We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 3749
    • 24,544 Posts
    There were a couple of typos in the snippet code. Try this (paste it from here to the snippet):

    $fields = array('name' => 'id');
    $docId = (int) $modx->runSnippet('getUrlParam', $fields);
    
    $query = $modx->newQuery('modResource', $docId);
    
    $msg = 'REQUEST_URI: ' . $_SERVER["REQUEST_URI"] .
        'HOST: ' . $_SERVER["HTTP_HOST"] .
        'SERVER_NAME: ' . $_SERVER["SERVER_NAME"] .
        'REFERER ' . $_SERVER["HTTP_REFERER"] .
        'URI" ' . $_SERVER["REQUEST_URI"];
    
    
    $modx->log(modX::LOG_LEVEL_ERROR, $msg);
    return '';
      Did I help you? Buy me a beer
      Get my Book: MODX:The Official Guide
      MODX info for everyone: http://bobsguides.com/modx.html
      My MODX Extras
      Bob's Guides is now hosted at A2 MODX Hosting
      • 38357
      • 178 Posts
      Thanks Bob,
      Got an error message this time:

      [2016-12-14 14:28:40] (ERROR @ /volume1/web/qpgc/core/cache/includes/elements/modsnippet/48.include.cache.php : 14) REQUEST_URI: /qpgc/HOST: 192.168.72.11SERVER_NAME: 192.168.72.11REFERER URI" /qpgc/
      [2016-12-14 14:28:58] (ERROR @ /volume1/web/qpgc/core/cache/includes/elements/modplugin/8.include.cache.php : 61) Event: OnBeforeWebLogin -- Line x of plugin executing
      [2016-12-14 14:28:58] (ERROR @ /volume1/web/qpgc/core/cache/includes/elements/modplugin/8.include.cache.php : 92) Event: OnWebAuthentication -- Line x of plugin executing

      It looks like the snippet in the iframe is executing before the plugin and is giving the URL of my server rather than the remote one?

      if I refresh the page I get:
      [2016-12-14 20:51:36] (ERROR @ /volume1/web/qpgc/core/cache/includes/elements/modsnippet/48.include.cache.php : 14) REQUEST_URI: /qpgc/index.php?id=17&service=logoutHOST: 192.168.72.11SERVER_NAME: 192.168.72.11REFERER http://192.168.72.11/qpgc/index.php?id=17URI" /qpgc/index.php?id=17&service=logout

      if i go to another page I get:
      [2016-12-14 20:52:27] (ERROR @ /volume1/web/qpgc/core/cache/includes/elements/modsnippet/48.include.cache.php : 14) REQUEST_URI: /qpgc/index.php?id=17HOST: 192.168.72.11SERVER_NAME: 192.168.72.11REFERER http://192.168.72.11/qpgc/index.php?id=17&service=logoutURI" /qpgc/index.php?id=17

      [ed. note: bobd72 last edited this post 9 years, 9 months ago.]
        • 3749
        • 24,544 Posts
        I was afraid of that. There ought to be an easy way around this, but I can't think of one. My only remaining thoughts are

        1. Use JavaScript with a timing loop that waits for the iFrame to be completed, then grabs and examines the iFrame content and makes an Ajax call to a processor that sets the users login status. It's not a trivial programming job and I'm not positive that it would work, but I think it would.

        2. Ditch the iFrame, let the page reload (make the form post to the current page), and in the form processing code, use cURL to log in to the remote, examine the returned page, and set the users login status based on what's there - then create and return the HTML showing the results.

        I think I would do #2, though it's still not an easy solution by any means.

        MODX assumes that any user other than the (anonymous) user is in the DB, so you might have to jump through some hoops to make it work, and in the end, it might not be possible without creating some dummy users, keeping track of which ones are currently logged in, and use one who is not to be the current $modx->user.

        Whenever I've done something like this, I've put the users in the DB with the same username and password used on the remote. That way, the convoluted code only has to work the first time they log in.

        PHP's get_headers() might, or might not, be useful in determining whether the user successfully logged in to the remote. [ed. note: BobRay last edited this post 9 years, 9 months ago.]
          Did I help you? Buy me a beer
          Get my Book: MODX:The Official Guide
          MODX info for everyone: http://bobsguides.com/modx.html
          My MODX Extras
          Bob's Guides is now hosted at A2 MODX Hosting
          • 38357
          • 178 Posts
          Hi Bob,
          Quote from: BobRay at Dec 14, 2016, 10:47 PM
          I was afraid of that. There ought to be an easy way around this, but I can't think of one.
          :-) I thought that also - but it has turned out to be far from trivial :-(

          My only remaining thoughts are

          1. Use JavaScript with a timing loop that waits for the iFrame to be completed, then grabs and examines the iFrame content and makes an Ajax call to a processor that sets the users login status. It's not a trivial programming job and I'm not positive that it would work, but I think it would.

          2. Ditch the iFrame, let the page reload (make the form post to the current page), and in the form processing code, use cURL to log in to the remote, examine the returned page, and set the users login status based on what's there - then create and return the HTML showing the results.

          I think I would do #2, though it's still not an easy solution by any means.

          MODX assumes that any user other than the (anonymous) user is in the DB, so you might have to jump through some hoops to make it work, and in the end, it might not be possible without creating some dummy users, keeping track of which ones are currently logged in, and use one who is not to be the current $modx->user.

          Whenever I've done something like this, I've put the users in the DB with the same username and password used on the remote. That way, the convoluted code only has to work the first time they log in.

          Yes and that first time login is what I need also.

          How do you ensure they are valid users if you can't check them against the database?

          The code and plugin I have now successfully adds the username to the database and users can log on just fine. However, anyone who puts in a random username and password gets their name added to the Modx database so they can see restricted pages and log in later - they just don't get logged in to the remote site.

          I am trying to use the successful login to that remote site to determine if the user is a valid user or not and block them if they are not.

          So the existing arrangement works perfectly to add valid users to the database and accept their future logins, but it does not enable me to exclude those who are not valid and the only way I can check that validity at the moment is by whether or not they can log in to the remote site successfully.

          Nothing is ever simple is it?
            • 3749
            • 24,544 Posts
            I would use cURL to log the user in.

            Something like this might do it (untested):

            $ch = curl_init();
            
            $data = array('username' => $_POST['username'], 'password' => $_POST['username']);
            curl_setopt($ch, CURLOPT_RETURNTRANSER, 1);
            curl_setopt($ch, CURLOPT_URL, 'http://remote/site/login/page');
            curl_setopt($ch, CURLOPT_POST, 1);
            curl_setopt($ch, CURLOPT_SAFE_UPLOAD, false); // required as of PHP 5.6.0
            curl_setopt($ch, CURLOPT_POSTFIELDS, $data);
            
            $page = curl_exec($ch);
            
            /* Check the $page with strpos() to see if it was successful */
            $success = false;
            
            if (strpos($page, 'some string' !== false)) {
                $success = true;
            }
            
            if ($success) {
               /* Your code to log the user in and put them in the DB */
            
            } else {
               return 'Login Failed';
            }



            For starters, just echo '<pre>' . $page . '</pre>'; to see if you're getting the page back and what's in it for good and bad logins.

            You might also need this, but try it first without it:

            curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);

              Did I help you? Buy me a beer
              Get my Book: MODX:The Official Guide
              MODX info for everyone: http://bobsguides.com/modx.html
              My MODX Extras
              Bob's Guides is now hosted at A2 MODX Hosting
              • 38357
              • 178 Posts
              Thanks Bob,
              I have tried this with various additions but nothing seems to work. The html form
              <form name="myclubLogin" id="myclubLogin" method="post" action="url_to_log_in_to_remote_server" target="myClub"> 
               
                          <fieldset class="loginLoginFieldset" >
               
                              <input id="action" type="hidden" name="action" value="login" /> 
                              <input class="loginUsername" type="hidden" name="user" id="user"   />
                               
                              <input type="hidden" name="password"  />
                              <input id="action" type="hidden" name="action" value="password" /> 
               
                              <input class="loginLoginValue" type="hidden" name="service" value="login" />
                              <span class="loginLoginButton">
                              <input id="myLogin" name="myLogin" type="submit" value="[[+actionMsg]]" style="float: right;"/>
                              </span>
               
                          </fieldset>
                      </form> 
              works perfectly but the Curl code returns a copy of the login page and the message 'Login Failed' at the bottom.
              I placed
              echo '<pre>' . $page . '</pre>'; 
              directly after
              $page = curl_exec($ch);
              and it gives a result of '1'
              I also replaced 'some string' with a string which appears on the 'logged-in' page? [ed. note: bobd72 last edited this post 9 years, 9 months ago.]
                • 3749
                • 24,544 Posts
                Do you have both of these in the cURL code?

                curl_setopt($ch, CURLOPT_RETURNTRANSER, 1);
                curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);

                Do a view source on their login page. See what the field names are, what the action is, and if there are any hidden fields that you need to set.

                You may have to make it a two-step process, where you use cURL to go to the Login page (without any $_POST variables set), THEN take the next step of posting to the URL specified in the action of the form with cURL.

                Even then, they may be rejecting login requests from a foreign server.

                Worst case, I think you can use cURL or JavaScript to go to the page, then use JS to fill in and submit their actual form. check the results, and launch a processor that authenticates the user.
                  Did I help you? Buy me a beer
                  Get my Book: MODX:The Official Guide
                  MODX info for everyone: http://bobsguides.com/modx.html
                  My MODX Extras
                  Bob's Guides is now hosted at A2 MODX Hosting
                  • 38357
                  • 178 Posts
                  Quote from: BobRay at Dec 19, 2016, 11:20 AM
                  Do you have both of these in the cURL code?

                  curl_setopt($ch, CURLOPT_RETURNTRANSER, 1);
                  curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
                  Yes - both are set

                  Do a view source on their login page. See what the field names are, what the action is, and if there are any hidden fields that you need to set.

                  <form action="/security/login.msp" method="post" name="form" id="form">
                  <div id="loginUsername">
                  <label for="username">Username:</label>
                  <input name="action" type="hidden" id="action" value="login" />

                  <input autocomplete="on" type="text" name="user" value="" size="11" maxlength="32" />
                  </div>
                  <div id="loginPassword">
                  <label for="username">Password:</label>
                  <input name="action" type="hidden" id="action" value="password" />

                  <input autocomplete="on" type="password" name="password" value="" size="11" maxlength="64" />
                  </div>
                  <input type="image" value="submit" src="/images/loginBtn.gif" border="0" alt="Submit" name="Submit" id="submitBtn" />
                  </form>


                  You may have to make it a two-step process, where you use cURL to go to the Login page (without any $_POST variables set), THEN take the next step of posting to the URL specified in the action of the form with cURL.

                  Even then, they may be rejecting login requests from a foreign server.

                  Worst case, I think you can use cURL or JavaScript to go to the page, then use JS to fill in and submit their actual form. check the results, and launch a processor that authenticates the user.

                  I am beginning to realise that this is beyond my skillset. I had thought that it would be a relatively simple process but not so. It is a job for a community group and is becoming far to complex for my rather ancient brain to resolve smiley

                  I really appreciate all you help but think that it is time to find another way and forgo this most convenient path.

                  Have a great Christmas and safe New Year celebrations.
                    • 3749
                    • 24,544 Posts
                    Thanks,

                    Sorry I couldn't be more help.
                      Did I help you? Buy me a beer
                      Get my Book: MODX:The Official Guide
                      MODX info for everyone: http://bobsguides.com/modx.html
                      My MODX Extras
                      Bob's Guides is now hosted at A2 MODX Hosting