Thanks Breezer, will check that out.
I’m actually trying to create a small site to keep track of the usage of some of my custom mootools scripts via a token. I want to see if I can do this using the new modx platform as it seems like it has a ton of options that will be needed, example is the custom user attributes. I can generate the tokens there and match them up to that users details including the domain that the script will be used on, limit the usage with the referring domain name as well so it can’t be simply hotlinked from any other site. I have started writing the script and it’s already working how I want it, using cURL.
I’m simply using vars in the url with the token, userID and domain to check against the database on the site and if any of the options do not match up then the script is not available. I’ll need to think of a way to best encrypt or scramble the information in the url being passed, such as the userID, it’s just simply 1,2 or what ever. But the concept is working. Any ideas what would be the safest method to pass details through the domain url so it can be checked?
Currently the link to a script will look similar to this...
http://www.domain.co.uk/scrollerscript.js?domain=mysite.co.uk&token=wEJASwadrayAPH5dr8ratu&user=1
The scrollerscript.js page is a blank modx javascript document with the snippet that checks the url information and matches it against the user_attributes table in modx via cURL. I’m not sure which is the best way to initiate the query as I don’t know REV at all so using user=1 knows to check the token and the domain against that users information. How safe this is, I don’t know but if I can somehow make this a little more secure then any ideas would be great.