-
☆ A M B ☆
- 2 Posts
Is there anyone has solution for preventing direct access to a content, which is going to be ajaxed load from other template (through jQuery.load())?
I’m using a template with including a snippet to redirect to deny-access-page, this will help on preventing some direct access to a page but a snippet to get its content. But then how can I protect that snippet, or do I need to write the seperate script?
Assuming that the document is only available to certain user groups, you can call the user object’s isMember() method before referring them to the page:
<?php
/* Is user a member of the Editors user group? */
$isEditor = $modx->user->isMember('Editors');
/* Is user a member of one of these groups */
$groups = array(
'Editors',
'CopyEditors',
'Proofers',
);
$isEmployee = $modx->user->isMember($groups);
-
☆ A M B ☆
- 2 Posts
Hi Bob,
I wonder that if the resource is for public, can I protect it through direct access?
Quote from: xgenvn at Aug 08, 2011, 08:24 AM
Hi Bob,
I wonder that if the resource is for public, can I protect it through direct access?
I’m sorry, I don’t understand the concept of protecting a public document. Do you mean that anyone can see it in the front end, but you want to hide it in the Manager?
-
☆ A M B ☆
- 2 Posts
Um, maybe I’ve been making it too complex and confused to you.
I have an A page, which has jQuery.load(B page).
A page of course has its well-designed template, and B page is blank template.
My problem is, I dont want the B page to be directly access but jQuery.load() can.
Do I need to add a DEFINE snippet in A page, then check in B page for that constant value before doing output the result?
I’m still not sure I’m understanding your problem, but if the B page is unpublished, there shouldn’t be any way for a site visitor to access it (unless you pull it in yourself using code -- but you can control how and when that happens).
If that still doesn’t answer your questions, can you describe exactly what’s happening now that you don’t want to happen?
-
☆ A M B ☆
- 2 Posts
I just want to know how can a document (published) be protected through it’s actual address but not specific referer. I just want it to be loaded from jQuery.load() at A page, and when we visit B page actual address, it wont show up or redirect us to somewhere. Is there any way to achieve this (or do I really need to do this)?
Sorry, still not following you. If you visit the B page address, there’s no way that will make the A page load the B page unless the B page contains a redirect to the A page.
If you don’t want the B page to be accessed directly, why publish it?
-
☆ A M B ☆
- 2 Posts
Sorry, for funny approach, I want A page as the only way to access and look into B page content, not directly to it. That’s something you wanna see, but you cant because you have no tool or certain permission to do that. (Just like a telescope we use to identify the further object, here that’s object is B page, and a telescope that’s my A page)...
Right, but if the B page is not published (and I can’t think of any reason why it should be), the only way to access it is through the A page.
EZfaq does this. The content you see on an FAQ page (e.g,
http://bobsguides.com/modx-newbie-faq.html is in another, unpublished, resource. The only way to access the content is through the page with the EZfaq snippet on it.