Well, as far as the MODx API goes, it generally covers the core functions available to get information from the Document Parser. The process of logging in a user consists of many functions in both the MODx API and the MODx DBAPI. to start, you have to take the username provided in the form and query the database to see if that user exists in the web_users table and that that web_users ’id’ matches the internal key in the web_user_attributes table. Next would be a good time to fire of a OnBeforeWebLogin call. After that check to see if the user is blocked. Then grab the password from that query and check it against the md5 of the password that the user passed in the form. if it isn’t correct, make another DB query and increment the failedlogin count. if it now is greater than that allowed in $modx->config[]....
You get the idea that this is beyond the realm of a simple API call and is a full blown snippet that takes advantage of the MODx API and DBAPI quite extensively.
What I have done with the WebLoginPE class that I have written is to make it accessible and easily extendable.
A login is as simple as
$wlpe = new WebLoginPE($modx); // Passing the $modx object as a variable is the quickest way to ensure access to it.
$wlpe->login($username, $password, $remeberMe);
I used PHPDoc to create documentation for my Class in HTML format to make it easy to read and understand. Anyway, the goal is to have a easy, object oriented kit for ALL web user related functions, all templateable with chunks, and all progressively enhanced with CSS and JavaScript, but perfectly functional without either or both. I can’t stand when stuff doesn’t work because I have JS turned off on a site I don’t know I can trust yet.
My declaration of intention in the areas to be coverd are:
- Login
- Logout
- Password reminder
- Show password hint (new)
- Change password
- Register new account
- more...?
I would like all of these items to have the ability to be processed asynchronously as well.
-sD-
Dr. Scotty Delicious