We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 45516
    • 14 Posts
    So, I've once again run into a "blip" when it comes to using resource group ACLs --- the AdvSearch addon doesn't account for resource group assignments and permissions when querying for search results. Oh sure, users can't actually reach those "locked" pages if they click on a link in the search results . . . but all of the pages supposedly "locked down" in a resource group still show up in the search results. My company definitely DOES NOT want "anonymous" users having ANY visibility into content we've flagged internally, even in an extract or shortened search result version.

    Now, if I was a PHP developer, I'd just go in and create my own snippet to compile an array of resource IDs that runs based on whether the user is logged in, and their permission sets, and then send those results to AdvSearch . . . but I'm not a PHP developer.

    It's just been a recurring theme for the way our company is using MODX --- MODX supports a fantastically flexible and configurable (if somewhat esoteric) permission system to allow users access to various pieces of the system and content . . . and then practically none of the content aggregation addons (other than Wayfinder and pdoMenu) actually USE THOSE PERMISSIONS.

    Now in this case, I've created a workaround using pdoMenu, a placeholder, and an output filter for that placeholder, then sending those results to AdvSearch . . . but as whole this workaround is just emblematic of the larger issue.

    So I'm wondering, is this just something that's sort of endemic to the MODX platform "ecosystem"? Understanding that the core platform is totally open source, it's easy to understand that when someone contributes an addon, they're generally just doing it for their own purposes. If it suits their use, they're not terribly concerned if it meets anyone else's. Since it's all free anyway, any contributions are purely at the discretion of the builder.

    Is it just generally not a concern for contributors in writing code that checks against permission sets? Is it just too much work to do so, meaning, are there too many variables to have to check against? I'm not trying to be critical, I'm just genuinely trying to understand.

    Personally, once I finally figured out the core concepts of Revo's permissioning, I found it generally useful, and I like the flexibility. Occasionally I find it a bit of a pain to have to update or revise some things, but overall I'm not displeased with total concept. But then I find myself having to fight against other components that simply aren't making use of the permission structures.

    Is there a better way, both structurally and from a user perspective, where permissions could move in the future? And would that direction encourage developers to consider using them more?
      • 4172
      • 5,888 Posts

      Its not that difficult to check the permissions of Resources.
      You can get a list of Resource-ids, where the current user has list-permissions, for example with this snippet:

      <?php
      
      $parent = $modx->getOption('parent', $scriptProperties, 0);
      $depth = $modx->getOption('depth',$scriptProperties,10);
      $context = $modx->getOption('context',$scriptProperties,$modx->context->get('key'));
      
      $c = $modx->newQuery('modResource');
      $c->select('id');
      $c->where(array('id:IN' => $modx->getChildIds($parent,$depth,array('context'=>$context))));
      $ids = array();
      if ($resources = $modx->getCollection('modResource', $c)) {
          foreach ($resources as $resource) {
              if ($resource->checkPolicy('list')) {
                  $ids[] = $resource->get('id');
              }
          }
         
      }
      return implode(',', $ids);
      ?>
      


      And you can put this list to AdvSearch's ids - property:

      &ids=`[[getAllowedIds]]`
        -------------------------------

        you can buy me a beer, if you like MIGX

        http://webcmsolutions.de/migx.html

        Thanks!