We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 32216
    • 1 Posts
    Hello Modx community,

    I have a question regarding how modX validates for open sessions. I have a feeling that this might in fact be a bug in 2.1.1, but I would like to confirm it first before opening a bug report. I have a somehow unique modx installation. In a nutshell I have to start session before I instantiate modX. So when modX calls the modX::getSessionState() from modX::_initSession() it returns modX::SESSION_STATE_EXTERNAL state. This itself is understandable, however the modAccessibleObject::checkPolicy() is depending on modX state to be modX::SESSION_STATE_INITIALIZED, which in this case will never be. This is causing all policy checks to pass.

    Can anyone comment on this please. Can modX support being instantiated after a session has been opened? If so, how?

    Thanks,
    Radek
      • 22303 MODX Staff
      • 10,725 Posts
      No, MODX controls it’s own session. It will not work if you start the session manually before MODX calls session_start. You can provide your own session_handler_class, but you must let MODX control the session.
        • 36763
        • 70 Posts
        Quote from: opengeek at Jul 22, 2011, 09:32 AM
        It will not work if you start the session manually before MODX calls session_start.

        I've been "Loading MODx Externally" and had found the sessions weren't being found on the external files. This explains it. Thanks. Solved me several hours of work. laugh

        Eg:

        require_once('../config.core.php');
        require_once MODX_CORE_PATH.'model/modx/modx.class.php';
        $modx = new modX();
        $modx->initialize('web');
        $modx->getService('error', 'error.modError');
        session_start();
        $sess_id = session_id();