$fields = array('name' => 'id');
$docId = (int) $modx->runSnippet('getUrlParam', $fields);
$query = $modx->newQuery('modResource', $docId);
$msg = 'REQUEST_URI: ' . $_SERVER["REQUEST_URI"] .
'HOST: ' . $_SERVER["HTTP_HOST"] .
'SERVER_NAME: ' . $_SERVER["SERVER_NAME"] .
'REFERER ' . $_SERVER["HTTP_REFERER"] .
'URI" ' . $_SERVER["REQUEST_URI"];
$modx->log(modX::LOG_LEVEL_ERROR, $msg);
return '';[2016-12-14 14:28:40] (ERROR @ /volume1/web/qpgc/core/cache/includes/elements/modsnippet/48.include.cache.php : 14) REQUEST_URI: /qpgc/HOST: 192.168.72.11SERVER_NAME: 192.168.72.11REFERER URI" /qpgc/
[2016-12-14 14:28:58] (ERROR @ /volume1/web/qpgc/core/cache/includes/elements/modplugin/8.include.cache.php : 61) Event: OnBeforeWebLogin -- Line x of plugin executing
[2016-12-14 14:28:58] (ERROR @ /volume1/web/qpgc/core/cache/includes/elements/modplugin/8.include.cache.php : 92) Event: OnWebAuthentication -- Line x of plugin executing
[2016-12-14 20:51:36] (ERROR @ /volume1/web/qpgc/core/cache/includes/elements/modsnippet/48.include.cache.php : 14) REQUEST_URI: /qpgc/index.php?id=17&service=logoutHOST: 192.168.72.11SERVER_NAME: 192.168.72.11REFERER http://192.168.72.11/qpgc/index.php?id=17URI" /qpgc/index.php?id=17&service=logout
[2016-12-14 20:52:27] (ERROR @ /volume1/web/qpgc/core/cache/includes/elements/modsnippet/48.include.cache.php : 14) REQUEST_URI: /qpgc/index.php?id=17HOST: 192.168.72.11SERVER_NAME: 192.168.72.11REFERER http://192.168.72.11/qpgc/index.php?id=17&service=logoutURI" /qpgc/index.php?id=17
I was afraid of that. There ought to be an easy way around this, but I can't think of one.:-) I thought that also - but it has turned out to be far from trivial :-(
My only remaining thoughts are
1. Use JavaScript with a timing loop that waits for the iFrame to be completed, then grabs and examines the iFrame content and makes an Ajax call to a processor that sets the users login status. It's not a trivial programming job and I'm not positive that it would work, but I think it would.
2. Ditch the iFrame, let the page reload (make the form post to the current page), and in the form processing code, use cURL to log in to the remote, examine the returned page, and set the users login status based on what's there - then create and return the HTML showing the results.
I think I would do #2, though it's still not an easy solution by any means.
MODX assumes that any user other than the (anonymous) user is in the DB, so you might have to jump through some hoops to make it work, and in the end, it might not be possible without creating some dummy users, keeping track of which ones are currently logged in, and use one who is not to be the current $modx->user.
Whenever I've done something like this, I've put the users in the DB with the same username and password used on the remote. That way, the convoluted code only has to work the first time they log in.
$ch = curl_init();
$data = array('username' => $_POST['username'], 'password' => $_POST['username']);
curl_setopt($ch, CURLOPT_RETURNTRANSER, 1);
curl_setopt($ch, CURLOPT_URL, 'http://remote/site/login/page');
curl_setopt($ch, CURLOPT_POST, 1);
curl_setopt($ch, CURLOPT_SAFE_UPLOAD, false); // required as of PHP 5.6.0
curl_setopt($ch, CURLOPT_POSTFIELDS, $data);
$page = curl_exec($ch);
/* Check the $page with strpos() to see if it was successful */
$success = false;
if (strpos($page, 'some string' !== false)) {
$success = true;
}
if ($success) {
/* Your code to log the user in and put them in the DB */
} else {
return 'Login Failed';
}curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
<form name="myclubLogin" id="myclubLogin" method="post" action="url_to_log_in_to_remote_server" target="myClub">
<fieldset class="loginLoginFieldset" >
<input id="action" type="hidden" name="action" value="login" />
<input class="loginUsername" type="hidden" name="user" id="user" />
<input type="hidden" name="password" />
<input id="action" type="hidden" name="action" value="password" />
<input class="loginLoginValue" type="hidden" name="service" value="login" />
<span class="loginLoginButton">
<input id="myLogin" name="myLogin" type="submit" value="[[+actionMsg]]" style="float: right;"/>
</span>
</fieldset>
</form> echo '<pre>' . $page . '</pre>';
$page = curl_exec($ch);and it gives a result of '1'
Do you have both of these in the cURL code?Yes - both are set
curl_setopt($ch, CURLOPT_RETURNTRANSER, 1);
curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
Do a view source on their login page. See what the field names are, what the action is, and if there are any hidden fields that you need to set.
You may have to make it a two-step process, where you use cURL to go to the Login page (without any $_POST variables set), THEN take the next step of posting to the URL specified in the action of the form with cURL.
Even then, they may be rejecting login requests from a foreign server.
Worst case, I think you can use cURL or JavaScript to go to the page, then use JS to fill in and submit their actual form. check the results, and launch a processor that authenticates the user.
