-
☆ A M B ☆
- 24,524 Posts
I'm attempting to create a read-only Manager login. A number of features do not have permissions other than access, for example the System Settings. If you have 'settings' permission, you can view, add, delete and edit all of the System Settings.
In the various update processors there is a public variable, $permission. Is there any way to assign more than one permission to this variable? An array doesn't work, nor does a comma-separated list. In the case of System Settings, I would want to have both 'settings' and 'save' permissions.
I can simply edit the line in the item's update processor to use 'save' instead of the item's specific permission, and the "sudo" user can save the settings even with a random non-existant permission value, but that's kind of flaky.
-
☆ A M B ☆
- 24,524 Posts
You know, now that I think about it, why is somebody who doesn't have the basic 'create', 'save', and 'remove' permissions able to perform those actions anywhere in the Manager
Hmm. In modprocessor.class.php, in the abstract class modObjectUpdateProcessor, it does in fact check for the 'save' permission.
modSystemSettingsUpdateProcessor extends modObjectUpdateProcessor, so why doesn't that check for 'save' permissions work?
[ed. note: sottwell last edited this post 12 years, 2 months ago.]
I'm having a weird, but slightly similar problem. This code (in the front end) always returns true even though there is no such permission and I'm not a sudo user.
return $modx->hasPermission('xxx');
An echo statement in the hasPermission() code tells me that checkPolicy() is returning an empty array, but I can't imagine why.