If I write / install a custom module in the MODx manager, what’s the best way to make sure only manager-admins can access those pages?
If all functionality happens in one single php page, this is a no-brainer. But what if I have several pages* in assets/modules/my-custom-module/ that I call from the iframe? If someone accidentally "finds" those URLs (obfuscation != security)?
I could use .htaccess protection for that special modules-folder, but having to login twice defeats the whole idea of "one cms that contains all I need". Is there maybe a way I can reuse the same session? Or should I somehow "sync" manager-session-data + cookies?
* e.g. a sub-navigation with options in frame 1 and content-page in frame 2
or separate forms and form-processing pages
use this at the top of your php pages:
<?php
if(IN_MANAGER_MODE!="true") die("Please use the MODx Content Manager instead of accessing this file directly.");
?>
"He can have a lollipop any time he wants to. That's what it means to be a programmer."
-
MODX Staff
- 10,725 Posts
Yeah, unfortunately, it’s very easy to include the file then after quickly defining that constant, IN_MANAGER_MODE. Reliance on the $modx instance being available (i.e. the request went through manager/index.php as it should) should be a much better test, and you could then programmatically add permission checking to the code (i.e. check the user role or specific permissions, user groups, etc.). Just make sure your pages won’t respond with anything meaningful if not used as expected.