Hello. In my website a main editor can make new editor users. These editor users have less edit posibilities and are locked in their part of the website.
The main editor is just an manager user (not admin / sudo)
But if he creates a new user he can make this user a admin (access levels) or sudo? (top corner of first screen)
I looked at the 172 permisions but none block this?
Miguel, You point is clear that a lower editor should not be able to make a higher level type editor.
Is see what can happen then and so i start searching if there is an solution in the Modx Backend.
Or maybe the basic ability to create a user (new_user, edit_user) simply always comes with the option to make someone sudo/admin level.
Then i have just badluck. I have to create the users each time the clients wants an new one with my admin level and restrict the client to do it himself. (the client is the user that (not wanted) can create admins now...I dont think he wants to mess up his own site but you never know who finds his PC logged in....)
Giving a user the permissions to create users allows him the full user creation permission.
You would need to create a plugin using "OnBeforeUserFormSave" to check the active user's group, and if he belongs to your Editors group, check the values being submitted and correct anything you don't want them to be able to do. The provided $user object should have all of the form's fields.
Thanks Sussan for your fast respond. Its now clear to me user creation is an Admin only thing by default in the first place.
I simply give the trust to the website owner to try and mess his own site up....