We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 3749
    • 24,544 Posts
    My tests indicate that when you are logged in to the Manager as the admin Super User and preview a document in the front end, you are in the "web" context, but are not logged in (authenticated) in that context unless you fill in a login form in the front end, although you are still authenticated in the "mgr" context.

    If you are previewing from the Manager as the admin Super User and log in in the front end as another user, you are authenticated in the "web" context as the other user and, at the same time, still authenticated in the "mgr" context as the admin as far as any snippet or plugin code is concerned.

    IOW, when logged in as the admin in the back end, then previewing in the front end with no front-end login:

    $modx->getAuthenticatedUser(); // fails because the context defaults to web and you're not logged in there.
    $modx->getAuthenticatedUser('web'); // fails because you're not logged in there.
    $modx->getAuthenticatedUser('mgr'); // returns the admin user.


    After logging into the back end as the admin, then logging in as the admin in a front-end login form while previewing:

    $modx->getAuthenticatedUser(); // returns the admin user.
    $modx->getAuthenticatedUser('web'); // returns the admin user.
    $modx->getAuthenticatedUser('mgr'); // returns the admin user.


    After logging in as the admin in the back end, and then previewing and logging in as JoeBlow in a front-end login form:

    $modx->getAuthenticatedUser(); // returns JoeBlow.
    $modx->getAuthenticatedUser('web'); // returns JoeBlow.
    $modx->getAuthenticatedUser('mgr') returns the admin user.


    I just wanted to make sure this is correct and is what is intended.


      Did I help you? Buy me a beer
      Get my Book: MODX:The Official Guide
      MODX info for everyone: http://bobsguides.com/modx.html
      My MODX Extras
      Bob's Guides is now hosted at A2 MODX Hosting
      • 22303 MODX Staff
      • 10,725 Posts
      That is as intended, yes. Keep in mind, getAuthenticatedUser() is used when modX::initialize(’web’) is called, and $modx->user is automatically assigned based on the following logic:


      • If session indicates a user is authenticated in the current context, that user is returned
      • elseif session indicates a user is authenticated in the mgr context, that user is returned
      • else a transient modUser object is created with id = 0 and username = (anonymous)

      So, as you can see, there is always a user object involved. Checking if the client session is authenticated in the current context is as easy as:
      <?php
      $isAuthenticated = $modx->user->hasSessionContext($modx->context->get('key'));
      ?>


      You can even check multiple contexts at once, if you needed to:
      <?php
      $isAuthenticated = $modx->user->hasSessionContext(array('web', 'web2', 'web3'));
      ?>
        • 3749
        • 24,544 Posts
        Quote from: OpenGeek at Feb 01, 2010, 02:45 PM


        So, as you can see, there is always a user object involved. Checking if the client session is authenticated in the current context is as easy as:
        <?php
        $isAuthenticated = $modx->user->hasSessionContext($modx->context->get('key'));
        ?>


        OK, but this seems simpler and appears to have the same result (i.e. returns null if no one is logged in in the current context):

        $isAuthenticated = $modx->getAuthenticatedUser();


        Is there a reason to use hasSessionContext() if you’re only interested in a single context?
          Did I help you? Buy me a beer
          Get my Book: MODX:The Official Guide
          MODX info for everyone: http://bobsguides.com/modx.html
          My MODX Extras
          Bob's Guides is now hosted at A2 MODX Hosting
          • 22303 MODX Staff
          • 10,725 Posts
          Quote from: BobRay at Feb 02, 2010, 08:26 PM

          Quote from: OpenGeek at Feb 01, 2010, 02:45 PM


          So, as you can see, there is always a user object involved. Checking if the client session is authenticated in the current context is as easy as:
          <?php
          $isAuthenticated = $modx->user->hasSessionContext($modx->context->get('key'));
          ?>


          OK, but this seems simpler and appears to have the same result (i.e. returns null if no one is logged in in the current context):

          $isAuthenticated = $modx->getAuthenticatedUser();


          Is there a reason to use hasSessionContext() if you’re only interested in a single context?
          modX::getAuthenticatedUser() is intended only to be called from modX::getUser(), which is already called for you on every request automatically (unless you are running from the CLI where there is no session). There is no reason to ever call this method in a component. $modx->user->hasSessionContext() is how you determine the authenticated status of the current user identified by the unique browser session. There is no reason to use modX::getAuthenticatedUser() which would result in another unnecessary SQL query to pull the user data that is already loaded in $modx->user.
            • 3749
            • 24,544 Posts
            OK, is either of these safe as a test of authentication in the current context?

            $isAuthenticated = $modx->user->hasSessionContext($modx->context->get());
            $isAuthenticated = $modx->user->hasSessionContext();
            
              Did I help you? Buy me a beer
              Get my Book: MODX:The Official Guide
              MODX info for everyone: http://bobsguides.com/modx.html
              My MODX Extras
              Bob's Guides is now hosted at A2 MODX Hosting
              • 22303 MODX Staff
              • 10,725 Posts
              Quote from: BobRay at Feb 03, 2010, 10:54 PM

              OK, is either of these safe as a test of authentication in the current context?

              $isAuthenticated = $modx->user->hasSessionContext($modx->context->get());
              $isAuthenticated = $modx->user->hasSessionContext();
              

              Neither,
               $isAuthenticated = $modx->user->hasSessionContext($modx->context->get('key'));
              is the only valid test for the "current" context. You can check a specific context by specifying it’s key directly, i.e.
               $isAuthenticated = $modx->user->hasSessionContext('web2');
                • 3749
                • 24,544 Posts
                Quote from: OpenGeek at Feb 03, 2010, 08:56 AM


                modX::getAuthenticatedUser() is intended only to be called from modX::getUser(), which is already called for you on every request automatically (unless you are running from the CLI where there is no session). There is no reason to ever call this method in a component.

                This may sound unlikely, but supposing that you wanted the user object for the Manager user who is previewing a resource in the front end (which you could possibly want to personalize a front-end tool designed to be used from the Manager via preview)?

                With the code above, I was writing a sort of "educational" snippet to show users who was currently logged in to which context. It seemed that getAuthenticatedUser(’mgr’) was the logical way to go (and the most intuitively obvious) since hasSessionContext() doesn’t return a user object.

                It’s also problematic, when trying to explain things, that $modx->user->hasSessionContext(’web’) and $modx->user->hasSessionContext(’mgr’) both return true when previewing from the Manager while also logged in to the front end, but don’t tell you anything about the fact that there may, or may not, be two separate users objects involved.

                I’m also wondering why you would use $modx->user->hasSessionContext($modx->context->get(’key’)), since it always returns true even when no one is logged in.

                In contrast, $modx->getAuthenticatedUser() returns null unless a user is actually logged in in the current front-end context.
                  Did I help you? Buy me a beer
                  Get my Book: MODX:The Official Guide
                  MODX info for everyone: http://bobsguides.com/modx.html
                  My MODX Extras
                  Bob's Guides is now hosted at A2 MODX Hosting
                  • 22303 MODX Staff
                  • 10,725 Posts
                  Quote from: BobRay at Feb 05, 2010, 12:31 AM

                  This may sound unlikely, but supposing that you wanted the user object for the Manager user who is previewing a resource in the front end (which you could possibly want to personalize a front-end tool designed to be used from the Manager via preview)?
                  That’s how it already works; if you are not logged into the current context, it loads the user you are logged into the manager with automatically. This is how view_unpublished works, for instance.

                  Quote from: BobRay at Feb 05, 2010, 12:31 AM

                  With the code above, I was writing a sort of "educational" snippet to show users who was currently logged in to which context. It seemed that getAuthenticatedUser(’mgr’) was the logical way to go (and the most intuitively obvious) since hasSessionContext() doesn’t return a user object.
                  The only information you can get about logged in users is from your own session. I don’t understand the intention here. You want to show the current user what contexts he’s logged into and as who? My point was, the appropriate user object is already loaded for you (see modX::getUser()), plus there are other implications, like user settings which are merged into the config and only available if you are actually logged into the current context (i.e. manager user options are not loaded when user is browsing web while logged into mgr context, only the permissions from the mgr user are considered).

                  Quote from: BobRay at Feb 05, 2010, 12:31 AM

                  It’s also problematic, when trying to explain things, that $modx->user->hasSessionContext(’web’) and $modx->user->hasSessionContext(’mgr’) both return true when previewing from the Manager while also logged in to the front end, but don’t tell you anything about the fact that there may, or may not, be two separate users objects involved.
                  The mgr user is only applicable to the front-end for administrative preview purposes, i.e. view_unpublished. You should never use the user data from the mgr context to drive logic in the front-end however. This is why we no longer separate users into web and mgr. A user is a user and is either authenticated in the current context or not. The mgr user being instantiated on the front-end is only there for functional purposes, and I may be changing this behavior to load the anonymous user and simply attach the mgr user permissions to it if logged into the mgr. This may be a better solution.

                  Quote from: BobRay at Feb 05, 2010, 12:31 AM

                  I’m also wondering why you would use $modx->user->hasSessionContext($modx->context->get(’key’)), since it always returns true even when no one is logged in.
                  That would be a bug if that is true, which I am testing after I post this.
                    • 22303 MODX Staff
                    • 10,725 Posts
                    Quote from: OpenGeek at Feb 05, 2010, 09:40 AM

                    Quote from: BobRay at Feb 05, 2010, 12:31 AM

                    I’m also wondering why you would use $modx->user->hasSessionContext($modx->context->get(’key’)), since it always returns true even when no one is logged in.
                    That would be a bug if that is true, which I am testing after I post this.
                    I can’t reproduce this. Putting the following snippet in a page in the front-end always returns ’false’, even when I am logged into ’mgr’:
                    <?php
                    return $modx->user->hasSessionContext($modx->context->get('key')) ? 'true' : 'false';
                    ?>

                      • 3749
                      • 24,544 Posts
                      Quote from: OpenGeek at Feb 05, 2010, 09:40 AM

                      Quote from: BobRay at Feb 05, 2010, 12:31 AM

                      With the code above, I was writing a sort of "educational" snippet to show users who was currently logged in to which context. It seemed that getAuthenticatedUser(’mgr’) was the logical way to go (and the most intuitively obvious) since hasSessionContext() doesn’t return a user object.
                      The only information you can get about logged in users is from your own session...

                      Settings may not be available, but the Mgr user’s profile is currently available via getAuthenticatedUser(’mgr’). I get your overall point, though, and am rethinking my approach to the topic. I was trying to delineate why, and in what circumstances, previewing from the Manager can give you misleading info versus viewing in a different browser.


                      I may be changing this behavior to load the anonymous user and simply attach the mgr user permissions to it if logged into the mgr. This may be a better solution.
                      It’s a tough call, IMO. Previewing from the Mgr is such an anomaly that it’s hard to foresee all the side effects of a given strategy.

                      And it’s hard to know whether users would want the preview to be a "true" preview of what an anonymous user would see or an "false" preview that makes certain development tasks possible. I suppose there could be a true_preview System Setting. wink


                      Quote from: BobRay at Feb 05, 2010, 12:31 AM

                      I’m also wondering why you would use $modx->user->hasSessionContext($modx->context->get(’key’)), since it always returns true even when no one is logged in.
                      That would be a bug if that is true, which I am testing after I post this.

                      My apologies. I was bitten by precedence and lack of sleep:

                      $isAuthenticated = $modx->user->hasSessionContext($modx->context->get('key'));
                      
                      return 'Authenticated: ' . $isAuthenticated? 'Yes' : 'No'; // always returns 'Yes'
                      

                      should have been:

                      return 'Authenticated: ' . ($isAuthenticated? 'Yes' : 'No');


                        Did I help you? Buy me a beer
                        Get my Book: MODX:The Official Guide
                        MODX info for everyone: http://bobsguides.com/modx.html
                        My MODX Extras
                        Bob's Guides is now hosted at A2 MODX Hosting