We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 25551 ☆ A M B ☆
    • 1,231 Posts
    Folks I’m needing some help with using SESSIONS and COOKIES...

    I have managed to hook modx up with vanilla forum in a basic form and now I need to find out the best way to allow the webuser to be logged in to both apps using either COOKIES or SESSIONS. I have the webuser profile updating the user details in Vanilla with a plugin I have wrote and everything is working well. All I need to get on to the next thing is to get the user login system working.

    I need to know if I use COOKIES or SESSIONS or a mix of both to allow cross app validation. I’m trying to think of the best way to do this but I’m a bit confused which to do.

    Has anyone managed to create a shared SESSION or COOKIE that will allow cross app login?
      Ross Sivills - MD AugmentBLU Edinburgh, Scotland UK
      AugmentBLU - MODX Partner

      BLUcart - MODX Revolution E-Commerce & Shopping Cart
      • 9130
      • 171 Posts
      Did you try it?

      Sharing cookies is easy, as long as both applications are on the same domain they should see each others cookies, nothing special has to be done in order for this to work.

      As for sessions, obviously both applications must be on the same domain and hosted on the same server, but since they are both php apps I don’t see why the session will not be shared but I might be missing something here.
        • 25551 ☆ A M B ☆
        • 1,231 Posts
        Both apps are on the same server but using separate databases. I don’t know much about cookies so I am unsure on how to do this.

          Ross Sivills - MD AugmentBLU Edinburgh, Scotland UK
          AugmentBLU - MODX Partner

          BLUcart - MODX Revolution E-Commerce & Shopping Cart
          • 22303 MODX Staff
          • 10,725 Posts
          Quote from: rossco at May 14, 2009, 08:59 AM

          Both apps are on the same server but using separate databases. I don’t know much about cookies so I am unsure on how to do this.
          Unfortunately, this is where you typically have some choices, and none of them are that good. The problem is that each PHP application uses sessions in a unique way; there is in a sense, too much flexibility built in to PHP sessions and no standards with which applications are constructed upon this session framework. In addition to making sure the session cookies are configured the same for both apps, you’ll need to know precisely what each application expects in it’s session, how it manages the session_id’s, and pretty much every other detail of the application that depends on session data. For a forum app, that is just about everything in it, as it is for a CMS framework like MODx. I think you see the conflict of interest.

          For example, in order to provide extra security against session fixation attacks, most PHP applications periodically rewrite the session id whenever certain events occur, for instance, a user logs in and performs an action which adds them to a new security group with new permissions; the app will typically clear all the session data and reload it at that point. So in order to integrate and use the same sessions on two applications designed by different people, you have to accommodate all of the needs of both apps at every point where the apps depend on session data. This is no small task in many cases, and the best you can hope for is real-time sync’ing of user data so that each application has everything it needs to manage its own sessions using the same set of users.
            • 25551 ☆ A M B ☆
            • 1,231 Posts
            I guess some way to send the information to both modx and vanilla in one click is about the best way. Perhaps a plugin that after a user signs in to modx is forwarded to vanilla taking the $_POST[] info and signing then in to the forum. No idea what to do... I already created 2 plugins that act with webloginpe that pass any updates done on the profile page or when someone registers that is sent to both the modx database and vanilla. Nearly there, just got to find a way to allow sharing cookies or sessions.
              Ross Sivills - MD AugmentBLU Edinburgh, Scotland UK
              AugmentBLU - MODX Partner

              BLUcart - MODX Revolution E-Commerce & Shopping Cart
              • 29774
              • 386 Posts
              Probably a bit ambitious, but could this work using openID?

              openid snippet for modx:
              http://extremeswank.com/modx_authopenid.html

              Google login for Vanilla (openid but limited to Google)
              http://lussumo.com/addons/?PostBackAction=AddOn&AddOnID=427
                Snippets: GoogleMap | FileDetails | Related Plugin: SSL
                • 25551 ☆ A M B ☆
                • 1,231 Posts
                Is this idea safe?

                A registered user logs in to modx, 2 new cookies are then created in the users browser. One holds a verification key that is regenerated everytime the user logs in to their account so at least this is unique. The other cookie simply holds an encrypted figure that relates to the user’s ID. With these 2 cookies and the webloginPE cookie marrying up by querying the database for the unique code and user ID would then allow a user to browse to the forum which would then check the cookies and allow auto login.


                What I have done so far works, users can sign in to modx and use the forum without signing in. If they update their profile in modx, it also updates the forum database but I have made modx control the username, password etc. The only functions in the forum that are usable is the layout preferences and some extras. It’s early days for this idea but it’s working as I want... I just wonder how safe the method is for authenticating the user across both applications.

                Plugins are controlling updates from modx to the forum database, cookie generation, updating the verification keys, allowing for new registrations to be auto registered in the forum as well.

                I’m still learning so I’m not entirely sure if my idea is that safe.


                  Ross Sivills - MD AugmentBLU Edinburgh, Scotland UK
                  AugmentBLU - MODX Partner

                  BLUcart - MODX Revolution E-Commerce & Shopping Cart
                  • 29774
                  • 386 Posts
                  Rossco, I’m not sure about your question but did you see this post about a single signon snippet?
                  http://modxcms.com/forums/index.php/topic,35956.0.html

                  Seems it might do what you want (not tested myself).

                  EDIT: scratch that, looks like it uses an iframe which is most likely not what you want.
                    Snippets: GoogleMap | FileDetails | Related Plugin: SSL
                    • 25551 ☆ A M B ☆
                    • 1,231 Posts
                    Yeah Iframes are not what I want to play with to be honest... even using objects instead of Iframes is crap, IE crashes (no surprise).

                    I’m just thinking that if you can’t match passwords due to the difference in hashing, can’t I create my own table with a unique validation key that would be near enough the same idea as a password but the user has no control over it’s content. The user still needs to sign in to modx using their valid username and password etc, the plugin would then take the sessionid for example, place this code in the modx user attributes and in the forum table... query the database to match up user id, validation key and then if everything is fine the user could then navigate to the forum without having to login.
                      Ross Sivills - MD AugmentBLU Edinburgh, Scotland UK
                      AugmentBLU - MODX Partner

                      BLUcart - MODX Revolution E-Commerce & Shopping Cart
                      • 9130
                      • 171 Posts
                      Rossco, the main drawback to the scheme you are purposing is handling logins from multiple computers.

                      If I login on one computer, I’m assigned a secret number in the db, then I login from another computer and the number is replaced with a new one. Now I go back to the first computer and the cookie is already there but does not verify against the db. I’m now logged-on to modx but not to the forum.