This code in the modAccessibleObject class file is definitely worth a look. This is in the checkPolicy() method (called by hasPermission() ):
if ($criteria && $this->xpdo instanceof modX && $this->xpdo->getSessionState() == modX::SESSION_STATE_INITIALIZED) {
/* ... */
}
return true;
If that "if" condition isn't met, the user has permission for everything.
It's worth noting that if PHP is reporting the wrong thing for cli mode tests, it would explain your problem, because in CLI mode, the session_state is set to UNAVAILABLE and there are no permission restrictions.
Try this code in a MODX snippet in the front end:
echo 'SAPI NAME: ' . php_sapi_name();
echo '<br />XPDO_CLI_MODE ' . XPDO_CLI_MODE;
[ed. note: BobRay last edited this post 11 years, 8 months ago.]