Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
15 changes: 15 additions & 0 deletions en/building-sites/client-proofing/security/policies/acls.md
Original file line number Diff line number Diff line change
Expand Up @@ -44,6 +44,21 @@ This means that an ACL applied to a Resource Group will:
- ... give the Resource Permissions (save, load, delete, etc) in the Policy specified
- ... to all the Resources in the Resource Group

## Manager publishing and multiple groups

Manager publish UI (Published checkbox, publish/unpublish dates, tree Publish/Unpublish actions, and the publish/unpublish processors) gates on the context permission `publish_document` (and `unpublish_document`) through `modX::hasPermission()`. In the manager, the current context is **`mgr`**.

That has a few practical consequences:

1. A policy that grants `publish_document` only on a frontend context (`web` or another site context) does **not** unlock manager publish controls. You need a Context Access ACL on **`mgr`**.
2. Resource ACL permissions `publish` / `unpublish` (on the [Resource Policy](building-sites/client-proofing/security/policies/permissions/resource-policy)) are a different ACL surface. The current manager publish UI and save path do not use them.
3. Multiple user groups still **OR** together for a given context. `checkPolicy` returns true when **any** matching Context Access ACL for that context grants the permission. You do not need every group to include publish.
4. A common trap: one shared group gives **Content Editor** (no publish) on `mgr`, and a second group puts a custom policy with publish only on another context. The user is in both groups, but still cannot publish in the manager until `publish_document` exists on an **`mgr`** Context Access ACL.

To fix that setup: add Context Access for **`mgr`** on at least one of the user's groups, with a policy that includes `publish_document` (and `unpublish_document` if needed). Leave Content Editor on the other group if you want. Flush sessions/permissions and retest.

See also [Administrator Policy](building-sites/client-proofing/security/policies/permissions/administrator-policy) (`publish_document`) and [Giving a User Manager Access](building-sites/client-proofing/security/security-tutorials/giving-a-user-manager-access). Background: [modxcms/revolution#14925](https://github.com/modxcms/revolution/issues/14925).

## See Also

1. [Users](building-sites/client-proofing/security/users)
Expand Down
4 changes: 3 additions & 1 deletion en/building-sites/client-proofing/security/policies/index.md
Original file line number Diff line number Diff line change
Expand Up @@ -9,7 +9,7 @@ _old_uri: "2.x/administering-your-site/security/policies"
An Access Policy is a set of [Permissions](building-sites/client-proofing/security/policies/permissions "Permissions") containing one or many Permissions, as defined in the manager. By default MODX comes with pre-configured Access Policies:

- **Administrator**: Context administration policy with all default permissions.
- **Context Editor**: Context administration policy with limited, content-editing related Permissions, but no publishing Permissions.
- **Content Editor**: Context administration policy with limited, content-editing related Permissions, but no publishing Permissions (`publish_document` / `unpublish_document`).
- **Context**: A standard Context policy that you can apply when creating Context ACLs for basic read/write and view\_unpublished access within a Context.
- **Element**: MODX Element policy with all attributes.
- **Load Only**: A minimal policy with permission to load an object.
Expand Down Expand Up @@ -39,6 +39,8 @@ Access Policies can be assigned as [Access Control Lists](building-sites/client-

MODX comes with a default ["Administrator" Policy](building-sites/client-proofing/security/policies/permissions/administrator-policy "Permissions - Administrator Policy") that contains all the [Permissions](building-sites/client-proofing/security/policies/permissions "Permissions") one would use in a Context ACL. It's best to duplicate this policy when creating a custom access policy for restricting manager users.

Manager publish controls require `publish_document` on a Context Access ACL for the **`mgr`** context. Policies attached only to another context do not unlock those controls. Details: [ACLs: Manager publishing and multiple groups](building-sites/client-proofing/security/policies/acls#manager-publishing-and-multiple-groups).

### Resource Group Access

They can also be Resource ACLs, that limit access to Resources based on Roles and Resource Groups. MODX comes packaged with a default ["Resource" Policy](building-sites/client-proofing/security/policies/permissions/resource-policy "Permissions - Resource Policy") that contains all the basic Permissions one would use in a Resource Group ACL.
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -80,7 +80,7 @@ This policy is packaged into MODX and is given to users on the 'mgr' context who
| packages | To use any Transport Packages in the [Package Management](extending-modx/transport-packages "Package Management") system. |
| property\_sets | To view and edit [Properties and Property Sets](building-sites/properties-and-property-sets "Properties and Property Sets"). |
| providers | To view and edit [Providers](building-sites/extras/providers "Providers") across the site. |
| publish\_document | To publish or unpublish any Resource. |
| publish\_document | To publish or unpublish any Resource. In the manager UI this is checked on the **`mgr`** context via `hasPermission('publish_document')`. A grant only on another context does not unlock manager publish controls. See [ACLs](building-sites/client-proofing/security/policies/acls#manager-publishing-and-multiple-groups). |
| purge\_deleted | To empty the Recycle Bin. |
| remove | Basic permission to remove any object. |
| remove\_locks | To remove all existing Locks throughout the site. |
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -26,6 +26,8 @@ This policy is packaged into MODX and is given to users on any context who want
| unpublish |
| view |

Do not confuse Resource permissions `publish` / `unpublish` with Administrator/context permission `publish_document`. The manager publish checkbox, dates, tree actions, and publish processors gate on `publish_document` for the **`mgr`** context. Resource `publish` / `unpublish` alone will not open those controls. See [ACLs: Manager publishing and multiple groups](building-sites/client-proofing/security/policies/acls#manager-publishing-and-multiple-groups).

## See Also

1. [Permissions - Administrator Policy](building-sites/client-proofing/security/policies/permissions/administrator-policy)
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -20,6 +20,16 @@ _old_uri: "2.x/administering-your-site/security/security-tutorials/giving-a-user
6. In Manage -> Users, create the new user, or edit existing, and via the Access Permissions tab, assign them to the Administrator group with a role of Editor.
7. Click on Security -> Flush Sessions and re-login.

## Publishing in the manager

If the user can edit resources but cannot publish (Published checkbox snaps back, no publish dates, no Publish in the tree menu):

- Stock **Content Editor** has no `publish_document` / `unpublish_document`.
- Those keys must appear on a Context Access ACL for **`mgr`**, not only on `web` or another frontend context.
- Resource Policy permissions `publish` / `unpublish` do not drive the current manager publish UI.

More detail: [ACLs: Manager publishing and multiple groups](building-sites/client-proofing/security/policies/acls#manager-publishing-and-multiple-groups).

## See Also

1. [Giving a User Manager Access](building-sites/client-proofing/security/security-tutorials/giving-a-user-manager-access)
Expand Down
4 changes: 3 additions & 1 deletion en/extending-modx/modx-class/reference/modx.haspermission.md
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,9 @@ _old_uri: "2.x/developing-in-modx/other-development-resources/class-reference/mo

## modX::hasPermission

Returns true if user has the specified policy permission.
Returns true if user has the specified policy permission in the **current** context (`$modx->context`). In the manager that context is usually `mgr`.

So `$modx->hasPermission('publish_document')` in manager code only sees Context Access policies attached to **`mgr`**. A policy that grants the same key on another context does not satisfy this check. See [ACLs: Manager publishing and multiple groups](building-sites/client-proofing/security/policies/acls#manager-publishing-and-multiple-groups).

## Syntax

Expand Down
15 changes: 15 additions & 0 deletions ru/building-sites/client-proofing/security/policies/acls.md
Original file line number Diff line number Diff line change
Expand Up @@ -43,6 +43,21 @@ ACL для ресурсов работают немного иначе и в о
- ... даст разрешения на ресурсы (save, load, delete и т. д.) из указанной политики
- ... для всех ресурсов в группе ресурсов

## Публикация в менеджере и несколько групп

Публикация в менеджере (чекбокс Published, даты publish/unpublish, пункты Publish/Unpublish в дереве, процессоры publish/unpublish) смотрит на контекстное разрешение `publish_document` (и `unpublish_document`) через `modX::hasPermission()`. В менеджере текущий контекст это **`mgr`**.

Следствия:

1. Политика с `publish_document` только на фронтовом контексте (`web` или другом) **не** включает кнопки публикации в менеджере. Нужен Context Access ACL на **`mgr`**.
2. Разрешения Resource ACL `publish` / `unpublish` ([ресурсная политика](building-sites/client-proofing/security/policies/permissions/resource-policy)) это другой слой. Текущий UI публикации в менеджере их не использует.
3. Несколько групп на **`mgr`** объединяются через OR: достаточно, чтобы **одна** подходящая ACL на `mgr` дала `publish_document`. Это не пересечение всех групп.
4. Типичная ловушка: одна группа даёт на `mgr` политику **Content Editor** (без публикации), а вторая кладёт политику с публикацией только на другой контекст. Пользователь в обеих группах всё равно без publish в менеджере, пока `publish_document` не появится на `mgr`.

Что сделать: добавьте Context Access на **`mgr`** хотя бы для одной группы пользователя с политикой, где есть `publish_document` (и при необходимости `unpublish_document`). Content Editor на другой группе можно оставить. Сбросьте сессии/права и проверьте снова.

Подробнее: [Политика администратора](building-sites/client-proofing/security/policies/permissions/administrator-policy) (`publish_document`), [доступ менеджера](building-sites/client-proofing/security/security-tutorials/giving-a-user-manager-access). Фон треда: [modxcms/revolution#14925](https://github.com/modxcms/revolution/issues/14925).

## Смотрите также

1. [Пользователи](building-sites/client-proofing/security/users)
Expand Down
4 changes: 3 additions & 1 deletion ru/building-sites/client-proofing/security/policies/index.md
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,7 @@ translation: "building-sites/client-proofing/security/policies"
Политика доступа - это набор [Разрешений](building-sites/client-proofing/security/policies/permissions "Разрешения") содержащий одно или несколько Разрешений, определённых в панели управления. По умолчанию в MODX определены следующие политики доступа:

- **Administrator**: Политика администрирования контекста со всеми разрешениями по умолчанию.
- **Content Editor**: Политика администрирования контекста с ограниченными разрешениями, относящимися к редактированию контента, но без разрешений на публикацию.
- **Content Editor**: Политика администрирования контекста с ограниченными разрешениями, относящимися к редактированию контента, но без разрешений на публикацию (`publish_document` / `unpublish_document`).
- **Context**: Стандартная политика контекста, которую можно применять при создании списков ACL для получения базового доступа в контексте (read/write и view\_unpublished).
- **Element**: Политика элемента MODX со всеми атрибутами.
- **Load Only**: Минимальная политика с разрешением на загрузку объекта.
Expand Down Expand Up @@ -39,6 +39,8 @@ translation: "building-sites/client-proofing/security/policies"

По умолчанию в MODX присутствует политика доступа ["Administrator"](building-sites/client-proofing/security/policies/permissions/administrator-policy "Политики - Политика Администратора") которая содержит все [Разрешения](building-sites/client-proofing/security/policies/permissions "Разрешения") которые можно использовать в контексте ACL. При создании пользовательской политики доступа, для пользователей с ограничениями, эту политику лучше всего продублировать.

Кнопки публикации в менеджере требуют `publish_document` в Context Access ACL на контексте **`mgr`**. Политика только на другом контексте эти кнопки не откроет. Подробнее: [ACL: публикация в менеджере](building-sites/client-proofing/security/policies/acls#публикация-в-менеджере-и-несколько-групп).

### Доступ к группе ресурсов

Доступ к ресурсам так же может быть разграничен с использованием ролей и групп ресурсов. По умолчанию MODX имеет [Ресурсную политику](building-sites/client-proofing/security/policies/permissions/resource-policy "Разрешения - Ресурсная политика"), содержащую все основные разрешения, которые можно использовать в ACL групп ресурсов.
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -79,7 +79,7 @@ translation: "building-sites/client-proofing/security/policies/permissions/admin
| packages | Использовать любые транспортные пакеты в системе [управления](extending-modx/transport-packages "Управление пакетами") пакетами. |
| property_sets | Для просмотра и редактирования [свойств и наборов свойств](building-sites/properties-and-property-sets "Свойства и наборы свойств") . |
| провайдеры | Для просмотра и редактирования [провайдеров](building-sites/extras/providers "Провайдеры") по всему сайту. |
| publish_document | Опубликовать или отменить публикацию любого ресурса. |
| publish_document | Опубликовать или отменить публикацию любого ресурса. В UI менеджера проверка идёт на контексте **`mgr`** через `hasPermission('publish_document')`. Выдача только на другом контексте кнопки публикации не откроет. См. [ACL](building-sites/client-proofing/security/policies/acls#публикация-в-менеджере-и-несколько-групп). |
| purge_deleted | Чтобы очистить корзину. |
| remove | Основное разрешение на удаление любого объекта. |
| remove_locks | Удалить все существующие блокировки по всему сайту. |
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -25,6 +25,8 @@ translation: "building-sites/client-proofing/security/policies/permissions/resou
| unpublish |
| view |

Не путайте разрешения Resource `publish` / `unpublish` с контекстным `publish_document` из политики администратора. Чекбокс публикации, даты, пункты в дереве и процессоры в менеджере смотрят на `publish_document` для контекста **`mgr`**. Одних `publish` / `unpublish` на Resource ACL недостаточно. См. [ACL: публикация в менеджере](building-sites/client-proofing/security/policies/acls#публикация-в-менеджере-и-несколько-групп).

## Смотрите также

1. [Разрешения - Политика администратора](building-sites/client-proofing/security/policies/permissions/administrator-policy)
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -19,6 +19,16 @@ translation: "building-sites/client-proofing/security/security-tutorials/giving-
6. В **Manage → Users** создайте пользователя или откройте существующего. На вкладке Access Permissions добавьте его в группу Administrator с ролью Editor.
7. Откройте **Security → Flush Sessions** и войдите снова.

## Публикация в менеджере

Если пользователь редактирует ресурсы, но не может публиковать (чекбокс Published откатывается, нет дат, нет Publish в меню дерева):

- В стоковой политике **Content Editor** нет `publish_document` / `unpublish_document`.
- Эти ключи должны быть в Context Access ACL на **`mgr`**, а не только на `web` или другом фронтовом контексте.
- Разрешения Resource Policy `publish` / `unpublish` текущий UI публикации в менеджере не открывают.

Подробнее: [ACL: публикация в менеджере](building-sites/client-proofing/security/policies/acls#публикация-в-менеджере-и-несколько-групп).

## Смотрите также

1. [Доступ пользователя к Менеджеру](building-sites/client-proofing/security/security-tutorials/giving-a-user-manager-access)
Expand Down
Loading
Loading