Jump to main content Jump to doc navigation

What is an ACL (Access Control List)?

An ACL, or Access Control List, is a set of Permissions attached to an object. More information on ACLs can be found here in Wikipedia.

Usage

In MODX, ACLs can be applied to any modAccessibleObject. Primarily MODX Revolution 2.0 allows for ACLs on Resources and Contexts.

Context ACL

A Context ACL is referenced of 4 parts:

This means that one can assign a ACL to a Context that will apply to:

  • All the Users in a User Group
  • ...with at least the Minimum Role specified
  • ...that will give the Users all the Permissions in the Access Policy assigned.

Resource ACL

Resource ACLs behave a bit differently, and basically allow you to restrict access to Resources (such as Documents, Weblinks, etc) by Resource Groups. They are comprised of 5 Parts:

This means that an ACL applied to a Resource Group will:

  • Effect all the Users in the specified User Group
  • ... with at least the Minimum Role specified
  • ... give the Resource Permissions (save, load, delete, etc) in the Policy specified
  • ... to all the Resources in the Resource Group

Manager publishing and multiple groups

Manager publish UI (Published checkbox, publish/unpublish dates, tree Publish/Unpublish actions, and the publish/unpublish processors) gates on the context permission publish_document (and unpublish_document) through modX::hasPermission(). In the manager, the current context is mgr.

That has a few practical consequences:

  1. A policy that grants publish_document only on a frontend context (web or another site context) does not unlock manager publish controls. You need a Context Access ACL on mgr.
  2. Resource ACL permissions publish / unpublish (on the Resource Policy) are a different ACL surface. The current manager publish UI and save path do not use them.
  3. Multiple user groups still OR together for a given context. checkPolicy returns true when any matching Context Access ACL for that context grants the permission. You do not need every group to include publish.
  4. A common trap: one shared group gives Content Editor (no publish) on mgr, and a second group puts a custom policy with publish only on another context. The user is in both groups, but still cannot publish in the manager until publish_document exists on an mgr Context Access ACL.

To fix that setup: add Context Access for mgr on at least one of the user's groups, with a policy that includes publish_document (and unpublish_document if needed). Leave Content Editor on the other group if you want. Flush sessions/permissions and retest.

See also Administrator Policy (publish_document) and Giving a User Manager Access. Background: modxcms/revolution#14925.

See Also

  1. Users
  2. User Groups
  3. Resource Groups
  4. Roles
  5. Policies
    1. Permissions
      1. Permissions - Administrator Policy
      2. Permissions - Resource Policy
    2. ACLs
    3. PolicyTemplates
  6. Security Tutorials
    1. Giving a User Manager Access
    2. Making Member-Only Pages
    3. Creating a Second Super Admin User
    4. Restricting an Element from Users
    5. More on the Anonymous User Group
  7. Hardening MODX Revolution
  8. Troubleshooting Security
    1. Resetting a User Password Manually

Support the team building MODX with a monthly donation.

The budget raised through OpenCollective is transparent, including payouts, and any contributor can apply to be paid for their work on MODX.

Backers

  • modmore
  • STERC
  • Digital Penguin
  • Jens Wittmann – Gestaltung & Entwicklung
  • CrewMark
  • Fabian Christen
  • Sepia River Studios
  • Dannevang Digital
  • Alex
  • A. Moreno
  • Chris Fickling
  • Stéphane Jäggi
  • Murray Wood
  • Anton Tarasov
  • JT Skaggs
  • deJaya
  • Lefthandmedia
  • eydolan
  • Following Sea
  • Guido Gallenkamp
  • YJ
  • Raffy
  • Snow Creative
  • Nick Clark
  • Guest
  • Helen
  • krisznet
  • Yanni
  • Richard

Budget

$194 per month—let's make that $500!

Learn more