We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 26310
    • 130 Posts
    Ok I apologize in advance for this noob question but I haven’t found a sufficient answer yet.

    If I wanted to pass a variable between modx pages, what is the best/most secure way of doing this?

    for example I’m logged in as a manager, click on a users name and pass the internal key to the next page to pull up user info?
      I twitch because I care....and drink too much coffee.
      • 5340
      • 1,624 Posts
      I would use session variables.

      $_SESSION['appId'] = "my_value";
        • 26310
        • 130 Posts
        $_SESSION[’appId’] = "my_value";

        Is the appId the ID of my choice? I’m not to experienced with session variables.

        Can you set that via a link? I’m trying to take a list of users and when clicking on the user you’re taken to a page where info is pulled from the DB with the userid passed from the previous page. I guess I could append to querystring but that doesn’t seem that secure.

        Unless I has the id.....but then I’m not sure if you could select a DB record where a value equals that to a hashed value??? Does any of this make sense because I think I’m lost! smiley
          I twitch because I care....and drink too much coffee.
          • 5274
          • 177 Posts
          or MODx PlaceHolders:

          Snippet:
          $modx -> setPlaceholder('var_name', 'var_value');
          


          HTML page:
          [+var_name+]
          
            • 5340
            • 1,624 Posts
            just do

            set’s up the session var(use with snippets)
            $_SESSION['my_session_var'] = "my_session_var_value";


            to read in another page using a snippet offcourse
            $my_session_var = $_SESSION['my_session_var'];
            echo $my_session_var;

              • 26310
              • 130 Posts
              The session method seems like it’d be the best but I’m not sure how to set a session variable with a link? If I POST back to the page and run a case statement to look for a QS variable and then run a function to set the session var and go to next page, it seems like I’m still passing the ID unsecurely....
                I twitch because I care....and drink too much coffee.
                • 5340
                • 1,624 Posts
                Why do you think that passing an ID is insecure?

                It’s just a number. It does not mean anything.

                ---

                I do not get how you want to set up a session variable with a link.

                Do you want to pass the id via the link like: index.php?my_get_var=5? This is not using a session variable but GET requests. In this case do

                $my_get_var = $_GET['my_get_var'];
                echo $my_get_var;




                  • 26310
                  • 130 Posts
                  You have a point about the security of a number that doesn’t mean anything on it’s own. Guess I’m just paranoid! So if I understand you right; I would have something like:

                  <a href="[~nextID~]?var=USERID>Username</a>


                  Then on my next page I’d use

                  $_GET
                  in my snippet to grab the variable being passed?
                    I twitch because I care....and drink too much coffee.
                    • 5340
                    • 1,624 Posts
                    That should work.