on my 0.9.5 setup, $modx->getLoginUserID() and $modx->getLoginUserName() only work on private web pages. if i am logged in, but view public pages, modx doesn’t recognise that i’m logged in.
also, sessions aren’t being destroyed properly on log out. i’ve created 2 user groups. if i log in as a member of one group, log out, and then log in as a member of the second, i am not allowed to access documents belonging only to the second user group.
has anyone else found these issues and has anyone found fixes?
thanks
ok, this isn’t quite what’s happening. about the only common thing i can find with modx having trouble working out when a user is logged in is on pages that have more than 4 parents. i’ll investigate further. no idea why it’s doing what it’s doing. if anyone wants to check out the problem, pm me for details of where to find the site.
i’ve found out what’s happening. if i log in, and view pages in subdirectories, cookies are sent to the browser with a path set to whatever the path of the page i’m looking at is. if i then log out, and log back in at a later date, i get a different session id. if the old session id has expired (or i’ve logged out), but the cookie for a particular path is still in the browser, the browser sends that id to modx. modx then checks whether i’m logged in against the value of the old session id. since that has expired, modx thinks i’m logged out.
i think that what should happen is that for every request, if i’m logged in i should be sent a cookie with the current session id in. it seems that if modx (falsely) detects that i’m not logged in it won’t then set any cookies anywhere from that point on.
i think something else contributing to this is that cookies marked to be valid until the end of the current session are persisting even after i close my browser because i’m using firefox’s feature to restore open tabs when i restart it. this means that it doesn’t delete cookies that were only meant to last until the end of a session. perhaps setting an expiry date on cookies would be better. i’m using ff 2.0 on linux.
a solution for this problem is to only ever set one cookie for the domain root.
change line 50 of /manager/includes/config.inc.php from
setcookie(session_name(), session_id(), $cookieExpiration);
to:
setcookie(session_name(), session_id(), $cookieExpiration, ’/’);