We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 11927
    • 105 Posts
    I’m trying to write a plugin that will grab the New password of a newly created or updated user and save it into another database table for a different section of our website that needs the same username and password. So far the only system events I’m checking for are OnUserBeforeSave and OnUserSave.

    I’ve looked into the core files and think I found what I need, but I don’t know how to get access to the variable that holds the new password.

    This is the variable in the core that I am trying to access:
    $scriptProperties[’specifiedpassword’]

    How would I get access the variable in a plugin and in which system event (if I need to check a different system event)?
      You may or may not want to use the code I write. It's probably all against the syntax rules of php and MODx. smiley

      Carpet Cleaning
      • 11927
      • 105 Posts
      How do I access the $scriptProperties array? This may be the best way to get the information, but not sure.


      I did find a way to get the information I need, but that is without MODx sanitizing it for me.
      $newPassword = $_POST['specifiedpassword'];
      $checkPassword = $_POST['confirmpassword'];



      How do I get the $_POST information after MODx checks it and sanitizes it? I found this, but I think my code is off because it’s not working (because all my plugin does is make the user save pop-up loop through infinitly).
      $my_request = $modx->getObject('modRequest');
      $newPassword = $my_request->getParameters('specifiedpassword', 'POST');
      $checkPassword = $my_request->getParameters('confirmpassword', 'POST');
        You may or may not want to use the code I write. It's probably all against the syntax rules of php and MODx. smiley

        Carpet Cleaning
        • 3749
        • 24,544 Posts
        I don’t think you need most of that.

        In OnSaveUser, you should be able to test for a new user and get the password hash from the $user object and OnUserChangePassword will fire if an existing user changes passwords. Be sure to connect the plugin to both OnUserSave and OnUserChangePassword.

        <?php
        
        $update = false;
        
        switch ($modx->event->name) {
           case 'OnUserSave':
              if ($mode == modSystemEvent::MODE_NEW) {
                 $update = true;
                 break;
        
           case 'OnUserChangePassword':
                $update = true;
                break;
         }  
        
        if ($update) {
             $pwd = $user->get('password');
            /* do your stuff here -- $pwd will be set */
        }
        


        Note that what’s stored in the password field is not the password, but a hash of the password.

        If you’re using Revolution, you might also want to pay attention to $user->get(’hash_class’), which will be either hashing.modMD5 or hashing.modPDKBF2. As of 2.1, MODX uses PDKBF2. For converted sites from previous versions, however, existing users have MD5 hashes.
          Did I help you? Buy me a beer
          Get my Book: MODX:The Official Guide
          MODX info for everyone: http://bobsguides.com/modx.html
          My MODX Extras
          Bob's Guides is now hosted at A2 MODX Hosting
          • 11927
          • 105 Posts
          BobRay,
          Thank you for your suggestion. I will eventually modify my plugin for OnUserChangePassword as well.

          But the thing is, I need to get the password that they entered. The reason being that I need to store it for another program that hashes the password a different way (don’t worry I’m not going to store the raw password). But since I can’t unhash md5 passwords, I need to get the raw password.

          I figured out how to get the POST data.
          $modx->request->getParameters('FIELD_NAME', 'POST')


          So if the user (in the manager) enters a password, I can get it. But if the user has modx create a password, I can’t. Does some one know how to get the variable $newPassword - in file /core/model/modx/processors/security/user/_validation.php (it’s probably not possible for security reasons)?
            You may or may not want to use the code I write. It&#39;s probably all against the syntax rules of php and MODx. smiley

            Carpet Cleaning
            • 11927
            • 105 Posts
            Should OnUserChangePassword be firing when someone in the manager changes a password for a user?

            As far as I could tell, it’s not.

            Revo 2.0.7
              You may or may not want to use the code I write. It&#39;s probably all against the syntax rules of php and MODx. smiley

              Carpet Cleaning
              • 3749
              • 24,544 Posts
              Quote from: heavensbest at Apr 22, 2011, 05:33 PM

              Should OnUserChangePassword be firing when someone in the manager changes a password for a user?

              As far as I could tell, it’s not.

              Revo 2.0.7

              I don’t think it does, but I’m not sure.

              For getting the user-entered password, you might take a look at OpenGeek’s pbkdf2Convert plugin. It catches the password when the user logs in, which might be what you’d have to do. Wait until the user actually logs in, then add them to the other DB if they’re not there already. At that point, you have both the user name and the current password. If you check every time a user logs in, you should be covered.
                Did I help you? Buy me a beer
                Get my Book: MODX:The Official Guide
                MODX info for everyone: http://bobsguides.com/modx.html
                My MODX Extras
                Bob's Guides is now hosted at A2 MODX Hosting
                • 11927
                • 105 Posts
                BobRay,
                Thanks again. That lead me in the right direction. I’ll have to wait until I install 2.1 to fully implement my plugin because the method ’passwordMatches()’ is not a part of 2.0.7.
                  You may or may not want to use the code I write. It&#39;s probably all against the syntax rules of php and MODx. smiley

                  Carpet Cleaning
                  • 3749
                  • 24,544 Posts
                  Quote from: heavensbest at Apr 25, 2011, 01:41 PM

                  BobRay,
                  Thanks again. That lead me in the right direction. I’ll have to wait until I install 2.1 to fully implement my plugin because the method ’passwordMatches()’ is not a part of 2.0.7.

                  2.0.7 had some problems with cache corruption, so upgrade sooner rather than later. wink

                  When weird stuff happens in 2.0.7, manually delete all the files in the core/cache directory.
                    Did I help you? Buy me a beer
                    Get my Book: MODX:The Official Guide
                    MODX info for everyone: http://bobsguides.com/modx.html
                    My MODX Extras
                    Bob's Guides is now hosted at A2 MODX Hosting
                    • 11927
                    • 105 Posts
                    Good to know. I was trying to hold out for 2.1 pl, but it probably would be best to upgrade to 2.0.8 now.
                      You may or may not want to use the code I write. It&#39;s probably all against the syntax rules of php and MODx. smiley

                      Carpet Cleaning