$modx->getAuthenticatedUser(); // fails because the context defaults to web and you're not logged in there.
$modx->getAuthenticatedUser('web'); // fails because you're not logged in there.
$modx->getAuthenticatedUser('mgr'); // returns the admin user.$modx->getAuthenticatedUser(); // returns the admin user.
$modx->getAuthenticatedUser('web'); // returns the admin user.
$modx->getAuthenticatedUser('mgr'); // returns the admin user.$modx->getAuthenticatedUser(); // returns JoeBlow.
$modx->getAuthenticatedUser('web'); // returns JoeBlow.
$modx->getAuthenticatedUser('mgr') returns the admin user.<?php
$isAuthenticated = $modx->user->hasSessionContext($modx->context->get('key'));
?><?php
$isAuthenticated = $modx->user->hasSessionContext(array('web', 'web2', 'web3'));
?>
So, as you can see, there is always a user object involved. Checking if the client session is authenticated in the current context is as easy as:
<?php $isAuthenticated = $modx->user->hasSessionContext($modx->context->get('key')); ?>
$isAuthenticated = $modx->getAuthenticatedUser();
modX::getAuthenticatedUser() is intended only to be called from modX::getUser(), which is already called for you on every request automatically (unless you are running from the CLI where there is no session). There is no reason to ever call this method in a component. $modx->user->hasSessionContext() is how you determine the authenticated status of the current user identified by the unique browser session. There is no reason to use modX::getAuthenticatedUser() which would result in another unnecessary SQL query to pull the user data that is already loaded in $modx->user.
Quote from: OpenGeek at Feb 01, 2010, 02:45 PM
So, as you can see, there is always a user object involved. Checking if the client session is authenticated in the current context is as easy as:
<?php $isAuthenticated = $modx->user->hasSessionContext($modx->context->get('key')); ?>
OK, but this seems simpler and appears to have the same result (i.e. returns null if no one is logged in in the current context):
$isAuthenticated = $modx->getAuthenticatedUser();
Is there a reason to use hasSessionContext() if you’re only interested in a single context?
$isAuthenticated = $modx->user->hasSessionContext($modx->context->get()); $isAuthenticated = $modx->user->hasSessionContext();
Neither,
OK, is either of these safe as a test of authentication in the current context?
$isAuthenticated = $modx->user->hasSessionContext($modx->context->get()); $isAuthenticated = $modx->user->hasSessionContext();
$isAuthenticated = $modx->user->hasSessionContext($modx->context->get('key')); $isAuthenticated = $modx->user->hasSessionContext('web2');
modX::getAuthenticatedUser() is intended only to be called from modX::getUser(), which is already called for you on every request automatically (unless you are running from the CLI where there is no session). There is no reason to ever call this method in a component.
That’s how it already works; if you are not logged into the current context, it loads the user you are logged into the manager with automatically. This is how view_unpublished works, for instance.
This may sound unlikely, but supposing that you wanted the user object for the Manager user who is previewing a resource in the front end (which you could possibly want to personalize a front-end tool designed to be used from the Manager via preview)?
The only information you can get about logged in users is from your own session. I don’t understand the intention here. You want to show the current user what contexts he’s logged into and as who? My point was, the appropriate user object is already loaded for you (see modX::getUser()), plus there are other implications, like user settings which are merged into the config and only available if you are actually logged into the current context (i.e. manager user options are not loaded when user is browsing web while logged into mgr context, only the permissions from the mgr user are considered).
With the code above, I was writing a sort of "educational" snippet to show users who was currently logged in to which context. It seemed that getAuthenticatedUser(’mgr’) was the logical way to go (and the most intuitively obvious) since hasSessionContext() doesn’t return a user object.
The mgr user is only applicable to the front-end for administrative preview purposes, i.e. view_unpublished. You should never use the user data from the mgr context to drive logic in the front-end however. This is why we no longer separate users into web and mgr. A user is a user and is either authenticated in the current context or not. The mgr user being instantiated on the front-end is only there for functional purposes, and I may be changing this behavior to load the anonymous user and simply attach the mgr user permissions to it if logged into the mgr. This may be a better solution.
It’s also problematic, when trying to explain things, that $modx->user->hasSessionContext(’web’) and $modx->user->hasSessionContext(’mgr’) both return true when previewing from the Manager while also logged in to the front end, but don’t tell you anything about the fact that there may, or may not, be two separate users objects involved.
That would be a bug if that is true, which I am testing after I post this.
I’m also wondering why you would use $modx->user->hasSessionContext($modx->context->get(’key’)), since it always returns true even when no one is logged in.
I can’t reproduce this. Putting the following snippet in a page in the front-end always returns ’false’, even when I am logged into ’mgr’:
Quote from: BobRay at Feb 05, 2010, 12:31 AMThat would be a bug if that is true, which I am testing after I post this.
I’m also wondering why you would use $modx->user->hasSessionContext($modx->context->get(’key’)), since it always returns true even when no one is logged in.
<?php
return $modx->user->hasSessionContext($modx->context->get('key')) ? 'true' : 'false';
?>
Quote from: BobRay at Feb 05, 2010, 12:31 AMThe only information you can get about logged in users is from your own session...
With the code above, I was writing a sort of "educational" snippet to show users who was currently logged in to which context. It seemed that getAuthenticatedUser(’mgr’) was the logical way to go (and the most intuitively obvious) since hasSessionContext() doesn’t return a user object.
It’s a tough call, IMO. Previewing from the Mgr is such an anomaly that it’s hard to foresee all the side effects of a given strategy.
I may be changing this behavior to load the anonymous user and simply attach the mgr user permissions to it if logged into the mgr. This may be a better solution.

Quote from: BobRay at Feb 05, 2010, 12:31 AMThat would be a bug if that is true, which I am testing after I post this.
I’m also wondering why you would use $modx->user->hasSessionContext($modx->context->get(’key’)), since it always returns true even when no one is logged in.
$isAuthenticated = $modx->user->hasSessionContext($modx->context->get('key'));
return 'Authenticated: ' . $isAuthenticated? 'Yes' : 'No'; // always returns 'Yes'
return 'Authenticated: ' . ($isAuthenticated? 'Yes' : 'No');