We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 34118
    • 45 Posts
    Hi All,

    Getting back to ACLs. I've a few thoughts.
    Based on Revo 2.2.14 and only build sites occasionally in MODx. So never get enough practise and I may be missing insights. But it makes me an informed newbie I think.

    ACL stuff is tough. Most folks don't build websites for mega-corporations with hordes of different users/supervisors/editors/subeditors/supereditors/liteAdmins/heavierAdmins/GuruAdmins. You build a site and hand it over to one person who wants a CMS to update their website. That's it. One Editor who wants to do everything sensible. In general. Most of the time. Etc.

    My guess, based on no real data, is that 99% of sites have one Owner/User/Editor. As the site Developer all you really want to do is hide the Elements Tab and the Manager Stuff that would allow them to destroy the site. And limit Media Sources so they know where to upload images and pdfs etc. but enable them to actually save images/pdfs etc without jumping through hoops.


    As things stand the out of the box setup of Policies is for the 1% IMHO. The Ninja Gurus building sites for Ford or a hotel chain and the like.



    My last attempt at ACL went reasonably well following Bob's Guide. Took about 45 minutes of careful work. Trying to learn stuff and take notes. But then there was a long process working with the site users where they tried to do stuff and kept getting blank screens or Permission Denied for Media Upload type stuff.

    I'm sure MODx Ninjas could do it in less than 5 minutes. But that's not me and certainly isn't likely for Newbies. Particularly as you have to figure out which of 172 boxes to tick/untick + many more for MediaSource Template + Context Template etc. In addition to trying to understand the interface (when to right click), tasks that are mandatory or optional, potential for 'chaining' Access Policies in the Context Tab etc.

    Suggestions: rather than rewrite the code make the defaults more agreeable.


    1) Create an Editor User Group in parallel with the Administrators and Anonymous. This should mean nobody new needs to worry too much about Roles (and the epic confusion that a Higher Role is actually a Lower Role).

    2) My ContentEditor Duplicate Policy ended up with 36 of 172 rather than 24 of 172. Hopefully, I've got these correct - some guessing went on. So, have the ContentEditor setup for the 99% with approx 36 of 172 options. Whatever they might be that would allow an Editor to do appropriate stuff instead of being all but dead in the water out of the box. Things like hiding the file-tree by default! Why would someone want a site where they couldn't add images or pdfs?

    3) Same for MediaSource. Looking at my notes I had to add Save (thinking that would be enough) only to realise that Create is also required. This for the Owner/User/Editor to do something really simple like uploading and saving an image. Hardly a controversial capability for a website CMS.

    4) Alternatively, instead of Content Editor and Media Source Policies that are actually useful (sarcasm, sorry) how about emphasising that the Context Access Tab Table can have lots of Polices 'chained' or added together. In hindsight the interface is obviously a table but reading the docs and guides the workflow suggests duplicating the ContentEditor based on the Admin Policy Template. In other words you would only need one Policy added (albeit with having to learn 172 options). How about having a ContentEditor (24of172) and a UsefulContentEditor (sarcasm again) with the 8 or so extras that I've had to use. Then you use both to setup an Editor with a litte more power than the current default.[/li]


    I appreciate the 3 of 7 Media settings and the 24 of 172 will have been carefully chosen for maximum protection from blundering Owner/User/Editors. But I think they are too stringent. And Roles are a pain and can mostly be bypassed most of the time. My suggestions above could be implemented without any actual code changes. Although the need to Right Click in one or two places for Crticical Path tasks could be addressed too.


    Make it easy for the 99%. Let the Ninjas do the hard work - they'll find it easy enough.
    I think it could be possible for a relative newbie to add a typical User/Editor in 45 seconds or so.


    Any thoughts.

    Stuart

      • 39092
      • 9 Posts
      I so agree with what Stuart is saying

      I have so far spent a day trying to get to grips with it, and following the tutorials but still a complete mystery to me why users are getting access denied, and in some case after thinking I've fixing it and then they can;t log in at all.

      After spending so much time, and being under pressure from users, the answer you come up with is to open up everything to everyone just to get out of the hole - and that can't be a good idea, the opposite of what was intended no doubt.

      I know it is my fault, so don't start!

      But a package or a pre installed moderate level that would work in the 90% case of a developer and a site admin customer would be very very welcome.

      In the meantime Stuart, any chance you could share a screenshot of your 36/172 settings, i'm trying to guess what you went for but my Files tab still just has 'Media' and no files in it.
        • 34118
        • 45 Posts
        Hi BlueSpark

        I've attached my exported Policy. No idea if it is correct. But it is now at 37 settings. Yes, after the site being live for about 10 months I found another policy that needed clicked. Turned out I hadn't noticed directory_list, which is needed to show sub directories in a media folder. Client/Editor hadn't noticed as they were happy enough (relieved) that after multiple attempts they were finally able to upload (and save etc) images. And I missed the missing sub-folders that were supposed to show up.

        Phew. This could be it. A Content Editor that isn't totally useless.



        Note that the media sources settings can be a bit tricky too. Things like the slashes before and after the path in basePath and baseURL. I had trouble with those I think because I was re-using content from a clunky old .NET website. So watch out for those, they could be making your media empty.



        Imagine if Wordpress "improved" their software by adding such fine grained ACL control for all users (no exceptions). They'd be dead within a month. Riots on virtual streets.


        Surprised by the lack of response. Have BlueSpark and myself missed something? Surely every new MODxer can't have to learn 172 options to make a website CMS work? And that on top of learning quite tricky concepts (ACLs) and on top of a non-intuitive workflow, on top of a non-intuitive user interface (semi random seeming right clicks in the critical path).

        I should have put this in the general thread rather than 2.2 specific. Can the thread be moved?

        [ed. note: parthian last edited this post 11 years, 10 months ago.]
          • 28042 ☆ A M B ☆
          • 24,524 Posts
          Policies and policy templates are fairly obvious. The policy template has the permissions that such users might need, while the policy itself enables or disables those permissions. I have used trial-and-error with a policy template that has any permissions that I am not absolutely positive the user won't need, then test with the permission unchecked in the policy, then remove the ones I'm sure they don't need from the policy template. Once I get a set of policy template/policy that I'm happy with, I export them to xml and save them so I can import them if I want to use them again.

          The tricky part is to make sure that each group has the correct policy settings for all necessary contexts, for manager users they need mgr and web context access both. And each group access setting needs to be checked, since by default they usually won't have the policy you want.

          As far as roles go, I just give everybody superuser roles because I have never been able to make any sense of what roles do.
            Studying MODX in the desert - http://sottwell.com
            Tips and Tricks from the MODX Forums and Slack Channels - http://modxcookbook.com
            Join the Slack Community - http://modx.org
            • 34118
            • 45 Posts
            Hi Susan,

            How do we get the MODx team to change the Content Editor default policy? This to remove the "trial and error" bit. There really should be no need. Agree that Roles are too hard (higher is the new lower etc). Which is why using the Administrator Group is a bad idea - see my step 1) above.

            A nice easy fix too as the Team just need to change 24 or so ticks to 37 or so. Although I imagine that without careful setting of Media Sources a Newbie Developer could be exposing too much of the Assets/Core etc. to their Editors???

            Of course nothing stopping the creation of an ActuallyUsefulContentEditor policy in addition to the current cautious ContentEditor. Best of Both.

            MODx deserves to not push people away.
              • 28042 ☆ A M B ☆
              • 24,524 Posts
              You may find these useful.
                Studying MODX in the desert - http://sottwell.com
                Tips and Tricks from the MODX Forums and Slack Channels - http://modxcookbook.com
                Join the Slack Community - http://modx.org
                • 34118
                • 45 Posts
                Thanks Susan, will take a look tomorrow. Maybe these could be installed by default.
                  • 3749
                  • 24,544 Posts
                  Some recommendations here in my talk at MODXpo: http://vimeo.com/54360208 (fair warning, it's 50 minutes long), especially with respect to roles.

                  I've proposed a new approach to security permissions for MODX 3. It's around here somewhere.

                    Did I help you? Buy me a beer
                    Get my Book: MODX:The Official Guide
                    MODX info for everyone: http://bobsguides.com/modx.html
                    My MODX Extras
                    Bob's Guides is now hosted at A2 MODX Hosting
                    • 34118
                    • 45 Posts

                    Thanks Bob, Got most of my information from your guide. 45 minutes of careful work did it. But oddly, I'm sure I created users 3 or 4 years ago in a matter of minutes. Maybe Evo and before Roles.

                    Summary

                    1) Dump Roles. If a Ninja like Susan doesn't/can't use them then they aren't top priority.
                    Do that by making an Editor Group alongside Anonymous and Administrator. Should be a setup thing, possibly no code changes.

                    2) Create an ActuallyUsefulContentEditor. With something like the 37 permissions I've ended up using.
                    Again no code.

                    3) Optional with a bit of coding. Remove the need to Right Click in those few places where it is critical. Remove Knowledge from being in the Head to being present in the Interface.


                    I think the above could take minutes to implement, particuarly 1) and 2) and yet save hours and sometimes days of blundering about.


                    Many MODx reviews I've seen have Cons as slow interface and the ACL. It's hurting not helping.


                    By silly WW2 analogy. Wordpress is Blitzkreig: you're at the coast of France without trouble. MODx ACL is Omaha Beach on Overlord: a massacre. Give us a chance to get off the landing craft.




                    [ed. note: parthian last edited this post 11 years, 10 months ago.]
                      • 3647
                      • 177 Posts
                      Hi Stuart

                      Thanks for the policy, that has helped me a lot!

                      It also helps to hear that others have had problems, I have found it curious moving from Evo to Revo how little discussion of this field of 'gotchas' there has been.