We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 1972
    • 15 Posts
    Hi there,

    I’m fairly new to MODx and need to password protect a section of a site. I’ve searched through the MODx forums and Googled ’modx web login’ but couldn’t find anything useful that lists the steps necessary to implement password protection.

    From what I’ve been able to pick up on, I’ve done the following:

    I. In MODx manager:
    A. I create a document group called ’employee_docs’ under Security > Web Permissions > Document Groups
    B. I assign the folder that I want to protect to this ’employee_docs’ group, ie, I have a container document called ’Employee Area’. I edit its General properties > Access Permissions by assigning it to the ’employee_docs’ group
    C. I create a web group called ’employees’ under Security > Web Permissions > Web User Groups
    D. I create a web user called ’employee’ under Security > Web Users and assign the the user to the ’employees’ web group
    E. In the ’Employee Area’ page, I copy the following WebLogin snippet code into the content field:
    [!WebLogin? &tpl=`FormLogin` &loginhomeid=`29`!]


    where ’29’ is the id of this container page

    F. the FormLogin template/chunk code is copied directly from the MODx sample site chunk:

    <!-- #declare:separator <hr> --> 
    <!-- login form section-->
    <form method="post" name="loginfrm" action="[+action+]"> 
        <input type="hidden" value="[+rememberme+]" name="rememberme" /> 
        <fieldset>
            <h3>Your Login Details</h3>
            <label for="username">User: <input type="text" name="username" id="username" tabindex="1" onkeypress="return webLoginEnter(document.loginfrm.password);" value="[+username+]" /></label>
        	<label for="password">Password: <input type="password" name="password" id="password" tabindex="2" onkeypress="return webLoginEnter(document.loginfrm.cmdweblogin);" value="" /></label>
        	<input type="checkbox" id="checkbox_1" name="checkbox_1" tabindex="3" size="1" value="" [+checkbox+] onclick="webLoginCheckRemember()" /><label for="checkbox_1" class="checkbox">Remember me</label>
        	<input type="submit" value="[+logintext+]" name="cmdweblogin" class="button" />
    	<a href="#" onclick="webLoginShowForm(2);return false;" id="forgotpsswd">Forget Your Password?</a>
    	</fieldset>
    </form>
    <hr>
    <!-- log out hyperlink section -->
    <h4>You're already logged in</h4>
    Do you wish to <a href="[+action+]" class="button">[+logouttext+]</a>?
    <hr>
    <!-- Password reminder form section -->
    <form name="loginreminder" method="post" action="[+action+]">
        <fieldset>
            <h3>It happens to everyone...</h3>
            <input type="hidden" name="txtpwdrem" value="0" />
            <label for="txtwebemail">Enter the email address of your account to reset your password: <input type="text" name="txtwebemail" id="txtwebemail" size="24" /></label>
            <label>To return to the login form, press the cancel button.</label>
        	<input type="submit" value="Submit" name="cmdweblogin" class="button" /> <input type="reset" value="Cancel" name="cmdcancel" onclick="webLoginShowForm(1);" class="button" style="clear:none;display:inline" />
        </fieldset>
    </form>
    



    I thought this might come close to what I need to accomplish, but when I try to access the ’Employee Area’ page, I get the contents of the [{start page}].

    Any clues what I’m missing or can you point me to a good tutorial on how to implement password protection via MODx?

    thanks!

      • 36592
      • 970 Posts
      I suspect you defined your Unauthorized page in the MODx configuration and that page contains another Weblogin snippet call whose &loginhomeid parameter is your site start page id.
        • 1972
        • 15 Posts
        Hi tk fm,

        Thanks for input. You are correct that the unauthorized page points to the same document as the site start page so that is the reason why the start page is displayed when the Employee page is requested. The thing I don’t understand is why doesn’t the login form display instead of the unauthorized page? It is an unauthorized page, but I was hoping the code above would display the login form instead of the redirecting to the unauthorized page.

        thanks!
          • 36592
          • 970 Posts
          Quote from: aragonne at Jun 18, 2008, 12:29 AM

          The thing I don’t understand is why doesn’t the login form display instead of the unauthorized page?
          Your Employee page itself is protected to public user, so your Weblogin snippet call on that page is processed after users are accepted to access to that page.

          So ...

          1. Make a new document ( suppose its id is XX ) and place Weblogin snippet call ( &loginhomeid=`29` ) in it.
          2. In your MODx setting, set the id XX in the unauthorized page setting.
          3. Remove Weblogin snippet call in your Employee container.

          In this case, when you access to the Employee page, you are redirected to the unauthorized page.
          And if you are accepted as authorized webuser with proper ID and Password, you are redirected to the Employee page and see the contents of that page.
            • 1972
            • 15 Posts

            thanks tk fm! that did the trick.

            I have a follow up. I also want to place a ’Logout’ link in the header on every page on the site if the user is logged in. I read in another posting that you can just use the simple call [!WebLogin!] and it will create the ’Logout’ link if the user is already logged in. This works great if the user is logged in. However, if the user is not logged in, the login form is displayed in the header.

            Is there any way I can conditionally check if the user is logged in and if so create the Logout link using [!WebLogin!], otherwise display nothing?

            Thanks!
              • 36592
              • 970 Posts
              I believe you can do it with Personalize snippet which is included MODx defaut install.
                • 4041
                • 788 Posts
                This simple snippet should do the trick, name it whatever you want and place accordingly.
                If they are logged in, it shows the logout link produced by the WebLogin snippet, otherwise it shows nothing.

                <?php
                /*   WebLogoutLink
                
                */
                $output ="";
                if(isset($_SESSION['webValidated'])){
                $output .="[[WebLogin]]";
                }
                return $output;
                ?>
                  xforum
                  http://frsbuilders.net (under construction) forum for evolution
                  • 1972
                  • 15 Posts
                  Thanks for your help everyone. Breezer, I wound up doing something similar to what you suggested. Neat to know from your code that you can actually call a snippet from within a snippet using the [[snippet]] syntax. I wound up using the $modx API but your approach seems easier.

                  <?php
                      /*
                       * Display logout link if user is logged in
                       */
                      $ret_str = ' '; // placeholder if no logout link
                      if ( $modx->userLoggedIn() ) {
                          $ret_str =  $modx->runSnippet("WebLogin",
                                          array(
                                          "logouthomeid" =>  "1" //$modx->config['site_start'])
                                         ,"logouttext"   => "Logout" 
                                          )
                                      );
                      }
                      return $ret_str;
                  ?>