Hello @ all,
I am modifying a bit the WebLogin snippet to get the Javascript out of it and to add some more things. However I also want to change some functionality and sure I want to lear how everything is working.
I got over this piece of code and I don’t know why it’s good for in "
weblogin.processor.inc.php":
<?php
...
// invoke OnWebAuthentication event
$rt = $modx->invokeEvent("OnWebAuthentication",
array(
"userid" => $internalKey,
"username" => $username,
"userpassword" => $givenPassword,
"savedpassword" => $dbasePassword,
"rememberme" => $rememberme
));
// check if plugin authenticated the user
if (!$rt||(is_array($rt) && !in_array(TRUE,$rt))) {
// check user password - local authentication
if($dbasePassword != md5($givenPassword)) {
$output = webLoginAlert("Incorrect username or password entered!");
$newloginerror = 1;
}
}
...
?>
I understand an event is invoked, but then the following check if a plugin authenticates a user is the one I don’t understand. What type should the variable
$rt be of after the event is invoked? An array, boolean, etc? And why do we check here if the user password is correct and not at the beginning in the SQL query (SELECT ... WHRE `username` = ’this’ and `password` = ’that’)?
Thank you very much!
Boby