We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 13610
    • 52 Posts
    Hi,

    I have a database that contains over 30,000 users that will be accessing my modx site.

    I have created 3 Web Users in the modx database and was wondering how I would impersonate 1 of those 3 users.

    Lets say my users are called Level1 User, Level2 User and Level3 User.

    I have created a connection to my remote database and built a login functionality that creates a $_SESSION[’UserLevel’] = "Level1"; (Level2 or Level3) depending on the database level for that user.

    How do I expose the Modx-> Class or Session that has the Web Users settings in it and assign it to this user?

    I hope that this makes sense. Any examples or documentation on Security functionality would be helpful.

    I have been examining the code in in the following files:
    manager/includes/
    secure_web_documents.inc.php and accesscontrol.inc.php

    Thanks in advance

    Jason Buck
    http://modx.tsia.com
      Jason Buck
      • 4041
      • 788 Posts
      You might take a look at the files in assets/snippets/weblogin/ folder, those are the ones that ship by default for webuser login and associated functions.
        xforum
        http://frsbuilders.net (under construction) forum for evolution
        • 13610
        • 52 Posts
        Thank you very much for your suggestion.

        I looked at the code for Weblogin in the snippets folder and figured things out.

                 if($record->fields->Access_Level__c == "OtherDatabaseAccessGroup"){
        
         // ==== This user has access to the file structure in Modx
              $username = "ModxUserName"; // Modx user to impersonate
              $password = "somapassword"; // Modx password for that user
             
        
                                    }
        
        // ================================================= HANDLE MODX LOGIN =================================
        if(isset($username)){
        
        $dbase = $modx->dbConfig['dbase'];
        $table_prefix = $modx->dbConfig['table_prefix'];
        
            $sql = "SELECT $dbase.`".$table_prefix."web_users`.*, $dbase.`".$table_prefix."web_user_attributes`.* FROM $dbase.`".$table_prefix."web_users`, $dbase.`".$table_prefix."web_user_attributes` WHERE BINARY $dbase.`".$table_prefix."web_users`.username = '".$username."' and $dbase.`".$table_prefix."web_user_attributes`.internalKey=$dbase.`".$table_prefix."web_users`.id;";
            $ds = $modx->db->query($sql);
            $limit = $modx->db->getRecordCount($ds);
        
            if($limit==0 || $limit>1) {
                $output = webLoginAlert("Incorrect username or password entered!");
                return;
            }
        
            $row = $modx->db->getRow($ds);
        
            $internalKey             = $row['internalKey'];
            $dbasePassword             = $row['password'];
            $failedlogins             = $row['failedlogincount'];
            $blocked                 = $row['blocked'];
            $blockeduntildate        = $row['blockeduntil'];
            $blockedafterdate        = $row['blockedafter'];
            $registeredsessionid    = $row['sessionid'];
            $role                    = $row['role'];
            $lastlogin                = $row['lastlogin'];
            $nrlogins                = $row['logincount'];
            $fullname                = $row['fullname'];
          //  $sessionRegistered         = checkSession();
            $email                     = $row['email'];
        
            // load user settings
            if($internalKey){
                $result = $modx->db->query("SELECT setting_name, setting_value FROM ".$dbase.".`".$table_prefix."web_user_settings` WHERE webuser='$internalKey'");
                while ($row = $modx->fetchRow($result, 'both')) $modx->config[$row[0]] = $row[1];
            }
        
            $_SESSION['webShortname']=$username;
            $_SESSION['webFullname']=$UserFullName ;
            $_SESSION['webEmail']=$_SESSION['USEREMAIL'];
            $_SESSION['webValidated']=1;
            $_SESSION['webInternalKey']=$internalKey;
            $_SESSION['webValid']=base64_encode($password);
            $_SESSION['webUser']=base64_encode($username);
            $_SESSION['webFailedlogins']=$failedlogins;
            $_SESSION['webLastlogin']=$lastlogin;
            $_SESSION['webnrlogins']=$nrlogins;
            $_SESSION['webUserGroupNames'] = ''; // reset user group names
        
           // get user's document groups
            $dg='';$i=0;
            $tblug = $dbase.".`".$table_prefix."web_groups`";
            $tbluga = $dbase.".`".$table_prefix."webgroup_access`";
            $sql = "SELECT uga.documentgroup
                    FROM $tblug ug
                    INNER JOIN $tbluga uga ON uga.webgroup=ug.webgroup
                    WHERE ug.webuser =".$internalKey;
            $ds = $modx->db->query($sql);
            while ($row = $modx->db->getRow($ds,'num')) $dg[$i++]=$row[0];
            $_SESSION['webDocgroups'] = $dg;
        
          
        
        
        } // end if isset modx user
        
        
        
        //==================================================END MODX LOGIN =====================================
        
        
        
        


        Now, I just have to modify the logout functionality to do clear the Modx values and SESSION.

        Thanks,

        Jason Buck
          Jason Buck