We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 5430
    • 247 Posts
    REVO 2.5.x on MODX Cloud

    I've been scouring the forums and I feel like I'm missing something obvious here, but I can't get this to work. I need to authenticate users across several MODX sites on separate clouds (they can't be combined into a multi-context environment) via a single login. I have no trouble using the login from one site to authenticate a user and start a session at an external site, but the created session doesn't work if I actually visit that site. How can I get MODX to recognize the visit as part of that same remotely activated session?

    I have two sites I'm experimenting with. I have a snippet on one site that posts user data to an endpoint on the second site (the endpoint is a snippet running in a resource). The endpoint snippet runs the following :

    if ($modx->user = $modx->getObject('modUser', array('username' => $_POST['username']))){
        $modx->user->addSessionContext('web');
        if ($modx->user->isAuthenticated('web')) {
          $message = 'user is authenticated';
        }else{
            $message = 'user is not authenticated';
        }
        $response = array(
          'status' => true,
          'message' => $message,
          'user' => $modx->user->get('username')
        );
    }else{
        $response = array(
          'status' => false,
          'message' => 'User not found'
        );
    }
    


    When I return $response I get a true status, user is authenticated, and the correct username, but if I try to visit this site in the same browser window the session doesn't apply and I'm viewed as anonymous. I'm sure this is exactly what's supposed to happen, but I've no idea how to change that behavior so the activated session to actually applied to the next visit. I feel like this should be obvious and I'm just too stupid to see it. How can I access that created session for an actual visit?

    This question has been answered by BobRay. See the first response.

      • 18373 ☆ A M B ☆
      • 3,141 Posts
      Mark Hamstra Reply #2, 9 years ago
      What you're doing in that code, is authenticating the user on the "host" site (the one that has the actual users). You're adding a context to their session on the host site.

      That's not going to give you a session or authentication on the "client" site (the one you're trying to login to), because they don't share sessions.

      On the client site, you should grab the user information (securely in a way that can't be exploited and that you're absolutely sure the user is who they say they are), and turn that into a user in the local database. Then log that user in locally.

      I feel like this should be obvious and I'm just too stupid to see it.

      SSO is not something that tends to be obvious. wink
        Mark Hamstra • Developer spending his days working on Premium Extras and a MODX Site Dashboard with the ability to remotely upgrade MODX and extras to make the MODX world a little better.

        Tweet me @mark_hamstra, check my infrequent blog at markhamstra.com, my slightly more frequent ramblings at MODX.today or see code at Github.
        • 5430
        • 247 Posts
        Thanks Mark, but I think I might not have painted the picture clearly. Starting a session on the host site is what I'm trying to do, I just can't find a way to visit the host site using that session.

        The user is already authenticated on the "client" site (let's call it domain1.com), I'm trying to use a hook on successful login to post valid user information (I'm using a catchall user, not the same user info) to a different site (domain2.com). I'm trying to find a way to let a user that's successfully logged in at domain1.com visit domain2.com without logging in again. I'm not trying to let a user from domain2.com login at domain1.com.

        Am I simply thinking of this in the wrong way? Do I have to use the same user information on both sites for this to be possible (I'm using a catchall user because the traffic will be one-way)? Perhaps I'm completely misunderstanding sessions here and it's simply not possible to start a usable session on a second site prior to actually visiting the site.

        I hate SSO.
        • discuss.answer
          • 3749
          • 24,544 Posts
          Something to try, rather than trying to start a new session on the remote site, is to store your own session variable. Then forward to the Login page with &service=login.

          A plugin in the Login process (attached to OnManagerAuthentication) can check for the session variable, and if it's there, tell MODX to log the user in the normal way. See this series of blog articles: https://bobsguides.com/blog.html/2016/04/06/bypassing-the-modx-manager-login-i/.
            Did I help you? Buy me a beer
            Get my Book: MODX:The Official Guide
            MODX info for everyone: http://bobsguides.com/modx.html
            My MODX Extras
            Bob's Guides is now hosted at A2 MODX Hosting
            • 5430
            • 247 Posts
            Quote from: BobRay at Sep 04, 2017, 04:26 PM
            Something to try, rather than trying to start a new session on the remote site, is to store your own session variable. Then forward to the Login page with &service=login.

            A plugin in the Login process (attached to OnManagerAuthentication) can check for the session variable, and if it's there, tell MODX to log the user in the normal way. See this series of blog articles: https://bobsguides.com/blog.html/2016/04/06/bypassing-the-modx-manager-login-i/.

            Thanks, Bob. That sounds like a plausible solution.
              • 3749
              • 24,544 Posts
              Don't thank me until it works. wink
                Did I help you? Buy me a beer
                Get my Book: MODX:The Official Guide
                MODX info for everyone: http://bobsguides.com/modx.html
                My MODX Extras
                Bob's Guides is now hosted at A2 MODX Hosting