Permissions

Icecube registers three permissions under Settings → Users → User Groups (or on an individual user’s permissions tab).

Manage locks

Grants access to the Icecube locks admin screen. Users with this permission can create, edit, enable, disable, and delete locks. Give this only to people you trust to decide what should be protected.

Bypass all locks without password

Users with this permission skip every unlock modal. Saves and deletes on locked content go through as if no lock existed. Use sparingly — it’s the equivalent of having the master password on file.

Unlock locked content with password

Users with this permission can enter the password on the unlock modal and get a time-limited unlock session. This is the permission most editors need.

It’s required, not cosmetic. A user without it never sees the unlock modal and can’t unlock content at all — they’ll simply be blocked from saving or deleting locked elements. Requests to the unlock endpoint from those users are rejected outright.

Upgrading from 5.1 or earlier? This permission is enforced as of 5.2.0. Before that it was listed in the permissions screen but never actually checked, so any logged-in user could unlock content. Grant it to your editors’ user groups before upgrading, or they’ll lose the ability to unlock. Admins are unaffected.

Setting Up Permissions

  1. Go to Settings → Users → User Groups in the control panel.
  2. Select the group you want to update.
  3. Scroll to the Icecube heading in the permissions list.
  4. Check the permissions that apply to the group.
  5. Save the user group.

Admin Users

Admin users have every permission by default. If Admins Bypass is enabled in plugin settings, admins skip the unlock flow entirely. See Configuration.