Hi
I have created an admin group who need to be able to create/edit users. No problem. But I do NOT want these admin users to be able to change my Super User account. How can I achieve this?
Unfortunately, the use management system isn't that granular. Either users can create and modify users or they can't.
The only solutions I know of are:
1. Create a CMP or front-end form for them to do their user management
2. Create a plugin connected to OnDocFormSave that undoes changes or forwards somewhere if an unauthorized record is being edited.
3. Refactor the Create/Edit User process yourself and replace MODX's version (not for the faint of heart).
Ah....I had hoped there was an easier answer that I'd missed. Might try a hack where an admin user can only view/edit users where their authority is >= their own. If I chicken out, I think it'll have to be Number 1.
Thanks
Your idea might be possible with a plugin attached to OnUserFormPrerender and OnUserFormSave. The only variables available there are $id and $mode (update or new). The $id variable is the ID of the user being edited, if any. The catch would be whether $modx->user is available there so you could determine who is doing the editing.
One problem is that users can have different roles (authority levels) in different groups. I would recommend putting the users who can create users in their own group (not the Administrator group). Putting them in the Administrator group limits your options for Form Customization.
[Update] I just did a quick check and $modx->user is available in both events.
[ed. note: BobRay last edited this post 12 years, 6 months ago.]