We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 50145
    • 5 Posts
    We have SuperAdmin and SubAdmin

    SubAdmin can manage Users (create, edit and delete) and thier permissions.
    He can do all that actions with all Users except SuperAdmin

    How to make SuperAdmin is non-removable and non-editable for SubAdmin?

    Is it possible to make that in REVO?

    (it would be better if SuperAdmin would be invisible for SubAdmin in table of Users)

    This question has been answered by sottwell. See the first response.

    [ed. note: best.peterburg last edited this post 11 years, 6 months ago.]
      • 5430
      • 247 Posts
      If I'm understanding your correctly, the answer is probably no. If you have a user group that is granted permission to create, edit, and delete users, ALL users will be editable by members of that group. To my knowledge there is no way to make a specific user untouchable.
        • 3749
        • 24,544 Posts
        It's theoretically possible to write code that checks the current user and removes names of protected users from the drop-down list of names in User Management, but it's extremely difficult.
          Did I help you? Buy me a beer
          Get my Book: MODX:The Official Guide
          MODX info for everyone: http://bobsguides.com/modx.html
          My MODX Extras
          Bob's Guides is now hosted at A2 MODX Hosting
          • 50145
          • 5 Posts
          Quote from: claytonk at Mar 25, 2015, 07:28 PM
          If I'm understanding your correctly, the answer is probably no. If you have a user group that is granted permission to create, edit, and delete users, ALL users will be editable by members of that group. To my knowledge there is no way to make a specific user untouchable.

          it`s strange, because, IMHO, the need for this functionality is obvious for cart-shops with registration and with several content managers (for example)

          i found this issue in github https://github.com/modxcms/revolution/issues/11208

          the fist question about that problem was at 2010 year, but it seems like nobody wants to solve it

            • 50145
            • 5 Posts
            Quote from: BobRay at Mar 25, 2015, 09:28 PM
            It's theoretically possible to write code that checks the current user and removes names of protected users from the drop-down list of names in User Management, but it's extremely difficult.

            may be it will not be so extremely difficult to remove from list of user only one user with ID=1 (Superadministrator-Developer)?

            For all users, even for Superadministrator

            and If i need to edit Superadministrator later, i can just remove that code, then edit Superadmin, and paste code back

            not pretty, but effective

            can you hint where should I look part of code, that i need
            and may be your can give me some practice ideas, because my php-level is extremely low smiley))))

            UPD. Ok, here we are

            manager/controllers/default/security/user/index.class.php
            assets/modext/widgets/security/modx.grid.user.js
            assets/modext/sections/security/user/list.js

            but still don`t understand what i can do with that
            I was expecting to see some array whith users and then to use something like unset ($array[$value_to_delete])
            need some help and ideas

            <?php
            /**
             * Loads the user list
             *
             * @package modx
             * @subpackage manager.controllers
             */
            class SecurityUserManagerController extends modManagerController {
                /**
                 * Check for any permissions or requirements to load page
                 * @return bool
                 */
                public function checkPermissions() {
                    return $this->modx->hasPermission('edit_user');
                }
            
                /**
                 * Register custom CSS/JS for the page
                 * @return void
                 */
                public function loadCustomCssJs() {
                    $mgrUrl = $this->modx->getOption('manager_url',null,MODX_MANAGER_URL);
                    $this->addJavascript($mgrUrl.'assets/modext/widgets/security/modx.grid.user.js');
                    $this->addJavascript($mgrUrl.'assets/modext/sections/security/user/list.js');
                    $this->addHtml("<script>
                        Ext.onReady(function() {
                            MODx.add('modx-page-users');
                        });</script>");
                }
            
                /**
                 * Custom logic code here for setting placeholders, etc
                 * @param array $scriptProperties
                 * @return mixed
            		*/
                public function process(array $scriptProperties = array()) {}
            
            
            
                /**
                 * Return the pagetitle
                 *
                 * @return string
            */
                public function getPageTitle() {
                    return $this->modx->lexicon('users');
                }
            
            
            
            
                /**
                 * Return the location of the template file
                 * @return string
              */
                public function getTemplateFile() {
                    return '';
                }
            
            
                /**
                 * Specify the language topics to load
            
                 * @return array
            	 */
                 
                public function getLanguageTopics() {
                    return array('user');
                }
            
            
                /**
                 * Get the Help URL
                 * @return string
            */
                public function getHelpUrl() {
                    return 'Users';
                }
            
            }
            [ed. note: best.peterburg last edited this post 11 years, 6 months ago.]
            • discuss.answer
              • 28042 ☆ A M B ☆
              • 24,524 Posts
              You don't want to do anything with that. Never meddle with the core code files.

              You will need to create a plugin, perhaps using OnUserFormPrerender, to stop the loading of the editing form for user #1.

              You'll need to also use whatever events are invoked before deleting/removing users to make sure that user #1 isn't getting deleted. It's already not possible to delete the last user left in the Administrator group, so if there is only one user in that group he can't be deleted.
                Studying MODX in the desert - http://sottwell.com
                Tips and Tricks from the MODX Forums and Slack Channels - http://modxcookbook.com
                Join the Slack Community - http://modx.org
                • 3749
                • 24,544 Posts
                I agree with Susan. That said, I think the file you'd want to be looking at is: core\model\modx\processors\security\user\getlist.class.php. It produces the data for the user grid.

                If certain users aren't listed (because they're excluded by the 'where' clause of the query), they can't be edited or deleted.
                  Did I help you? Buy me a beer
                  Get my Book: MODX:The Official Guide
                  MODX info for everyone: http://bobsguides.com/modx.html
                  My MODX Extras
                  Bob's Guides is now hosted at A2 MODX Hosting
                  • 50145
                  • 5 Posts
                  Quote from: sottwell at Mar 26, 2015, 01:29 PM
                  Never meddle with the core code files.
                  Quote from: BobRay at Mar 26, 2015, 10:33 PM
                  I agree with Susan.

                  Yea, i`m understand that any meddling in core code is unacceptable and immoral for the educated man!

                  Вut, it's forgivable for such ignorant barbarian, as me...

                  And if, as i said, my low experience in coding does not allow me to make plugins, I was forced to do 2 actions

                  1) core\model\modx\processors\security\user\getlist.class.php

                  here i`m added

                  $c->where(array('modUser.username:NOT LIKE' => 'Superadmin'));


                  after

                  $c->leftJoin('modUserProfile','Profile');


                  to remove user with username Superadmin from users grid.

                  2) manager/assets/modext/widgets/security/modx.panel.user.js

                  here i`m comment part of code which displays checkbox SUDO in user settings.
                  And now, i`m suppose, Subadmin can`t make any other user a SUDO-user.

                  So, i think, my problem is solved until the next update of a system smiley)))))))))

                  and thank you both for the tips

                  [ed. note: best.peterburg last edited this post 11 years, 6 months ago.]