Your guide is very good Sottwell. Anyway, I’ll write an article for the wiki. Something more like a step by step guide, more simple and maybe more exhaustive. I’ll put a link to your guide as a place to get more information, it’s ok?.
Just 3 things.
to retrieve you module id this line I’ve found in Quick Edit module seems to work
$id = (!empty($_REQUEST["id"])) ? (int)$_REQUEST["id"] : $yourModuleId;
$youModuleId it’s an optional variable which value can be set through module parameters and it’s necessary just if the automatic method doesn’t work. It has always worked for me until now, anyway.
To get back to module "init" page, I’ve also found another more simple way.
Starting from the point that we have a module manager page where other files are included or (ajax) called and we use a form to handle action states, then we should use a hidden input where to write the actual state. Our code should be:
<form method="post id="state_mantainer"><input type="hidden" id="statevalue" value="statevalue" /></form>
No other informations for the form tag are necessary.
After our module has completed the part of a specific state handler we should just call a js inline script with
<script>
function goback(){
document.getElementById('statevalue').value = "back"; //not handled
setTimeout(function(){document.getElementById('state_mantainer').submit()},'3000');
}
</script>
while showing to the user something like "Operation has completed its trip with a comfortable landing

You’ll be redirect to the admin panel within 3 seconds. Have a nice day".
About Ajax. Prototype is great! But to use ajax inside modx you had to write a parser to ensure your site against possible exploit usign your server pages (for server pages I mean pages that serve Ajax calls). As we know, modx has not only code, but snippet, tvs etc etc so the parser should erase all possible injections from the calls.
And... if your server pages just ask to the site db the value of a certain tv for example, it’s not so dungerous, if instead they handle the user os session tables for some reason, who writes the code has to be REALLY careful on what she/he’s doing.
For this reasons I like to say that Modx has the great advantage to include prototype (if you want) but need also a standard api or method to write code that play with ajax leaving modx in a high level of security.
I’ve seen Ajax Search work. Great job! I think that index-ajax.php it has to be a standard or part of the modx application framework. And someone has to write a clear step by step "Howto write secure ajax application with ModxCMS (both module or snippet ; frontend - backend)" illustrating the ajax-search snippet way.
But also if I really appreciate ajax-search works, I’m wondering if I have to do an ajax application that need to know who is doing the request, the only way to do it, is to include almost all of what index.php or /manager/index.php includes, get a (what?) sessionid and/or userid and/or something else through POST or GET and check if i get a correspondence in the site db?
Maybe someone have a better solutions for this, cause I don’t like it that much, a session hijack is at the door. I think the best way is to do an hand shaking between the (ajax) caller and the server, but I also think that it should be better to outline a standard way to do that making it part (with some script or api) of modx. Or outline a secure method to implement it.
Anyway, I’ll change my modules interfaces and meanwhile write the article for the wiki, without the inclusion of how to do with ajax. I think that someone else could do it better than me.