Hi,
I had a problem when accessing a protected page when not login, i get redirected to login page but after a succesfully login i didn’t get back to the page I requested, instead i stayed at the login page.
I found that line 130 and 145 was commented out in document.parser.class.inc.php and replaced with two other rows that didn’t redirect to the referring page. Is this by accident or any other reason.
// $this->sendRedirect($this->makeUrl($this->config[’unauthorized_page’], ’’, ’&refurl=’ . urlencode($_SERVER[’PHP_SELF’] . ’?’ . $_SERVER[’QUERY_STRING’])), 1);
$this->sendForward($unauthorizedPage, ’HTTP/1.0 401 Unauthorized’);
I checked the current modx-0.9.5.zip (2006-12-05) and it’s comment out there but a look in CVS said that it changed the behaviour between version 1371 and 1411.
Isn’t it supposed to work that way?
/Anders
-
MODX Staff
- 10,725 Posts
ahd71:
Thanks for bringing that to my attention. In fact, the response is now proper; previously it was not responding with the proper 401 response, but rather with a 302 OK redirect. We just need a better way of handling the login back to the requested page now. Typically I do this by forcing users to specific pages upon login via the snippet parameters, but in this case, to mimic the previous behavior, I think we should use a session variable to store the referring page id (and any GET params), then modify the weblogin snippet code to use this to rebuild the requested page URL properly for redirection upon login.
My goal is not to force behavior on any authentication approach someone implements within MODx, and the previous method was a little too obtrusive for me. Using this new approach will both satisfy the needs of the 401 response being forwarded too from the originally requested URL and allow redirection back to the original URL once the user provides the credentials via a WebLogin snippet configuration.
I’ll try and work that up tonight and slip this into the 0.9.5.1 release, which is just waiting on a few cleanups from the migration to mootools v1.0 and removal of scriptaculous and prototype from the default template.
Thankyou for fast respons, and by the way i think MODx is a great framework /Anders