We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 38850
    • 110 Posts
    I have many resources, in fact probably most resources, which are already restricted from anonymous access. So they must be viewed by logged in members.
    But beyond just being logged in, there needs to be some restricted content on certain pages. For example lets say I'm showing the user a list of items. All users can see the list and interact, but only an editor or "admin" of sorts should also have a button to delete an item, or add an item, directly in the front end.

    Another scenario would be like a dashboard where there are a handful of "modules" showing various data summaries, but only certain users like admin or maybe a manager, would also get just an extra module or two that other users can't see. Or lets say the users themselves can choose which modules they want to see from a list, then obviously they should not be able to choose restricted modules or even see them in the list to choose from.

    My question is, from the perspective of the resource, or a snippet in the resource, what is the best way to manage permissions?
    I know I can check the current user role for example, but there might also be things like filters which can test roles or user groups? Do I actually have to test down to the specific permission itself? Can I add custom permissions which I can then add to ACLs?
    Should I be testing for a group, or for the role, or for a "minimum role" authority, or for a specific permission?

    Or am I getting this backwards, can I set a minimum role authority at the snippet level where the snippet itself is protected by MODX without me having to test anything at all? Can I set a permission for chunks like this too if possible?

    What about the database? If there is a table of data but some rows might be restricted, I would need a column to somehow list what permission (or role?) is needed for that row to be viewable on the front end. This way in any database call I can filter out rows which I don't want a user to see.

    Anybody have ideas on how best to handle mix-n-match content on a single resource as far as permissions or roles?
      • 28042 ☆ A M B ☆
      • 24,524 Posts
      There are several ways you can do this. One way is to use the Personalize snippet. Or you could have custom snippets to check the user's permissions for more complex uses. These work with groups, and display one chunk if the user belongs to a specified group or groups, and another chunk if he does not.

      http://bobsguides.com/personalize-tutorial.html
        Studying MODX in the desert - http://sottwell.com
        Tips and Tricks from the MODX Forums and Slack Channels - http://modxcookbook.com
        Join the Slack Community - http://modx.org
        • 4172
        • 5,888 Posts
        This are many questions at once.

        Picking one here:


        What about the database? If there is a table of data but some rows might be restricted, I would need a column to somehow list what permission (or role?) is needed for that row to be viewable on the front end. This way in any database call I can filter out rows which I don't want a user to see.

        It is absolutely up to you and depends how granular you need to have permissions on different rows.
        The MODX - permission - system is very flexible to use there.

        IMO the simplest solution is to create custom-permissions and give your table two columns 'view_permission' and 'edit_permission' for example
        Then its easy to check the current users specific view- or edit-permission for that table and filter the rows.



          -------------------------------

          you can buy me a beer, if you like MIGX

          http://webcmsolutions.de/migx.html

          Thanks!
          • 38850
          • 110 Posts
          Quote from: sottwell at Dec 03, 2014, 02:35 PM
          There are several ways you can do this. One way is to use the Personalize snippet. Or you could have custom snippets to check the user's permissions for more complex uses. These work with groups, and display one chunk if the user belongs to a specified group or groups, and another chunk if he does not.

          http://bobsguides.com/personalize-tutorial.html

          Thanks. In my case I'm not sure this is the right fit. I like that they added group checking but MODX is more refined than that. For example it is likely that ALL users will be in a single group called "employees" for example, but some would be separate by roles. The admin, super admin, manager, member, etc.
          So I'd rather check for roles or authority than purely group.

          Second, I will likely need more freedom in handling the condition than just showing one chunk or a different chunk. More likely I would be calling another snippet entirely, or even changing templates. It might look like this:

          * User selects page from menu.
          * If user is logged in, the template is loaded.
          * The template has snippets to call various page elements, let's say a list of items.
          * The list is generated by another snippet, but if user doesn't have X permission or authority or role or group(?), certain items are removed from list.
          * Potentially, as the snippet displays the list, if role is yet higher still, say super admin instead of manager, an additional button or link to delete the item is displayed as well.

          * If the action to delete or edit an item is given, permissions would have to be checked again I would think.

          This is not as simple as just showing one chunk or a different chunk. There is a lot of logic going on. I'd like all this logic, and what to show and not show, be part of the same script. In other words, I don't want to call separate, nearly identical snippets or chunks for each user type (i.e. this chunk for members, that chunk for managers, and this other chunk for admins, etc).

          Do you think it's better to test for group, role, authority, or individual permissions?
            • 38850
            • 110 Posts
            Quote from: Bruno17 at Dec 04, 2014, 01:28 AM


            It is absolutely up to you and depends how granular you need to have permissions on different rows.
            The MODX - permission - system is very flexible to use there.

            IMO the simplest solution is to create custom-permissions and give your table two columns 'view_permission' and 'edit_permission' for example
            Then its easy to check the current users specific view- or edit-permission for that table and filter the rows.

            You said the key word, "create custom permissions". I've been looking around MODX and I don't see any place where I can add my own permissions.

            Is it necessary to do this? I'm building a custom manager in the front end context so all the groups and permissions are very specific to just my app. For example you could have the "can see financial reports" permission, or specific types of CRUD permissions on editing contractors, data manipulation, overrides, workflows, etc. Another "permission" might be "can approve contractor submissions".

            Should I invent all my own permissions like this, or is it overkill?

            I'm thinking about this kind of like how our ecommerce website works. I am the admin, so I can add and remove users who can access the back end. For each user I create, I simply check a box next to every permission they have, such as viewing reports, importing data, managing templates, seeing dashboard, and 50 other permissions. I set them on a user-by-user basis.
            Can I do something similar in MODX, by creating my own list of custom permissions and assigning them to my users? Or is there a better way?

            In most security systems, you only have users, and groups, and permissions. A set of permissions make up a group, then users are assigned a group. MODX is much more detailed than this, with ACLs and context and resource groups and authority levels and roles within groups and then all the individual permissions at the base, it's hard to grasp. I'm not sure how to piggyback the MODX system to do something like our ecommerce setup has.

            Thanks!
              • 4172
              • 5,888 Posts
              I've been looking around MODX and I don't see any place where I can add my own permissions.

              you can duplicate a 'Policy Template'
              Add custom-permissions, remove unneeded permissions.

              Then you can create different 'Access Policies' based on your 'Policy Template' (check all Permissions, which you want to give users with a specific Role in a Usergroup)

              Then you can create Usergroups and different roles in them.

              Now when you update a Usergroup, in the Tab 'Permissions', you can give each Role in your group another 'Access Policy' for a selected context.

              Read more about it here:
              http://bobsguides.com/revolution-permissions.html
                -------------------------------

                you can buy me a beer, if you like MIGX

                http://webcmsolutions.de/migx.html

                Thanks!
                • 38850
                • 110 Posts
                Quote from: Bruno17 at Dec 04, 2014, 10:58 AM

                you can duplicate a 'Policy Template'
                Add custom-permissions, remove unneeded permissions.

                I've created a policy template and it seems I can invent arbitrary permissions by just typing a name and description. How do these work then? There is no code or logic about these permissions, it is just a name. So how do I use them?

                Do I test specifically for a permission such as "does current user have permission Y"? This disregards context or groups or roles. This means I would be hard-coding the names of permissions.

                Or do I only test for a role which has the permission such as "does user have role X and member of group Y"? This would mean I'm hard-coding valid roles and groups but not permissions.

                Or do I test for a user group and then look for minimum authority level "is user in group X and at least authority Y"? This means I hard-code only the group and authority level, without caring about roles or permissions.

                Keep in mind none of my users will have mgr context so I'm assuming all of MODX built-in templates and permissions are not really relevant or useful for front-end security. Or are they?

                So confusing!