We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 7923
    • 4,213 Posts
    That’s good to know!

    Be sure to check out the upcoming version of MODx called Revolution.


      "He can have a lollipop any time he wants to. That's what it means to be a programmer."
      • 23927
      • 1 Posts
      So I am new to MODx, and having LDAP/Active Directory would be perfect for my environment. I just saw this post, and thought I would add my two cents. I know that puki1400 said that he was using the IMAP snippet as a guide, and the one item in the code he provided that jumps out at me, is that it is still using the IMAP port to authenticate and LDAP uses port 389. I haven’t tested this theory out yet, but I will post my results tomorrow.

      Cheers!
      Eric
        • 29774
        • 386 Posts
        There is an extension for Expression Engine that provides LDAP authentication. Looking at the code it looks like it could be ported to use the equivalent modx system events with a plugin without too much trouble.

        In EE the hooks used are login_authenticate_start and member_member_login_start; the equivalent events in modx are:
        OnManagerAuthentication and OnWebAuthentication.

        http://code.google.com/p/ee-ldap-extension/


          Snippets: GoogleMap | FileDetails | Related Plugin: SSL
          • 3749
          • 24,544 Posts
          Quote from: therebechips at Oct 14, 2009, 04:51 AM

          There is an extension for Expression Engine that provides LDAP authentication. Looking at the code it looks like it could be ported to use the equivalent modx system events with a plugin without too much trouble.

          In EE the hooks used are login_authenticate_start and member_member_login_start; the equivalent events in modx are:
          OnManagerAuthentication and OnWebAuthentication.

          http://code.google.com/p/ee-ldap-extension/

          Note that those two MODx events only fire *after* a user has been authenticated by logging in normally. If you want to use the user’s LDAP credentials to log them in and bypass the MODx login, they won’t help.

          OnBeforeManagerLogin and OnBeforeWebLogin fire just before any authentication attempt. Doing the LDAP authentication here won’t stop the normal authentication that comes next, however, so you might want to check to see if the MODx user exists in your plugin and, if not, create them at that point so they’ll pass the following authentication.

          Hope this makes sense. smiley

            Did I help you? Buy me a beer
            Get my Book: MODX:The Official Guide
            MODX info for everyone: http://bobsguides.com/modx.html
            My MODX Extras
            Bob's Guides is now hosted at A2 MODX Hosting
            • 18726
            • 4 Posts
            Just a side note, I threw together a quickie LDAP Authentication module and made a thread for it here: http://modxcms.com/forums/index.php?topic=38967.0 It functions in MODx 1.1.

            I’m trying out revolution now but am having a hard time porting the plugin - or finding any information that will help me out. I can see the MODx framework stuffing username/password into $loginAttributes, then passing that to invokeEvent(), which then takes that as a variable named $params and from there .... I’m lost. I don’t know how to get at those parameters from inside the plugin in revolution.
              • 3749
              • 24,544 Posts
              Quote from: mausmalone at Oct 29, 2009, 03:03 PM

              Just a side note, I threw together a quickie LDAP Authentication module and made a thread for it here: http://modxcms.com/forums/index.php?topic=38967.0 It functions in MODx 1.1.

              I’m trying out revolution now but am having a hard time porting the plugin - or finding any information that will help me out. I can see the MODx framework stuffing username/password into $loginAttributes, then passing that to invokeEvent(), which then takes that as a variable named $params and from there .... I’m lost. I don’t know how to get at those parameters from inside the plugin in revolution.

              The variables available in OnManagerAuthentication are:

              $user (the user object) -- use $user->get(’fieldname’) for the member variables.
              $password (I think this is the encrypted password, not what the user enters - not sure).
              $rememberme

              Note, though that OnManagerAuthentication fires after the user has been found and authenticated in the MODx db and is determined to be headed for the Manager, but before the user has been determined to be authorized to access the Manager context.

              So I think you might want OnBeforeManagerLogin instead, which comes before any attempt to authenticate the user, but after the login form is submitted.

              Variables available in OnBeforeManagerLogin:

              $username: string entered by user
              $password: string entered by user
              $attributes: array -- $rememberme, $logincontext( =’mgr’’).

              I think returning false there will prevent the regular MODx authentication, but I’m not sure.

              You may have trouble on success, though, if the user isn’t in the MODx DB and authorized for the ’mgr’ context. Not sure about that either.

              Hope this helps. smiley


                Did I help you? Buy me a beer
                Get my Book: MODX:The Official Guide
                MODX info for everyone: http://bobsguides.com/modx.html
                My MODX Extras
                Bob's Guides is now hosted at A2 MODX Hosting