We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 38357
    • 178 Posts
    Hello,
    I normally use Login for secure access to Modx sites but have a problem in this instance.
    I have a site where users need to login with Username and Password to a remote site (not Modx and not under my control). I do this with a form on the Modx site and use an iframe to display the remote site on a Modx page.

    How can I use a successful login to that remote site to activate that successful login to the Login snippet without using two submit buttons as I don't want to maintain a user database in modx? ie if they successfully login to the remote site they are also authenticated on the Modx site.
    Is it possible for example to use two entries in action=" " in the form or similar to do this or is there another way of achieving it such as localStorage?

    thanks [ed. note: bobd72 last edited this post 9 years, 11 months ago.]
      • 3749
      • 24,544 Posts
      This might work for you: http://bobsguides.com/blog.html/2016/04/06/bypassing-the-modx-manager-login-i/.

      See all three articles there. There is a discussion of how to make it work in the front end as well.
        Did I help you? Buy me a beer
        Get my Book: MODX:The Official Guide
        MODX info for everyone: http://bobsguides.com/modx.html
        My MODX Extras
        Bob's Guides is now hosted at A2 MODX Hosting
        • 38357
        • 178 Posts
        Thanks Bob - that looks promising.
          • 38357
          • 178 Posts
          I have tried the plugin at http://bobsguides.com/blog.html/2016/04/06/bypassing-the-modx-manager-login-i/ as suggested by Bob. It is generally successful but am getting some weird results.

          I have put together some code for the element lgnLoginTpl which successfully logs in a Modx user as well as logging in to a remote site using the same credentials.
          Code I am using is as below. I'm not an expert so it is probably untidy and can be refined, but it works. I am able to access the other site succesfully using an iframe on another Modx page. Credentials entered into the first form are duplicated into the second form using 'onblur' and then both forms are submitted by the script.

          However, I have a couple of problems.
          1. When a user who is not in the Modx database (but is in the remote server database) tries to access, the plugin doesn't fire and create a new user in Modx as I expect it should. It does however work if I am logged into the manager as admin in the same browser in a separate Tab , so I am assuming that it is some sort of permissions problem for anonymous user?

          2. When a user logs in, the page is not refreshed which means that the form remains and the logout link does not appear in its place.

          3. Error messages do not show.

          Any ideas from those more skilled than me would be appreciated.


          <script>
          $(document).ready(function() {
              $("#myLogin").click(function() {
                  $.post($("#Login").attr("action"), $("#Login").serialize(),
                    function(data) {
                      $("#msg").append(data);
                      $.post($("#myclubLogin").attr("action"), $("#myclubLogin").serialize(),
                        function(data) {
                          $("#msg").append(data);
                        });
                    });
                });
            });
          </script>
          
          
          <div class="loginMessage">[[+errors]]</div>
                  <form id="Login" name="Login" class="loginLoginForm" action="[[~[[*id]]]]" method="post" >
                      
                      <fieldset class="loginLoginFieldset">
                          
                           <!-- Show Member Login message -->  <legend class="loginLegend"></legend> 
                          <label class="loginPasswordLabel" style="color: #AEE67A;"> Username:
                              <input class="loginUsername" type="txt" name="username" onblur="document.myclubLogin.user.value = this.value;" />
                            </label>
                          
                          <label class="loginPasswordLabel" style="color: #AEE67A;"> Password:
                              <input type="password" name="password" onblur="document.myclubLogin.password.value = this.value;"/>
                          </label>
                               <input class="returnUrl" type="hidden" name="returnUrl" value="[[+request_uri]]" />
          
                          [[+login.recaptcha_html]]
                          
                              <input class="loginLoginValue" type="hidden" name="service" value="login" />
                        
                         
                      </fieldset>
                  </form>
                  
          <div class="loginMessage">[[+errors]]</div>
                  <form name="myclubLogin" id="myclubLogin" method="post" action="url_to_log_in_to_remote_server" target="myClub"> 
          
                      <fieldset class="loginLoginFieldset" >
          
                          <input id="action" type="hidden" name="action" value="login" /> 
                          <input class="loginUsername" type="hidden" name="user" id="user"   />
                          
                          <input type="hidden" name="password"  />
                          <input id="action" type="hidden" name="action" value="password" /> 
          
                          <input class="loginLoginValue" type="hidden" name="service" value="login" />
                          <span class="loginLoginButton">
                          <input id="myLogin" name="myLogin" type="submit" value="[[+actionMsg]]" style="float: right;"/>
                          </span>
          
                      </fieldset>
                  </form> 
          
          <div> 
          <iframe id="myClub" name="myClub" style="width:0; height:0; border:0; border: none;"></iframe>
          </div>




          [ed. note: bobd72 last edited this post 9 years, 10 months ago.]
            • 3749
            • 24,544 Posts
            Did you look at the following articles in that series? They discuss how to handle the situation when the user is not in the database.
              Did I help you? Buy me a beer
              Get my Book: MODX:The Official Guide
              MODX info for everyone: http://bobsguides.com/modx.html
              My MODX Extras
              Bob's Guides is now hosted at A2 MODX Hosting
              • 38357
              • 178 Posts
              Thanks Bob,
              Yes i have been through all three and used the plugin in the last one after changing 'manager' for 'web'. It seems that the script is working OK as a user who is both on the Modx database with a password and also the remote site is logged into both correctly. However, if the user is not on the Modx site ( or doesn't have a password associated with their account) the plugin doesn't seem to fire. Everything is set up as you indicated - plugin has both system events activated. Perhaps the credentials being passed from the script is the problem? I don't care if the Modx user doesn't have a password - if they are authenticated by the remote account that is enough.
                • 3749
                • 24,544 Posts
                Hmmm. I tested the scripts in the blog posts before posting them, but lots of things can go wrong in a real-world situation.

                You can see if the code of the plugin is executing by inserting log messages something like this (then look in the error log):

                $eventName = $modx->event->name;
                $msg = 'Event: ' . $eventName . ' -- Line x of plugin executing';
                $modx->log(modX::LOG_LEVEL_ERROR, $msg);
                


                Since the plugin has multiple parts (for the different events), you'll want log message in both parts.
                  Did I help you? Buy me a beer
                  Get my Book: MODX:The Official Guide
                  MODX info for everyone: http://bobsguides.com/modx.html
                  My MODX Extras
                  Bob's Guides is now hosted at A2 MODX Hosting
                  • 38357
                  • 178 Posts
                  Thanks again Bob. Error log shows as below when an anonymous user tries to log in - no new user is created in the database.

                  [2016-11-12 17:25:34] (ERROR @ /volume1/web/qpgc/core/cache/includes/elements/modplugin/8.include.cache.php : 44) [OnBeforeWebLogin] permission_denied
                  [2016-11-12 17:25:34] (ERROR @ /volume1/web/qpgc/core/cache/includes/elements/modplugin/8.include.cache.php : 51) Event: OnBeforeWebLogin -- Line x of plugin executing [ed. note: bobd72 last edited this post 9 years, 10 months ago.]
                    • 3749
                    • 24,544 Posts
                    Is that permission_denied error from your own code calling $modx->log(), or is MODX throwing that error?

                      Did I help you? Buy me a beer
                      Get my Book: MODX:The Official Guide
                      MODX info for everyone: http://bobsguides.com/modx.html
                      My MODX Extras
                      Bob's Guides is now hosted at A2 MODX Hosting
                      • 38357
                      • 178 Posts
                      When I remove the inserted log messages code from the plugin the error messages are no longer shown in the log, so it is the error code in the plugin that is generating the message.