We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 20911
    • 84 Posts
    Hi, i know that this have been discussed before but i really need some help writing a plugin between the MODX authentication events and SMF forum. (If possible, WebLoginPE). Would be really great if we could get this to work between MODX and SMF.
    I took some lines out of the SMF_Module and the smf_api.

    Function Login
    function smf_LoginById($username, $cookieLength = 3600){
    
    	global $smf_connection, $smf_settings;	
    
    	// enable binary look up for MODx workaround.
    	$binaryLookup = !empty($smf_settings['reserveCase']) ?  'BINARY':'';
    
         $sql = "SELECT *
              FROM $smf_settings[db_prefix]members 
              WHERE $binaryLookup memberName = '".mysql_escape_string($username)."'
              LIMIT 1";
         $request = smf_query($sql, __FILE__, __LINE__);
         $smf_user = mysql_fetch_assoc($request);
         
        //Now login
        smf_setLoginCookie($cookieLength, $smf_user['ID_MEMBER'], sha1($smf_user['passwd'] . $smf_user['passwordSalt']));
        return smf_authenticateUser();
    }
    
    // Log out user - Added by Raymond
    function smf_LogoutById($username){
    
    	global $smf_connection, $smf_settings;


    Function used to authenticate a user from SMF.
    function smf_authenticateUser()
    {
    	global $smf_connection, $smf_settings, $smf_user_info;
    
    	// No connection, no authentication!
    	if (!$smf_connection)
    		return false;
    
    	// Check first the cookie, then the session.
    	if (isset($_COOKIE[$smf_settings['cookiename']]))
    	{
    		$_COOKIE[$smf_settings['cookiename']] = stripslashes($_COOKIE[$smf_settings['cookiename']]);
    
    		// Fix a security hole in PHP 4.3.9 and below...
    		if (preg_match('~^a:[34]:\{i:0;(i:\d{1,6}|s:[1-8]:"\d{1,8}");i:1;s:(0|40):"([a-fA-F0-9]{40})?";i:2;[id]:\d{1,14};(i:3;i:\d;)?\}$~', $_COOKIE[$smf_settings['cookiename']]) == 1)
    		{
    			list ($ID_MEMBER, $password) = @unserialize($_COOKIE[$smf_settings['cookiename']]);
    			$ID_MEMBER = !empty($ID_MEMBER) ? (int) $ID_MEMBER : 0;
    		}
    		else
    			$ID_MEMBER = 0;
    	}
    	elseif (isset($_SESSION['login_' . $smf_settings['cookiename']]))
    	{
    		list ($ID_MEMBER, $password, $login_span) = @unserialize(stripslashes($_SESSION['login_' . $smf_settings['cookiename']]));
    		$ID_MEMBER = !empty($ID_MEMBER) && $login_span > time() ? (int) $ID_MEMBER : 0;
    	}
    	else
    		$ID_MEMBER = 0;


    Logout function.
    function smf_LogoutById($username){
    
    	global $smf_connection, $smf_settings;	
    
    	// enable binary look up for MODx workaround - Raymond
    	$binaryLookup = !empty($smf_settings['reserveCase']) ? 'BINARY':'';
    
    	// shouldn't have to do this but it works!!
    	$sql = "SELECT *
    	  FROM $smf_settings[db_prefix]members 
    	  WHERE $binaryLookup memberName = '".mysql_escape_string($username)."'
    	  LIMIT 1";
    	$request = smf_query($sql, __FILE__, __LINE__);
    	$smf_user = mysql_fetch_assoc($request);
    	smf_query("DELETE FROM $smf_settings[db_prefix]log_online WHERE ID_MEMBER = '".$smf_user['ID_MEMBER']."' LIMIT 1", __FILE__, __LINE__);
    
        unset($_SESSION['login_' . $smf_settings['cookiename']]);
        smf_setLoginCookie(-3600, $smf_user['ID_MEMBER']);
        smf_setLoginCookie(-3600, 0);
    
    }
    
      Mysql 5.1.52
      Apache 2.2.17
      PHP 5.2.12
      Linux
      • 20911
      • 84 Posts
      Guess no one is interested in making a revolutionary thing....
        Mysql 5.1.52
        Apache 2.2.17
        PHP 5.2.12
        Linux
        • 25663 MODX Staff
        • 12,272 Posts
        What is happening when you try to run the code, or is this a request to have someone create it?
          Ryan Thrash, MODX Co-Founder
          Follow me on Twitter at @rthrash or catch my occasional unofficial thoughts at thrash.me
          • 20911
          • 84 Posts
          This code is just examples that ive pulled out of the smf api, and yes i would need some help with it.
            Mysql 5.1.52
            Apache 2.2.17
            PHP 5.2.12
            Linux
            • 20911
            • 84 Posts
            Is it possible that you can use the AutoLogin function for both events? Can you use same cookie for both modx and smf?

            function AutoLogin()
            	{
            		global $modx;
            		
            		$cookieName = 'WebLoginPE';
            		
            		$cookie = explode('|', $_COOKIE[$cookieName]);
            		$this->Username = $cookie[0];
            		$this->Password = $cookie[1];
            		
            		$web_users = $modx->getFullTableName('web_users');
            		$web_user_attributes = $modx->getFullTableName('web_user_attributes');
            		
            		$query = "SELECT * FROM ".$web_users.", ".$web_user_attributes." WHERE MD5(".$web_users.".`username`) = '".$this->Username."' AND ".$web_user_attributes.".`internalKey` = ".$web_users.".`id`";
            		$dataSource = $modx->db->query($query);
            		$limit = $modx->db->getRecordCount($dataSource);
            		if ($limit == 0 || $limit > 1)
            		{
            			$this->User = NULL;
            			return false;
            		}
            		else
            		{
            			$this->User = $modx->db->getRow($dataSource);
            			$this->Username = $this->User['username'];
            		}
            		
            		if ($this->User['password'] !== $this->Password){
            			return false;
            		}
            		
            		$this->UserIsBlocked();
            		$this->Authenticate();
            		$this->SessionHandler('start');
            		$this->UserDocumentGroups();
            		if ($type !== 'taconite')
            		{
            			$this->LoginHomePage();
            		}
            	}
            	
              Mysql 5.1.52
              Apache 2.2.17
              PHP 5.2.12
              Linux
              • 20911
              • 84 Posts
              I have no idea why this code doesnt work with Webloginpe.
              (Code is taken from SMFConnect Plugin).

              switch($e->name) {
              
              	case "OnWebAuthentication": 
              		// check to see if this user was imported from SMF database
              		if (strpos('<SMF>',$savedpassword)!==false) {
              			$password = array();
              			// get hased password
              			$sql = "SELECT * FROM $smf_settings[db_prefix]members 
              			  		WHERE $binaryLookup memberName = '".$modx->db->escape($username)."' LIMIT 1";
              			$request = smf_query($sql, __FILE__, __LINE__);
              			$smf_user = mysql_fetch_assoc($request);
              			$hashPassword = $smf_user['passwd']; 	
              			// build password hash list
              			$passwords[] = @sha1(strtolower($username) . $userpassword); // version 1.1 encryption
              			if($smf_user['passwordSalt']==''){
              				// other password hash formats
              				$passwords[] = sha1($userpassword);
              				$passwords[] = md5($userpassword);
              				$passwords[] = md5($userpassword.strtolower($username));
              				$passwords[] = md5_hmac($userpassword,strtolower($username));
              			}
              			// compare passwords
              			if(in_array($hashPassword, $passwords)) {
              				// update user account with MODx hash format
              				$tbl = $modx->getFullTableName('web_users');				
              				$fld = array('password'=>md5($userpassword));
              				$modx->db->update($fld,$tbl,"username='".mysql_escape_string($username)."'");
              				$e->output(TRUE);
              			}
              			
              		}
              		cms_smf_reset_db(); // set MODx DB as the default
              		break;
                Mysql 5.1.52
                Apache 2.2.17
                PHP 5.2.12
                Linux