We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 14883 ☆ A M B ☆
    • 450 Posts
    I would win friends and influence people if I could figure out how to authenticate Manager users against our LDAP rather than against the modx_users table. Any tips at where to begin with this?
      • 22303 MODX Staff
      • 10,725 Posts
      Quote from: jrotering at Jun 01, 2010, 11:11 AM

      I would win friends and influence people if I could figure out how to authenticate Manager users against our LDAP rather than against the modx_users table. Any tips at where to begin with this?
      There are three events you can attach plugins to for this. OnUserNotFound, OnWebAuthenticate, OnManagerAuthenticate. Use OnUserNotFound to lookup the user in the directory and collect their information. Then On*Authenticate you can check the password provided against the LDAP directory. If authentication is successful, you can then add the user to MODx (leaving the password blank) and set the output of the plugin to true so the login processor can then skip local authentication. Otherwise, you set the output to false, indicating authentication failed.

      You can take it further and extend modUser to customize the behavior of such users, store and manage external data you retrieve from the LDAP source, and much more. I’m in the process of documenting this process in general based on several different external user sources I’ve done this with (Crowd, RPXNow, etc.) and will have more detail for you soon. Feel free to continue to ask questions in this thread in the meantime.

      FWIW, here is an example plugin and extended user class from our Crowd integration for reference until I can finish the documentation/tutorial.
        • 33983 ☆ A M B ☆
        • 181 Posts
        Here is one: http://modxcms.com/forums/index.php/topic,44833.0.html

        I created a simple Active Directory LDAP login that support SSL, TLS and you can search the directory for info on the user. I used this class as the base: http://adldap.sourceforge.net/ version 3.3.1.

        How to use:
        1. Download and the class file adLDAP.php from: http://adldap.sourceforge.net/ and upload it to this path: assets/components/adLDAP/adLDAP.php.

        2. Create a new plugin and call it LDAP, copy the code from the attached file into the textarea. Read throught the code and change the vars for your system.

        3. Now click on the System Events tab and select OnManagerAuthentication and OnWebAuthentication.

        4. Save it!

        This should work, I am trying to do some more advaced features like auto create and assign a modx user based on AD, but I am not any where near that yet.
          • 5340
          • 1,624 Posts
          Hi jrotering,

          any advances on the manager LDAP authentication? I need to allow manager access via LDAP

          Thanks