ACLs
Last updated Sep 6th, 2026 | Page history | Improve this page | Report an issue
Support the team building MODX with a monthly donation.
The budget raised through OpenCollective is transparent, including payouts, and any contributor can apply to be paid for their work on MODX.
Backers
Budget
$194 per month—let's make that $500!
Learn moreWhat is an ACL (Access Control List)?¶
An ACL, or Access Control List, is a set of Permissions attached to an object. More information on ACLs can be found here in Wikipedia.
Usage¶
In MODX, ACLs can be applied to any modAccessibleObject. Primarily MODX Revolution 2.0 allows for ACLs on Resources and Contexts.
Context ACL¶
A Context ACL is referenced of 4 parts:
- A Context
- A User Group
- A Minimum Role
- An Access Policy
This means that one can assign a ACL to a Context that will apply to:
- All the Users in a User Group
- ...with at least the Minimum Role specified
- ...that will give the Users all the Permissions in the Access Policy assigned.
Resource ACL¶
Resource ACLs behave a bit differently, and basically allow you to restrict access to Resources (such as Documents, Weblinks, etc) by Resource Groups. They are comprised of 5 Parts:
- A Resource Group
- A User Group
- A Minimum Role
- An Access Policy
- A Context
This means that an ACL applied to a Resource Group will:
- Effect all the Users in the specified User Group
- ... with at least the Minimum Role specified
- ... give the Resource Permissions (save, load, delete, etc) in the Policy specified
- ... to all the Resources in the Resource Group
Manager publishing and multiple groups¶
Manager publish UI (Published checkbox, publish/unpublish dates, tree Publish/Unpublish actions, and the publish/unpublish processors) gates on the context permission publish_document (and unpublish_document) through modX::hasPermission(). In the manager, the current context is mgr.
That has a few practical consequences:
- A policy that grants
publish_documentonly on a frontend context (webor another site context) does not unlock manager publish controls. You need a Context Access ACL onmgr. - Resource ACL permissions
publish/unpublish(on the Resource Policy) are a different ACL surface. The current manager publish UI and save path do not use them. - Multiple user groups still OR together for a given context.
checkPolicyreturns true when any matching Context Access ACL for that context grants the permission. You do not need every group to include publish. - A common trap: one shared group gives Content Editor (no publish) on
mgr, and a second group puts a custom policy with publish only on another context. The user is in both groups, but still cannot publish in the manager untilpublish_documentexists on anmgrContext Access ACL.
To fix that setup: add Context Access for mgr on at least one of the user's groups, with a policy that includes publish_document (and unpublish_document if needed). Leave Content Editor on the other group if you want. Flush sessions/permissions and retest.
See also Administrator Policy (publish_document) and Giving a User Manager Access. Background: modxcms/revolution#14925.
See Also¶
- Users
- User Groups
- Resource Groups
- Roles
- Policies
- Security Tutorials
- Hardening MODX Revolution
- Troubleshooting Security
Support the team building MODX with a monthly donation.
The budget raised through OpenCollective is transparent, including payouts, and any contributor can apply to be paid for their work on MODX.
Backers
Budget
$194 per month—let's make that $500!
Learn more










