MODX ACL Context Restrictions and Least-Privilege Inheritance
28K reputation · 19 Jun 2021, 08:33 UTC
Implementing a least-privilege security model in MODX Revolution requires precise configuration of Access Control Lists (ACLs) to ensure users are restricted to specific contexts without inheriting unintended administrative privileges.
While the system supports nested user groups and granular permissions for resources and extras, the interaction between Group-level permissions and Context-specific restrictions can create ambiguity. Specifically, when a user belongs to multiple groups with overlapping inheritance trees, the priority of restriction versus permission is not always transparent.
To verify this behavior in current versions, a test environment should be used where a new User Group is created with zero inherited permissions, and access is manually assigned to a single resource.
- How does MODX resolve conflicting permissions when a user is assigned to both a restricted context group and a broader inherited group?
- What is the expected behavior for session expiration when a user's group permissions are modified while they have an active session?