We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 24374
    • 322 Posts
    On one of my websites, I managed to set up some permissions to do what I wanted, but it was very complicated, and I'm wondering (hoping) there is a simpler way to do it. All I want to do is this:

    I want an "admin" group (no others). When I check that off for a resource, I want only an Administrator to be able to both see the resource in the resource tree and edit it. I want the resource to be visible on the public website, though. So, the web page needs to be viewable by everyone on the web (whether logged into MODX or not) but only visible and editable by and Administrator in the MODX manager.
      • 3749
      • 24,544 Posts
      It sounds simple enough. The second part will happen naturally if you never create a Resource Group Access ACL entry with a context of 'web'.

      The first part just means putting all the resources in a resource group and connecting that resource group to the Administrator user group with a Resource Group Access ACL entry with a context of 'mgr'. that will hide all the resources from anyone outside the Administrator group, but only in the Manager.

      Beyond that, the default ACL entries that you get on install should be all you need. http://bobsguides.com/default-acl-entries.html
        Did I help you? Buy me a beer
        Get my Book: MODX:The Official Guide
        MODX info for everyone: http://bobsguides.com/modx.html
        My MODX Extras
        Bob's Guides is now hosted at A2 MODX Hosting
        • 24374
        • 322 Posts
        Quote from: BobRay at Dec 17, 2014, 09:55 PM
        It sounds simple enough. The second part will happen naturally if you never create a Resource Group Access ACL entry with a context of 'web'.
        [/url]

        Sorry, but this isn't working. I get "page not found" on the front end for any resource with the "admin" user group assigned to it. I'm running MODX 2.3.2. I set up the user group "admin", then edited the Administrator user group and installed, under the Permissions tab, just one entry:
        Resource Group: Admin, Minimum Role:9999, Access Policy:Resource, Context:mgr. [ed. note: rainbowtiger last edited this post 11 years, 9 months ago.]
          • 3749
          • 24,544 Posts
          Hmm. I don't see how that could happen unless you have 'web' as the context of a Resource Group Access ACL entry or the resource is not published.

          Have you flushed permissions and sessions, and are you checking from another browser where you're not logged in to the Manager?

            Did I help you? Buy me a beer
            Get my Book: MODX:The Official Guide
            MODX info for everyone: http://bobsguides.com/modx.html
            My MODX Extras
            Bob's Guides is now hosted at A2 MODX Hosting
            • 24865
            • 289 Posts
            What BobRay is suggesting is always step one. When I configure my deeply nested ACLs (we have about 10-15 of them with 10-20 roles and 10 resource groups, not to mention element permissions), you'd always have to work like a surgeon. Get your MODX manager SUDO login going in like Chrome, and do your testing in an Incognito tab (again, from Chrome) or rather Firefox or Opera.
            When you do updates to the permission sets, always and ALWAYS either flush permissions or logout. I'd make it best practice to simply delete your cookies with the Webdeveloper Toolbar, both for Firefox and Chrome.

            Alright, let's get into the thick of it.

            If you've got a set of resources protected by a Resource Group, MODX needs to 'see' those resources before either granting or revoking your access to those resources. So, if you are an anonymous user, always make sure you got the 'load' permission set up on that Resource Group. The same goes for the fact when you're logged in and the logged in user belongs to a different user group. Match the role and permissions to that of the ACL and link it to the resource group.

            Simply put, this'd be the following:

            Anonymous - Member 9999 - Resource Group Name - load
            Revoked User Name in User Group Name - User Revoked 5000 - Resource Group Name - load
            Granted User Name in User Group Name - User Granted 4000 - Resource Group Name - load, list & view

            I hope this helps! smiley
              @MarkGHErnst

              Developer at Adwise Internetmarketing, the Netherlands.