need of a template variable. Then there was an application where I needed it and all of the sudden I went, "duh!!" and I fully got it. I am just waiting for that ah-hah moment to happen with Modx ACLs. I am going to delete all my resource groups and start fresh tonight.
This is what I want to do. The main administrator will have access to everything, obviously. The rest of the IT staff will only have access to one folder to create and edit resources. They also only need to see the Resource tab and the File tab for just their media resources (which I have set up and working.).
To do this I will ...
Create a resource group for the admin and assign all resources to that resource group. Then I will create an IT Staff group and assign just the resource folder they need access to to them. All I will also assign that group an administrative policy I have set up that removes 99% of the features the backend offers to they have minimal options. (They like things simple).
My hope is then that everything will work? Do I have it right?
discuss.answer
-
☆ A M B ☆
- 894 Posts
You need to create 2 resource groups 1 for Admins and another for your IT Staff.
Admin Resource Group: Drag all resources to the admin resource group.
IT Staff Resource Group: Drag only the resources the IT Staff need access to.
Go to Security > Access Controls, click on the Access Policies tab and duplicate your administrator policy.
Enable/Disable any features you want for your IT Staff user group and save your access policy.
Go to Security > Access Controls right click your IT Staff user group and choose Update User Group
Click on the Context Tab make sure you have mgr and your web context or whatever context it is they need access to and change the access policy to use the IT Staff policy you created by duplicating the administrators policy.
Click on Resource Group Access tab and make sure you have access to the IT Staff resource group.
Flush Permissions or Flush Sessions and clear your cache.
Try logging in as an IT Staff user you should only see the resources in the IT Staff Resource Group.
If you don't see the IT Staff Resource Group when logged in as an Admin account make sure you add access to the Resource Group to your admin account.
Hopefully that gets you where you need to be.
Good Luck.
Thanks benmarte. You went out of your way to help and it is greatly appreciated. I will let you know after I make the changes if everything is working. Thanks again for all your assistance. I hope after this project then I am knowledgable enough to start helping others here.
I was right! As I was working through this issue last night the lightbulb went off and everything made sense. I have everything working thanks to all your help. Thanks to both of you for all your assistance.
-
☆ A M B ☆
- 894 Posts
leemchildress thats great, care to share what you did in case someone else has issues
Truthfully, I just followed the instructions you provided and it worked like a charm. I just was screwed up in the way I was thinking the whole ACL out. Once you get it though, it makes complete sense. The only problem I can't figure out yet is I created two resource groups, one for admin and one for staff (editors) to separate who can see what. But when an editor edits a document, under the resource tab he sees both the staff resource group AND the admin resource group. I need to hide only the admin resource group from the editor and have conquored that yet.
-
☆ A M B ☆
- 894 Posts
I'm not sure I follow you, so when a staff member edits a resource he can see and admin resource?
If so I think the problem is that if an admin creates a new resource he needs to make sure it is only part of the admins resource group, there's a tab on every resource that says resource group you can select what resource group it belongs to when creating or editing a document.
Bobray made a handy extra that takes care of this for you which you can download
here.
Hopefully that is your issue and not something else, if so we might need a screenshot to see what you mean.
Good Luck.
I am creating a knowledgebase site for our IT staff. There are articles the general kb articles that the overall employees of the company can view, there are documents that only the IT Staff can view, and then there are all the pages, elements, etc. that only the admin can see. Only reason for not making the IT staff admins is I wanted to strip away everything but the essentials to make it easy for input.
I made the administrator part of the Admin resource group and assigned all the pages for just the administrator to that group. Works fine. Pages are only visible to the admin in the backend. I have a resource group called IT staff which is assigned to ... you guessed it, the IT staff. When a knowledgebase article is assigned to this resource group, only the IT staff can see it, not the overall employees of the company. These articles contain passwords or other info that outside of the IT department doesn't need to know.
Everything works.
When the IT staff adds an article and goes to the Resource group tab to select IT staff so that it becomes a "private" kb article, they also see the option to choose the admin resource group. If they were to accidently check that, then they would no longer be able to see that article. I need to hide the admin resource group with its checkbox. A screenshot is attached.
-
☆ A M B ☆
- 894 Posts
What you can do is use Bobrays extra since it sounds like all resources created by ITStaff will be private and remove access to the Resource Group tab by modifying the ACL policy for the ITStaff group, this will work unless the ITStaff will make documents that need to be public as well.
I get what you're trying to do but sometimes you can't fix stupid so if they lock themselves out of a resource then they have to contact an admin and he will have to go and change the resource group checkbox.
Good Luck.
lol @ "fixing stupid". It's ironic that we have a bunch of very intelligent IT people, but when it comes to documentation it is hard enough just to get them to write it and if they have to do too many clicks or steps they would rather not document anything. Again, thank you for your help. Your instructions were remarkable.