Joomla on LiteSpeed: CSS and JavaScript 403 errors with query strings Joomla 3 to Joomla 6 with T3 and Purity III: a migration case study Website hacked? What to do first and mistakes to avoid How to import Excel into WordPress with a custom plugin ChatGPT Ads: Paid Advertising Is Challenging Google Ads Ecommerce localization in Italy: catalogue, checkout and technical support Italian web developer for website support and local coordination Italian website localization: more than translating web content Taking over an existing Italian website without rebuilding it Website localization in Italy: a technical guide for international companies WordPress Dashboard Won't Load: 8 Causes and How to Fix Them WordPress Not Working: What to Check Before Panicking WordPress Site Stuck After Update: How to Recover It WP-Admin Error 500: Common Causes and Effective Solutions How to Identify Which WordPress Plugin Is Really Slowing Down Your Site Without Guesswork Joomla on LiteSpeed: CSS and JavaScript 403 errors with query strings Joomla 3 to Joomla 6 with T3 and Purity III: a migration case study Website hacked? What to do first and mistakes to avoid How to import Excel into WordPress with a custom plugin ChatGPT Ads: Paid Advertising Is Challenging Google Ads Ecommerce localization in Italy: catalogue, checkout and technical support Italian web developer for website support and local coordination Italian website localization: more than translating web content Taking over an existing Italian website without rebuilding it Website localization in Italy: a technical guide for international companies WordPress Dashboard Won't Load: 8 Causes and How to Fix Them WordPress Not Working: What to Check Before Panicking WordPress Site Stuck After Update: How to Recover It WP-Admin Error 500: Common Causes and Effective Solutions How to Identify Which WordPress Plugin Is Really Slowing Down Your Site Without Guesswork

Joomla 3 ACL: diagnose user access and permission errors

Author Graziano De Maio - Gdmtech
I wish you a good read and remember: if after reading this article you need help, don't hesitate to contact me.
Author: Graziano De Maio | Founder of Gdmtech
Table of contents

When a Joomla 3 user cannot view an article or edit it, investigate two different systems. Viewing access levels control visibility; action permissions control operations. Both involve user groups, but assigning a viewing level does not automatically grant publishing rights.

Start with a precise requirement: which user should see which resource and perform which action? The Joomla 3 ACL tutorial separates viewing from doing. Keep that distinction throughout diagnosis.

Separate groups, viewing levels and actions

Groups represent users with shared requirements. A viewing access level identifies groups allowed to see an item. Permissions govern actions such as creating, editing, editing one’s own content and changing publication state.

RequirementSettings to examine
Read a restricted articleUser groups and content access level
See a menu entryMenu item’s viewing level
Edit an articleComponent, category and article permissions
Publish a changeState-changing permission
Enter administration and use a componentAdministrator login and component access

The Joomla Community Magazine access-control article explains groups and viewing levels. These controls are distinct from filesystem permissions; failure to write a server file needs a different investigation.

Example: a document area for selected customers

Consider a hypothetical area where selected users must read private articles without editing them. On staging, prepare a dedicated group within an appropriate hierarchy and a viewing level containing the authorised groups. Apply that level to the protected items and test with a representative member.

Check the article, category, menu item and linking module separately. Hiding a menu does not automatically protect the underlying content when its direct URL is known.

If an article links to a publicly served PDF, restricting the article does not make the file private. Document delivery needs its own authorisation check or server protection. Test the direct document URL anonymously as well.

Include an excluded user in the test. Successful access confirms that someone can enter; a negative test establishes that those without permission cannot.

Example: an editor who can write but not publish

For a contributor limited to one category, define the required actions first. Creating, editing their own articles and changing state are separate capabilities. Do not assign a full administrative role simply to reveal one missing button.

Use a test category and two articles with different authors. Check creation, editing an owned article, editing someone else’s article and publishing. If backend work is required, test administrator login and component access too; editing permission alone does not guarantee entry to the interface.

This exposes an overly broad grant made globally when it should apply only to one section. Choose the narrowest appropriate scope after checking what the user already inherits.

Interpret allowed, denied and inherited permissions

Ordinary action permissions account for group hierarchy and resource scope. An inherited explicit denial cannot simply be overridden by selecting Allowed lower down. Locate the source of the denial and assess whether it matches the intended group design.

Inherited is not synonymous with allowed: it refers to the result of higher levels. Inspect calculated permissions after saving and review every group membership associated with the user, not just the group currently being edited.

Do not use a Super User as the sole test account, because those privileges do not represent an operational role. Retain a recovery administration account while changing rules and avoid tests that could lock out all administrators.

A useful record identifies the permission, resource and membership responsible for the result. This prevents successive adjustments from turning into an undocumented collection of exceptions.

Investigate hidden modules when access is correct

Check publication state, dates, language, position and menu assignments. A module allowed for the group may not be assigned to the current page or rendered by its template.

After changing permissions, retest in a fresh session and consider caching behaviour. A stored page generated under another authentication state is not definitive evidence of the current ACL calculation.

For third-party components, verify that the affected operations enforce the intended authorisation. Hiding an interface button does not replace checking permission on the request that changes data.

If the problem occurs only within one component, preserve that distinction in the report instead of changing unrelated global permissions.

Build a permissions acceptance matrix

Preserve configuration and a backup before changes, recording the original rule and required behaviour. A small matrix can compare anonymous visitors, authorised readers, contributors and administrators against viewing, editing and publishing.

Test each allowed action and at least one action that must be denied, including direct page access. Use controlled accounts rather than customer credentials and record the result for each role.

Joomla 3 is unsupported. Correct ACL remains necessary but does not replace platform maintenance. Keep the matrix for verifying permissions after migration as well.

If users have inappropriate access, I can review Joomla groups and permissions and define a configuration that can be checked against the operations each role needs.

Author Graziano De Maio - Gdmtech
I wish you a good read and remember: if after reading this article you need help, don't hesitate to contact me.
Author: Graziano De Maio | Founder of Gdmtech