We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 18409
    • 54 Posts
    Apologies if I’ve missed something obvious in API docs, but I can’t see how to do this.

    If someone is logged into the manager, and then opens up a new browser tab to the "public" website, I want to be able to detect in a snippet that they are logged in, and what groups they are a member of. i.e. I want to display some different content to people that are logged into the manager than anonymous people.

    Is this possible?

    If I do:
    $username = $modx->getLoginUserName();
    I just get false back.
      • 18409
      • 54 Posts
      I worked it out after find the page at http://bobsguides.com/revolution-permissions.html:

      $username = $modx->getLoginUserName(’mgr’);
      or
      $user = $modx->getUser(’mgr’);

      does the job...might take me a while to understand how all this user/security stuff works....!
        • 3749
        • 24,544 Posts
        I’m still working on it myself. wink

        That’s a funny situation. Usually, users are considered to be in one context or the other -- not both. If you find something that works, it’s probably not guaranteed to work in the future and Manager users previewing the front end have some rights to documents they wouldn’t see if they were viewing the front end in another browser.

        I’m not at all sure about this, but you might be better off with a plugin that would log them into the front-end context when they log in to the Manager. That way, they’d have the same rights no matter how they logged in and you wouldn’t have to worry about upgrades breaking things.
          Did I help you? Buy me a beer
          Get my Book: MODX:The Official Guide
          MODX info for everyone: http://bobsguides.com/modx.html
          My MODX Extras
          Bob's Guides is now hosted at A2 MODX Hosting
          • 18409
          • 54 Posts
          OK, I see. Essentially I have a small site where people are either just browsing, so no credentials, or a few people have permission to access the manager. It’s all or nothing.

          I’m writing a very basic calendar snippet and need it so that when authenticated people view the calender (in the front end) each day has an "add" button on it. Obviously non-auth people don’t see the "add" button. In future I might want people to log into the front end, but not the manager as well.

          The easiest way to do this seemed to be to detect if they were logged into the manager, and because I haven’t get my head around the security model yet (I’m not sure I ever will manage to understand it!) I was trying to keep it as simple as possible.

          If writing a plugin to do that is easy then I’ll do that, it makes sense. I’m trying to get the basics of writing a snippet at the moment!
            • 3749
            • 24,544 Posts
            That sounds like are reasonable approach.

            I haven’t tried it, but this might be a good way to do it:

            $isAuthenticated = $modx->user->hasSessionContext('mgr');


            That would be fairly secure and wouldn’t require a plugin (and would be a lot easier than working out the security details with resource groups and user groups).

            Take a look at the code of the NpEditThisButton snippet that comes with the Revolution version of NewsPublisher: https://github.com/BobRay/newspublisher/blob/dev/core/components/newspublisher/elements/snippets/npeditthisbutton.snippet.php.

            With a little tweaking, I think it would do exactly what you want. It puts a button on the page that launches NewsPublisher for that page. It doesn’t it by forwarding the user to another page with the form action, but it could just as well use $modx->sentRedirect() or $modx->runSnippet(). The button is hidden from people without certain permissions but it could just as well use the code above. It returns an empty string if the user isn’t qualified so the button is invisible.

            You might find the method it uses a little confusing. The Edit button caption is set to "Edit" at the top. If there’s any error, it’s set to an error message instead. At the end, the snippet checks the value against "Edit" and if they match, it returns the button. If they don’t match and debug is on, it still returns the button (which will contain the error message). If debug is off, it returns an empty string.
              Did I help you? Buy me a beer
              Get my Book: MODX:The Official Guide
              MODX info for everyone: http://bobsguides.com/modx.html
              My MODX Extras
              Bob's Guides is now hosted at A2 MODX Hosting