Quote from: jrotering at Jun 01, 2010, 11:11 AM
I would win friends and influence people if I could figure out how to authenticate Manager users against our LDAP rather than against the modx_users table. Any tips at where to begin with this?
There are three events you can attach plugins to for this. OnUserNotFound, OnWebAuthenticate, OnManagerAuthenticate. Use OnUserNotFound to lookup the user in the directory and collect their information. Then On*Authenticate you can check the password provided against the LDAP directory. If authentication is successful, you can then add the user to MODx (leaving the password blank) and set the output of the plugin to true so the login processor can then skip local authentication. Otherwise, you set the output to false, indicating authentication failed.
You can take it further and extend modUser to customize the behavior of such users, store and manage external data you retrieve from the LDAP source, and much more. I’m in the process of documenting this process in general based on several different external user sources I’ve done this with (Crowd, RPXNow, etc.) and will have more detail for you soon. Feel free to continue to ask questions in this thread in the meantime.
FWIW, here is an
example plugin and extended user class from our Crowd integration for reference until I can finish the documentation/tutorial.