/* Generate a random, 50 character password */
$password = "";
for($i=0;$i<50;$i++) {
$password .= chr( (mt_rand(1, 36) <= 26) ? mt_rand(97, 122) : mt_rand(48, 57 ));
}
/* Create the new user */
$fields = array(
'username' => $username,
'password' => $password,
'blocked' => '0',
'email' => '[email protected]',
'passwordnotifymethod' => 'x',
);
$response = $modx->runProcessor('security/user/create', $fields);
/* Log the error if the processor fails */
if ($response->isError()) {
if ($response->hasFieldErrors()) {
$fieldErrors = $response->getAllErrors();
$errorMessage = implode("\n", $fieldErrors);
} else {
$errorMessage = $response->getMessage();
}
$modx->log(modX::LOG_LEVEL_ERROR, '[OnBeforeWebLogin] ' . $errorMessage);
$output = true; /* prevent login */
} else {
$output = false;
}
break;
$user = $modx->newObject('modUser');
$user->set('username', $userName);
$user->set('password', $password);
$user->set('active', false); /* or true */
$user->set('blocked', false);
$user->save();
$user = $modx->getObject('modUser', array('username' => $username));
if ($user) {
$userId = $user->get('id');
$profile = $modx->newObject('modUserProfile');
$profile->set('email', $email);
$profile->set('internalKey', $userId);
$profile->save();
} else {
$modx->log(modX::LOG_LEVEL_ERROR, 'could not retrieve user -- USERNAME: ' . $username);
}
<script>
$(document).ready(function() {
$("#myLogin").click(function() {
$.post($("#Login").attr("action"), $("#Login").serialize(),
function(data) {
$("#msg").append(data);
$.post($("#myclubLogin").attr("action"), $("#myclubLogin").serialize(),
function(data) {
$("#msg").append(data);
});
});
});
});
</script>
<div class="loginMessage">[[+errors]]</div>
<form id="Login" name="Login" class="loginLoginForm" action="[[~[[*id]]]]" method="post" >
<fieldset class="loginLoginFieldset">
<!-- Show Member Login message --> <legend class="loginLegend"></legend>
<label class="loginPasswordLabel" style="color: #AEE67A;"> Username:
<input class="loginUsername" type="txt" name="username" onblur="document.myclubLogin.user.value = this.value;" />
</label>
<label class="loginPasswordLabel" style="color: #AEE67A;"> Password:
<input type="password" name="password" onblur="document.myclubLogin.password.value = this.value;"/>
</label>
<input class="returnUrl" type="hidden" name="returnUrl" value="[[+request_uri]]" />
[[+login.recaptcha_html]]
<input class="loginLoginValue" type="hidden" name="service" value="login" />
</fieldset>
</form>
<div class="loginMessage">[[+errors]]</div>
<form name="myclubLogin" id="myclubLogin" method="post" action="url_to_log_in_to_remote_server" target="myClub">
<fieldset class="loginLoginFieldset" >
<input id="action" type="hidden" name="action" value="login" />
<input class="loginUsername" type="hidden" name="user" id="user" />
<input type="hidden" name="password" />
<input id="action" type="hidden" name="action" value="password" />
<input class="loginLoginValue" type="hidden" name="service" value="login" />
<span class="loginLoginButton">
<input id="myLogin" name="myLogin" type="submit" value="[[+actionMsg]]" style="float: right;"/>
</span>
</fieldset>
</form>
<div>
<iframe id="myClub" name="myClub" style="width:0; height:0; border:0; border: none;"></iframe>
</div><?php
/* Get the event name */
$eventName = $modx->event->name;
/* Run the code appropriate to the event */
switch($eventName) {
case 'OnBeforeWebLogin':
/* Return if the user is already in the database */
/** @var $username string */
$existingUser = $modx->getObject('modUser', array ('username' => $username));
if ($existingUser) {
$modx->event->_output = false; /* allow login */
return;
}
/* Retrieve password here
$password = "";
*/
/* Create the new user */
$fields = array(
'username' => $username,
'password' => $password,
'active' => '1',
'blocked' => '0',
'email' => '[email protected]',
'passwordnotifymethod' => 'x',
);
$response = $modx->runProcessor('security/user/create', $fields);
/* Assign new user to User Group / Role */
$user = $modx->getObject('modUser', array('username' => $username));
if( $user ){
$user->save();
$user->joinGroup('Members','Members');}
/* Log the error if the processor fails */
if ($response->isError()) {
if ($response->hasFieldErrors()) {
$fieldErrors = $response->getAllErrors();
$errorMessage = implode("\n", $fieldErrors);
} else {
$errorMessage = $response->getMessage();
}
$modx->log(modX::LOG_LEVEL_ERROR, '[OnBeforeWebLogin] ' . $errorMessage);
$output = true; /* prevent login */
} else {
$output = false;
}
$eventName = $modx->event->name;
$msg = 'Event: ' . $eventName . ' -- Line x of plugin executing';
$modx->log(modX::LOG_LEVEL_ERROR, $msg);
break;
case 'OnWebAuthentication':
$authenticated = false;
/* Your authentication code here sets $authenticated to true if the
user should be allowed to log in */
/* Set authentic user to active if not already active */
if ($authenticated) {
if (! $user->get('active')) {
$user->set('active', '1');
$user->save();
}
}
$output = (bool)$authenticated;
$eventName = $modx->event->name;
$msg = 'Event: ' . $eventName . ' -- Line x of plugin executing';
$modx->log(modX::LOG_LEVEL_ERROR, $msg);
break;
}
$modx->event->_output = $output;
return;/* Set authentic user to active if not already active */
if ($authenticated) {
if (! $user->get('active')) {
$user->set('active', '1');
$user->save();
}
}I'm not sure it's related to any issues you have, but this code will never execute since you've set $authenticated to false:
/* Set authentic user to active if not already active */ if ($authenticated) { if (! $user->get('active')) { $user->set('active', '1'); $user->save(); } }
As a result, the return from OnWebAuthentication will always be false.
if( /*some condition set by successful login to remote site */){
$authenticated=true;
$user->set('active', '1');
$user->save();
} else {
authenticated=false;
}<div class="loginMessage">[[+errors]]</div>
<form name="myclubLogin" id="myclubLogin" method="post" action="url_to_log_in_to_remote_server" target="myClub">
<fieldset class="loginLoginFieldset" >
<input id="action" type="hidden" name="action" value="login" />
<input class="loginUsername" type="hidden" name="user" id="user" />
<input type="hidden" name="password" />
<input id="action" type="hidden" name="action" value="password" />
<input class="loginLoginValue" type="hidden" name="service" value="login" />
<span class="loginLoginButton">
<input id="myLogin" name="myLogin" type="submit" value="[[+actionMsg]]" style="float: right;"/>
</span>
</fieldset>
</form> case 'OnWebAuthentication':
$authenticated = false;
/* Your authentication code here sets $authenticated to true if the
user should be allowed to log in */
/* Set authentic user to active if not already active */
if ($authenticated) {
if (! $user->get('active')) {
$user->set('active', '1');
$user->save();
}
}How to authenticate the user on the remote site in code will depend on the remote site. Some sites will have an API, some have another method, and for some you actually need to use cURL to post the users credentials and any necessary hidden fields to the remote site's login form and check the returned page for signs that the login was successful.
$_SESSION['successAtRemote'] = 1; // or 0 if it failed
$authenticated = isset($_SESSION['successAtRemote']) && $_SESSION['successAtRemote'] === 1)'
If you can tell whether the user is successfully logged in to the remote site,Yes - herein lies the problem. I can see visually that the user is logged in as the URL changes but how do I turn that into a variable?
you can set a $_SESSION variable and read it later in your plugin:But can this be used in a .tpl file which is a chunk?
$_SESSION['successAtRemote'] = 1; // or 0 if it failed
Then in the plugin:
$authenticated = isset($_SESSION['successAtRemote']) && $_SESSION['successAtRemote'] === 1)'
