We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 8592
    • 22 Posts
    I need to make my own login form for web users (maybe an snippet). All of my needs are as follow:


    • After getting the username and password from the user, what table of database should I look for for the exact data? And which fields?
    • After checking the username and password with the corresponding fields in the table, having the user entered correct username and password, what should I do to finalize the login process? Which values should be set in the session?
    • Is there any API to do this for me?

    Regards,
      I love computer programming...
      • 26435
      • 1,193 Posts
      Hi there esun7b.

      I have a nearly complete rewrite of the WebLogin snippet. Should be ready later today... at least by monday. It allows specifying your own form in a chunk and another chunk for a block of content to be displayed on successful login. It will also handle the Taconite framework for dynamically updating the DOM if you want to log your users in asynchronously (AJAX Login).

      If that does not sound interesting to you, you can find the entire login process from the original weblogin snippet in "/assets/snippets/weblogin/weblogin.processor.php".

      You sound personally vested in this process, so I might just send you a PM with an attachment of what I have so far. Maybe we can collab on it. The original weblogin snippet is showing it’s age... procedurally written... inline styles and scripts. That’s why I started rewriting it, to get it back in shape with the MODx philosophy.

      -sD-
      Dr. Scotty Delicious, Scientist.
        Husband, Father, Brother, Son, Programmer, Atheist, Nurse, Friend, Lover, Fighter.
        All of the above... in no specific order.


        I send pointless little messages
        • 8592
        • 22 Posts
        Oh man!

        I actually wanted to Ajaxify the weblogin snippet with Taconite! laugh
        I’m waiting for your weblogin and I’m interested to work on it! wink

        But another thing I want to know about and want to make a good snippet for, is the same story about registration!
        Please explain your work for me, I’m an expert in PHP and somehow expert in Ajax, But very novice in MODx!!! But I’ve realized that MODx worth to work on! smiley
          I love computer programming...
          • 26435
          • 1,193 Posts
          Quote from: ehsun7b at Aug 04, 2007, 06:46 AM

          Oh man!

          I actually wanted to Ajaxify the weblogin snippet with Taconite! laugh
          I’m waiting for your weblogin and I’m interested to work on it! wink
          I think it is going to be really awesome wink
          Quote from: ehsun7b at Aug 04, 2007, 06:46 AM

          But another thing I want to know about and want to make a good snippet for, is the same story about registration!
          Please explain your work for me, I’m an expert in PHP and somehow expert in Ajax, But very novice in MODx!!! But I’ve realized that MODx worth to work on! smiley
          I have not even begun work on user registration yet, but once I get login/logout/login_reminder functions working perfectly I am for sure going to add registration support. The creator of the original weblogin snippet, Raymond Irving, is a brilliant developer. Unfortunately this code was written in 2004 and, like I mentioned earlier, contains a lot of inline styles and scripts and does not easily lend itself to the use of custom template chunks unless you really know what you are doing. My aim is to make this easy for the user who is well versed in (X)HTML but shy of PHP. With your background and my MODx knowledge I think you will be a tremendous resource on this project.

          *** EDIT ***
          I have attached the README documentation that I have put together so far, in case anyone is curious.

          -sD-
          Dr. Scotty Delicious, Scientist.
            Husband, Father, Brother, Son, Programmer, Atheist, Nurse, Friend, Lover, Fighter.
            All of the above... in no specific order.


            I send pointless little messages
            • 33337
            • 3,975 Posts
            Nice news Scotty!

            WebLoginPE -> PE = Pirate Edition ? tongue

            I like the optional placeholders for account information..., may be add a [+changepassword+] and a parameter which can be assigned a MODx doc id with change password snippet?
              Zaigham R - MODX Professional | Skype | Email | Twitter

              Digging the interwebs for #MODX gems and bringing it to you. modx.link
              • 26435
              • 1,193 Posts
              Quote from: zi at Aug 04, 2007, 09:26 AM

              Nice news Scotty!

              WebLoginPE -> PE = Pirate Edition ? tongue

              I like the optional placeholders for account information..., may be add a [+changepassword+] and a parameter which can be assigned a MODx doc id with change password snippet?

              PE = PIRATE EDITION!!!!
              I love it Zi!
              It originally stood for "Progressively Enhanced" as it outputs pure, strict XHTML code (or whatever the user provides in a chunk) that can be progressively enhanced by CSS and JavaScript but works perfectly if either are not supported or disabled, but scratch that. PE now stands for "Pirate Edition"!

              Also, I like the idea for the additional placeholder. I will add it in.

              -sD-
              Dr. Scotty Delicious, Scientist.
                Husband, Father, Brother, Son, Programmer, Atheist, Nurse, Friend, Lover, Fighter.
                All of the above... in no specific order.


                I send pointless little messages
                • 8592
                • 22 Posts
                I have not even begun work on user registration yet, but once I get login/logout/login_reminder functions working perfectly I am for sure going to add registration support. The creator of the original weblogin snippet, Raymond Irving, is a brilliant developer. Unfortunately this code was written in 2004 and, like I mentioned earlier, contains a lot of inline styles and scripts and does not easily lend itself to the use of custom template chunks unless you really know what you are doing. My aim is to make this easy for the user who is well versed in (X)HTML but shy of PHP. With your background and my MODx knowledge I think you will be a tremendous resource on this project.

                *** EDIT ***
                I have attached the README documentation that I have put together so far, in case anyone is curious.

                -sD-
                Dr. Scotty Delicious, Scientist.

                Very nice Scotty!
                I’m really interested in the project! and may develop most of the Registration (Ajax version) after reviewing your weblogin (Ajax version).
                BTW why don’t we/they extend login APIs, for example there is such a API:

                boolean changeWebUserPassword($oldPwd, $newPwd);

                So, we can have such API for login too, like this:

                boolean/int loginWebUserPassword($username, $password);

                What is your idea? huh


                my email: ehsun7b at gmail dot com
                  I love computer programming...
                  • 26435
                  • 1,193 Posts
                  Well, as far as the MODx API goes, it generally covers the core functions available to get information from the Document Parser. The process of logging in a user consists of many functions in both the MODx API and the MODx DBAPI. to start, you have to take the username provided in the form and query the database to see if that user exists in the web_users table and that that web_users ’id’ matches the internal key in the web_user_attributes table. Next would be a good time to fire of a OnBeforeWebLogin call. After that check to see if the user is blocked. Then grab the password from that query and check it against the md5 of the password that the user passed in the form. if it isn’t correct, make another DB query and increment the failedlogin count. if it now is greater than that allowed in $modx->config[]....

                  You get the idea that this is beyond the realm of a simple API call and is a full blown snippet that takes advantage of the MODx API and DBAPI quite extensively.

                  What I have done with the WebLoginPE class that I have written is to make it accessible and easily extendable.
                  A login is as simple as
                  $wlpe = new WebLoginPE($modx); // Passing the $modx object as a variable is the quickest way to ensure access to it.
                  $wlpe->login($username, $password, $remeberMe);


                  I used PHPDoc to create documentation for my Class in HTML format to make it easy to read and understand. Anyway, the goal is to have a easy, object oriented kit for ALL web user related functions, all templateable with chunks, and all progressively enhanced with CSS and JavaScript, but perfectly functional without either or both. I can’t stand when stuff doesn’t work because I have JS turned off on a site I don’t know I can trust yet.

                  My declaration of intention in the areas to be coverd are:

                  • Login
                  • Logout
                  • Password reminder
                  • Show password hint (new)
                  • Change password
                  • Register new account
                  • more...?

                  I would like all of these items to have the ability to be processed asynchronously as well.

                  -sD-
                  Dr. Scotty Delicious
                    Husband, Father, Brother, Son, Programmer, Atheist, Nurse, Friend, Lover, Fighter.
                    All of the above... in no specific order.


                    I send pointless little messages
                    • 8592
                    • 22 Posts
                    Yeah I see,
                    These are exactly my interested areas as well. Which of them are ready now? Do you want me to work on the others which are not ready? cool (In parallel with your development)

                    Where can I find good information about document events like OnBeforeWebLogin? And the proper time to invoke each of them? huh
                      I love computer programming...
                      • 8592
                      • 22 Posts

                      to start, you have to take the username provided in the form and query the database to see if that user exists in the web_users table and that that web_users ’id’ matches the internal key in the web_user_attributes table. Next would be a good time to fire of a OnBeforeWebLogin call. After that check to see if the user is blocked. Then grab the password from that query and check it against the md5 of the password that the user passed in the form. if it isn’t correct, make another DB query and increment the failedlogin count. if it now is greater than that allowed in $modx->config[]....

                      Can you explain the rest of the process in details??? undecided
                        I love computer programming...