We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 10449
    • 956 Posts
    If I write / install a custom module in the MODx manager, what’s the best way to make sure only manager-admins can access those pages?

    If all functionality happens in one single php page, this is a no-brainer. But what if I have several pages* in assets/modules/my-custom-module/ that I call from the iframe? If someone accidentally "finds" those URLs (obfuscation != security)?

    I could use .htaccess protection for that special modules-folder, but having to login twice defeats the whole idea of "one cms that contains all I need". Is there maybe a way I can reuse the same session? Or should I somehow "sync" manager-session-data + cookies?

    * e.g. a sub-navigation with options in frame 1 and content-page in frame 2
    or separate forms and form-processing pages
      • 7923
      • 4,213 Posts
      use this at the top of your php pages:

      <?php
      if(IN_MANAGER_MODE!="true") die("Please use the MODx Content Manager instead of accessing this file directly.");
      ?>
      


        "He can have a lollipop any time he wants to. That's what it means to be a programmer."
        • 22303 MODX Staff
        • 10,725 Posts
        Yeah, unfortunately, it’s very easy to include the file then after quickly defining that constant, IN_MANAGER_MODE. Reliance on the $modx instance being available (i.e. the request went through manager/index.php as it should) should be a much better test, and you could then programmatically add permission checking to the code (i.e. check the user role or specific permissions, user groups, etc.). Just make sure your pages won’t respond with anything meaningful if not used as expected.
          • 10449
          • 956 Posts
          Thanks. In addition to doze’s line, I’m now using:

          if (realpath(__FILE__) == realpath($_SERVER['SCRIPT_FILENAME'])) {
          	exit();
          }
          


          I’m probably gonna add 1-2 permission checks via sessions. And I’ll re-code the whole module to use switch() + always go via the manager-file instead of just including files in assets/modules/mymodule/