We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 3749
    • 24,544 Posts
    I'm getting a very strange result with this code in a snippet:

    echo $modx->user->get('username') . '<br />';
    if ($modx->hasPermission('xxxababa')) {
       echo '<br />Has permission xxxababa';
    } else {
       echo '<br />Does not have permission xxxababa';
    }
    if ($modx->user->get('sudo')) {
       echo '<br />Sudo user';
    } else {
       echo '<br />Not a sudo user';
    }
    


    That permission does not exist (and never has).

    When I log in in the front-end (no one is logged in in the Manager), and visit the page with the snippet, I get this result:

    admin
    Has permission xxxababa
    Not a sudo user



    I flushed all permissions and sessions and deleted all files in the core/cache directory before testing. I've also tried it in several browsers with the same result and with different non-existing permissions. I checked the DB, and there is only one user with the username admin and the sudo field is 0. I get the exact same result when previewing the page from the Manager (not logged in in the front end).

    Is it expected behavior for a non-sudo admin to have a permission that doesn't exist in any policy?

    If I put this code in the checkPolicy() method in the modAccessibleObject class file:

    $policy = $this->findPolicy();
    /* added *
    if (empty($policy)) {
        echo 'Empty';
    }
    


    It prints 'Empty' (twice). Because the policy is empty, checkPolicy() returns true.

    [UPDATE] OK, I think I've found the cause. I had a web Context ACL entry for the administrator group with no policy specified. I'm not sure how that happened, but removing it solved the issue. I can see how that would cause checkPolicy() to return true, but it seems like that condition shouldn't result in everyone in the user group having all possible permissions. If it happened to the (anonymous) group, it could be pretty serious.

    Maybe it shouldn't be possible to save an ACL entry with no policy.
    [ed. note: BobRay last edited this post 12 years, 2 months ago.]
      Did I help you? Buy me a beer
      Get my Book: MODX:The Official Guide
      MODX info for everyone: http://bobsguides.com/modx.html
      My MODX Extras
      Bob's Guides is now hosted at A2 MODX Hosting