We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 34118
    • 45 Posts
    Hello,

    Trying very hard to understand ACLs. I sort of get it sometimes. But I notice that all the RTFMs and Bob's Guides and others rarely, if ever, mention the active permissions required for a certain approach to work.

    E.g. I want my Advanced Content Editors (ACE) Users to be able to view, create, edit and save a Publication Type TV. A checkbox list of types of books associated with several templates. The approach perhaps doesn't make sense (I think there is probably a better way of doing this) but I'm really just trying to allow an ACE to see the Element Tree and see nothing in it but the one Category of TV (there are 3 TV categories just now). MODx 2.4.2.

    Tried approaches like - https://rtfm.modx.com/revolution/2.x/administering-your-site/security/security-tutorials/restricting-an-element-from-users and
    http://bobsguides.com/controlling-access-to-elements-in-the-manager.html

    But at first I didn't see the Element Tree. So I had to add to my ACE Context (Administrators Template) Policy Permissions things like element_tree, tree_show_element_id and 1 or 2 others. Then I could see the Element Tree but not Publication Type Category.

    So after a rummage around (assuming I was getting ACL stuff wrong) I noticed the view_tv permission (and edit_tv etc). So I turned these on. Now I could see my 3 TV Categories (doing all the Element Category Access stuff with Element Access Policy).

    But I only want to see the one Publication Type TV Category. So it looks like my ACE Context has view_tv thus they are all showing.

    Two Questions.

    Do all the RTFMs etc assume a very specific handbuilt Access Policy built from Administrator Template with just the right settings (like element_tree). Should all these RTFMs/BobsGuides etc then come with a XML of an appropriate Access Policy otherwise they are arguably never going to work without additional knowledge?

    Any hints to just show 1 specific Category of TV instead of the whole lot? I'm thinking I need to view_tv at Context. Then use roles or something to turn them all off for lower orders of life and then the ACE will see the one Element Category specified. Sneaky feeling TVs are a special case.

    Thanks

    Stuart

    This question has been answered by sottwell. See the first response.

      • 28042 ☆ A M B ☆
      • 24,524 Posts
      To clarify, you want to view TVs according to their Category?
        Studying MODX in the desert - http://sottwell.com
        Tips and Tricks from the MODX Forums and Slack Channels - http://modxcookbook.com
        Join the Slack Community - http://modx.org
        • 28042 ☆ A M B ☆
        • 24,524 Posts
        As far as I know, you would need to assign the rest of the TVs a Resource Group, then give your other user groups access to that Resource Group.

        And ACLs are very difficult to get a grip on. The general principle is easy enough, but exactly what permissions are required for any given scenario is, at least in my experience, largely a matter of trial-and-error. But there's no means of controlling access by category.

        You might be able to craft a plugin that would only show TVs in a given category to users that are members of a given group, but I'm not sure exactly how that would go. [ed. note: sottwell last edited this post 10 years, 10 months ago.]
          Studying MODX in the desert - http://sottwell.com
          Tips and Tricks from the MODX Forums and Slack Channels - http://modxcookbook.com
          Join the Slack Community - http://modx.org
          • 34118
          • 45 Posts
          Thanks Susan,

          Yes I wanted to show the TV in a single category and hide the others (each in their own category).

          This is mainly a training exercise roughly related to something I may need to do on a project. Thought it would be standard ACL fare but as I hinted it looks like I'm trying something really Ninja.

          Unless anyone else chips in over night I'll make a tactical retreat on this task and try some other ACL training stuff then worry about my extendable Publication Type issue. (It's like a 'let Editors add more Tags or Categories on a blog' - without the blog).

          But for MODx RTFM HQ I think a bit more on combinations of effective Permission scenarios would be handy for the docs.

          Cheers
          Stuart
            • 3749
            • 24,544 Posts
            When people talk about TV permissions, it's not always clear if they mean access to the TVs in the Elements tree, or on the Create/Edit Resource panel (or both).

            I'm assuming you mean in the Elements tree, but I must be missing something. Wouldn't Element Category Access ACL entries do exactly what you want?

              Did I help you? Buy me a beer
              Get my Book: MODX:The Official Guide
              MODX info for everyone: http://bobsguides.com/modx.html
              My MODX Extras
              Bob's Guides is now hosted at A2 MODX Hosting
              • 28042 ☆ A M B ☆
              • 24,524 Posts
              Ah. I was assuming in the Resource editing TVs tab.
                Studying MODX in the desert - http://sottwell.com
                Tips and Tricks from the MODX Forums and Slack Channels - http://modxcookbook.com
                Join the Slack Community - http://modx.org
                • 34118
                • 45 Posts
                Quote from: BobRay at Dec 02, 2015, 02:17 PM

                I'm assuming you mean in the Elements tree, but I must be missing something. Wouldn't Element Category Access ACL entries do exactly what you want?
                Yes. I mean Elements Tree. Sorry Susan, perhaps I wasn't very clear (struggle a bit with the lingo).

                Tried all sorts of combinations of your guides and rtfm Bob. Followed this one:
                http://bobsguides.com/controlling-access-to-elements-in-the-manager.html
                very closely. Which expands on the RTFM equivalents by having the EditorElement for finer control. A handy insight.

                My theoretical question could be summed up by your overview bulletpoint.
                Edit the duplicate Policy to set the appropriate Permissions
                I wonder if your 'appropriate permissions' are very different from mine. As stated, initially I didn't know about element_tree. Which is kind of basic, but nothing worked until I turned it on. I wonder if the docs/guides could be enhanced by describing "your duplicate content editor using admin template will probably need ... element_tree... etc."
                And then for fine tuning of Elements search for _chunk, _tv, _snippet etc in your Content Editor Policy, and turn on as applicable.
                You know what I mean.
                I think it would help remind newbies that specific permissions are necessary. I just assumed if I followed the docs/guides the element stuff would magically appear. Not so.

                Do you think that would help improve the docs?


                I also found this interesting (by that I mean I don't get it).
                Note that some Permissions are dependent on Permissions in the Policy granted to users in any Context Access ACL entry. If the user does not have the create_snippet Permission there, granting the create Permission here will not let the user create snippets. In order to create snippets, the user must have both Permissions.

                When I do the Add Category bit you get access to a limited subset of Access Policies. Presumably a 'context sensitive' menu, meaning that Adminstrator type policies can never appear. Which leads me to ponder where would create_snippet be in this example? Noting that there is a new_snippet which probably means the guide is referencing an older MODx but I'm thinking principles here. So the "the user must have both Permissions" bit leaves me puzzled. Category Element Access Policy could never have create_snippet or new_snippet (or new_tv for that matter). Simply because the available Access Policies never give access to the full range of Policies. I hope that makes sense.

                Finally, other parts of permissions/ACLs suggest an OR relationship. If a Context policy has new_tv, a later policy can't take it away. But the create_snippet part of your guide sort of suggests an AND relationship. I think this is interesting, in that maybe some subtle point about the whole ACL approach is buried in this.

                Theoretical musings - trying to help improve the guides/docs rather than solve a specific problem.

                Getting late here (UK). I'll not be able to reply tonight. Something to ponder. [ed. note: parthian last edited this post 10 years, 10 months ago.]
                • discuss.answer
                  • 28042 ☆ A M B ☆
                  • 24,524 Posts
                  Ah. In that case, a plugin would definitely work. Somewhat similar to the one for limiting the users a Manager user can see to manage. http://modxcookbook.com/customize-manager/form-customization/restrict-users-list.html
                    Studying MODX in the desert - http://sottwell.com
                    Tips and Tricks from the MODX Forums and Slack Channels - http://modxcookbook.com
                    Join the Slack Community - http://modx.org
                    • 34118
                    • 45 Posts
                    Quote from: sottwell at Dec 02, 2015, 03:34 PM
                    Ah. In that case, a plugin would definitely work. Somewhat similar to the one for limiting the users a Manager user can see to manage. http://modxcookbook.com/customize-manager/form-customization/restrict-users-list.html

                    Key bit being this I think. if ($action == 'security/user/getList') {
                    Change to something appropriate.

                    I'll mark your post as answer but hopefully my suggestions for Doc/Guide writers to mention handy Permissions you would need will have been noted.

                    Cheers
                      • 3749
                      • 24,544 Posts
                      Thanks for the suggestions. smiley I've updated the page to use new_snippet and mention the element_tree permission.

                      Yes, there is an OR relationship for specific permissions in the sense that if an ACL entry gives the user that permission, another ACL entry can't take it away.

                      There are actions, though, that require at least two permissions, one from the Context Access ACL entry and one from a Resource Group or Element Category ACL entry. In those cases, the user must have one AND the other to perform the action.

                      I explain the details of how this works in this 50-minute video: https://vimeo.com/54360208.
                        Did I help you? Buy me a beer
                        Get my Book: MODX:The Official Guide
                        MODX info for everyone: http://bobsguides.com/modx.html
                        My MODX Extras
                        Bob's Guides is now hosted at A2 MODX Hosting