We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 42681
    • 64 Posts
    Is there any way to disallow viewing the Manager Actions (manager logs) for a user independently from the error log?

    It looks like the permission to view the Manager Actions can only be set in the Access Policies in combination with the permission to view the error logs.

    This question has been answered by BobRay. See the first response.

      • 3749
      • 24,544 Posts
      If you go into System -> Actions and update the Manager Actions item on the right side (under Reports), you can add a custom permission to that menu option. That will hide the menu option from anyone without that permission. I would call it see_manager_actions

      Permissions: logs,see_manager_actions


      It's *very* important to give yourself the custom permission first (and spell it correctly), before updating the menu option. Otherwise, you'll hide it from yourself and you won't be able to fix it without some unpleasant work in the database.

      Add the permission to the Administrator Policy Template, and make sure it's checked on the Administrator Policy before adding it in System -> Actions.




        Did I help you? Buy me a beer
        Get my Book: MODX:The Official Guide
        MODX info for everyone: http://bobsguides.com/modx.html
        My MODX Extras
        Bob's Guides is now hosted at A2 MODX Hosting
        • 42681
        • 64 Posts
        Hi Bob,

        thanks so much for your help.

        Btw: Is there any page where we can add a snippet which sends me a mail if anybody opens the manager-actions-page? Normally this should be no problem but I am not familiar with the modx-manager-templates and I don´t know where I should add these code lines.
        • discuss.answer
          • 3749
          • 24,544 Posts
          Yes, but the correct way would be with a plugin, not a snippet:


          This should do it, attached to OnManagerPageInit:

          <?php
          $allActions = $modx->request->getAllActionIDs('core');
          
          /* Do nothing if we're on some other page */
          if ($action != $allActions['system/action']) {
             return;
          }
          
          /* PHP code to send email goes here */
          
          
          
          return '';
          



          IMPORTANT: Be very careful when entering the code. Any syntax error will crash the manager on every manager page load. You won't be able to do anything at all in the Manager until you go into PhpMyAdmin, disable the plugin, and then delete all files in the core/cache directory.





            Did I help you? Buy me a beer
            Get my Book: MODX:The Official Guide
            MODX info for everyone: http://bobsguides.com/modx.html
            My MODX Extras
            Bob's Guides is now hosted at A2 MODX Hosting
            • 42681
            • 64 Posts
            Bob,
            your script works almost perfectly. Thanks a lot.

            The only problem is: $allActions['system/action'] returns not the manager log. Do you know how to return the action-id of the manager log?

            Is $action a system variable? Can I read anywhere more about this? I didn´t found anything in the rtfm about this. And the same concerning $modx->request->getAllActionIDs Where can I get more information about this call? Anywhere in the modx-rtfm?

            Thanks again!
              • 28042 ☆ A M B ☆
              • 24,524 Posts
              According to its URL it's a=system/logs, at least for Revo 2.3
                Studying MODX in the desert - http://sottwell.com
                Tips and Tricks from the MODX Forums and Slack Channels - http://modxcookbook.com
                Join the Slack Community - http://modx.org
                • 3749
                • 24,544 Posts
                Just visit that page and look at the URL. The ID of the action will be there. It's 66 in my local version (I think 2.2.13). The action is definitely 'system/action' on mine. I wouldn't expect that to change, but maybe it does in 2.3.
                  Did I help you? Buy me a beer
                  Get my Book: MODX:The Official Guide
                  MODX info for everyone: http://bobsguides.com/modx.html
                  My MODX Extras
                  Bob's Guides is now hosted at A2 MODX Hosting
                  • 28042 ☆ A M B ☆
                  • 24,524 Posts
                  In 2.3 it's just ?a=system/logs
                    Studying MODX in the desert - http://sottwell.com
                    Tips and Tricks from the MODX Forums and Slack Channels - http://modxcookbook.com
                    Join the Slack Community - http://modx.org
                    • 28042 ☆ A M B ☆
                    • 24,524 Posts
                    Hm. Looks like it doesn't track viewing any of the logs. At least, 2.3 doesn't. I haven't paid that much attention, but if I recall correctly, Evo tracks manager login and logout, viewing logs, all of the Manager actions.
                      Studying MODX in the desert - http://sottwell.com
                      Tips and Tricks from the MODX Forums and Slack Channels - http://modxcookbook.com
                      Join the Slack Community - http://modx.org
                      • 3749
                      • 24,544 Posts
                      Quote from: sottwell at Jul 22, 2014, 02:40 AM
                      In 2.3 it's just ?a=system/logs

                      Ah, right. In that case, you shouldn't need to get the action ID. 'system/logs' *is* the action ID. So this should work (untested):

                      <?php
                       
                      /* Do nothing if we're on some other page */
                      if ($action != 'system/logs']) {
                         return;
                      }
                       
                      /* PHP code to send email goes here */
                      
                      return '';
                        Did I help you? Buy me a beer
                        Get my Book: MODX:The Official Guide
                        MODX info for everyone: http://bobsguides.com/modx.html
                        My MODX Extras
                        Bob's Guides is now hosted at A2 MODX Hosting