We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 24719
    • 194 Posts
    on my 0.9.5 setup, $modx->getLoginUserID() and $modx->getLoginUserName() only work on private web pages. if i am logged in, but view public pages, modx doesn’t recognise that i’m logged in.

    also, sessions aren’t being destroyed properly on log out. i’ve created 2 user groups. if i log in as a member of one group, log out, and then log in as a member of the second, i am not allowed to access documents belonging only to the second user group.

    has anyone else found these issues and has anyone found fixes?

    thanks
      • 27376
      • 576 Posts
      Check out the MODx Bugtacker to see if this has been reported, if not, feel free to report it over there.
        • 24719
        • 194 Posts
        i can’t see it on there. ah, i was hoping someone would say "yeah, this has been fixed already". wink i’ve added it to the bug tracker now
          • 24719
          • 194 Posts
          ok, this isn’t quite what’s happening. about the only common thing i can find with modx having trouble working out when a user is logged in is on pages that have more than 4 parents. i’ll investigate further. no idea why it’s doing what it’s doing. if anyone wants to check out the problem, pm me for details of where to find the site.
            • 24719
            • 194 Posts
            i’ve found out what’s happening. if i log in, and view pages in subdirectories, cookies are sent to the browser with a path set to whatever the path of the page i’m looking at is. if i then log out, and log back in at a later date, i get a different session id. if the old session id has expired (or i’ve logged out), but the cookie for a particular path is still in the browser, the browser sends that id to modx. modx then checks whether i’m logged in against the value of the old session id. since that has expired, modx thinks i’m logged out.

            i think that what should happen is that for every request, if i’m logged in i should be sent a cookie with the current session id in. it seems that if modx (falsely) detects that i’m not logged in it won’t then set any cookies anywhere from that point on.

            i think something else contributing to this is that cookies marked to be valid until the end of the current session are persisting even after i close my browser because i’m using firefox’s feature to restore open tabs when i restart it. this means that it doesn’t delete cookies that were only meant to last until the end of a session. perhaps setting an expiry date on cookies would be better. i’m using ff 2.0 on linux.
              • 27376
              • 576 Posts
                • 24719
                • 194 Posts
                http://modxcms.com/bugs/task/868 is better since the problems aren’t to do with getLoginUserID() or getLoginUserName().
                  • 24719
                  • 194 Posts
                  a solution for this problem is to only ever set one cookie for the domain root.

                  change line 50 of /manager/includes/config.inc.php from

                  setcookie(session_name(), session_id(), $cookieExpiration);

                  to:
                  setcookie(session_name(), session_id(), $cookieExpiration, ’/’);
                    • 22303 MODX Staff
                    • 10,725 Posts
                    Or actually, this would be more accurate, depending on where you installed MODx relative to the web server document root...

                    setcookie(session_name(), session_id(), $cookieExpiration, MODX_BASE_URL);