EasyStore Administrator Access / Joomla ACL - Question | JoomShaper

EasyStore Administrator Access / Joomla ACL

BP

Bruce Paine

EasyStore 1 week ago

I am setting up EasyStore 2.0.1 for a small retail business and would like to create a Joomla backend user who can manage EasyStore orders without having broad Joomla Administrator access. In this instance, the business owner needs to process orders, update order status and view customer details, but does not need to manage Joomla users, menus, templates or site configuration.

I have tested the standard Joomla user groups:

  • Manager – cannot see the EasyStore component under Components.
  • Administrator – can access EasyStore, but also has access to many other Joomla administration areas that are unrelated to order processing.

I have searched the documentation but have not found any information about configuring EasyStore-specific administrator permissions or Joomla ACL.

My question is: Is there currently a supported way to allow a backend user to access only EasyStore (or specific EasyStore functions such as Orders) without making them a Joomla Administrator?

If this is not currently possible, I would like to suggest it as a feature request. It would be very useful if EasyStore supported Joomla's native ACL so that site owners could create roles such as "Order Manager" or "Store Manager" with access only to the EasyStore component and its relevant functions.

1
5 Answers
Ziaul Kabir
Ziaul Kabir
Accepted Answer
Support Agent 1 week ago #229140

Hi Bruce,

Thanks for reaching out to us.

Yes, this is possible using Joomla ACL. You can configure a backend user with access only to the EasyStore component (or specific EasyStore functions, depending on your ACL configuration) without granting full Joomla Administrator permissions.

If you run into any issues while configuring the permissions, please let us know. We'll be happy to assist you.

Best Regards,

0
Scott
Scott
Accepted Answer
1 week ago #229046

I concur, what a great and must have option for ES

0
BP
Bruce Paine
Accepted Answer
1 week ago #229241

Hi Ziaul Kabir,

Thanks for confirming Joomla ACL was the correct approach. I have now successfully created a restricted EasyStore user.

For anyone else trying to do this, the important point is that the configuration is mainly handled through Joomla ACL rather than inside the EasyStore component.

The basic steps I followed were:

  1. Create a new Joomla User Group (e.g. Store Manager).

  2. Assign the required EasyStore permissions through: System → Global Configuration → EasyStore → Permissions

  3. Configure the group permissions through: System → Global Configuration → Permissions

  4. Assign the user to the new group.

  5. In my case, I also had to remove the user from the Administrator group.

Joomla ACL permissions are additive, so leaving the user in Administrator will override any restrictions.

Initially the user could see several components. By adjusting the permissions in Global Configuration for each of the components, I was able to hide unnecessary backend areas (e.g. Articles, Banners, Media, SmartSearch) and leave only EasyStore visible.

The final result is a user who can access EasyStore order management without access to Joomla configuration, users, content, or other components.

One additional point that may help other users: the permission named "Access Administration Interface" can be confusing.

It does not control whether a user can log into the Joomla Administrator area. Instead, it controls whether the user can access that specific component from within the Administrator interface.

By setting this permission to Denied for unwanted components, the corresponding component menu items disappear from the user's backend view.

It might be worth adding a worked example to the EasyStore documentation, as users who are unfamiliar with Joomla ACL may not realise that the setup is done mainly through Joomla's permission system rather than EasyStore itself.

0
BP
Bruce Paine
Accepted Answer
1 week ago #229242

I would like to add the following observation:

Joomla ACL successfully allows us to restrict backend access to EasyStore. However, once inside EasyStore, there are still menu items and sections visible that may not be relevant to a particular staff role.

Fine-grained permissions within EasyStore would allow administrators to create purpose-specific roles such as Order Manager, Product Manager, or Store Administrator.

I may have missed something, but so far I have not found a way to achieve this level of restriction.

For example, in our case an Order Manager may need access to Orders but not necessarily Customer management (our site only allows guest checkout) or configuration areas.

That said, I am happy with the current configuration. The ability to hide or restrict options within EasyStore is more of a "nice to have" feature rather than a blocker.

Thanks.

0
Ziaul Kabir
Ziaul Kabir
Accepted Answer
Support Agent 1 week ago #229248

Hi,

Thank you for the detailed explanation. I understand what you mean now.

EasyStore relies on Joomla's ACL to control access to the component, but it doesn't yet support section-level permissions inside the component itself.

Thank you for sharing your use case and for clarifying that this is a "nice to have" rather than a blocker. Feedback like yours is very valuable, and we'll definitely keep it in mind as we plan future improvements to EasyStore.

We really appreciate your suggestion and your continued support!

0