We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 1932
    • 137 Posts
    I wanted to pass a specific id to a custom feed page, displaying an individual post + comments. From what I understand, there is currently no way to pass user input such as $_GET to snippets (without modifying the snippet itself). I first tried retrieving $_GET vars using pure PHx modifiers but that currently seems to be beyond its limits.

    .. So I decided to write a little snippet which allows external variables such as $_GET[’varname’], $_POST[’varname’], $_COOKIE[’cookie’], etc. to be set as placeholders for display purposes or for use in another snippet.

    Arguments:


    • $varList, takes a comma separated list of external variables to retrieve. Each variable can have an optional "type"; available types include POST, GET, SERVER, SESSION, COOKIE, and REQUEST. These equate to POST, $_GET[’varname’], $_SERVER[’varname’], . . . where the variable name is the array key.

    • $varTag, is an optional string to append to every placeholder created. For example, a placeholder that would normally be [+varname+] would become [+varname.vartag+]

    Example Call:
    [[GetExtern? &varList=`var1:GET,var2:POST,var3` &varTag=`myinput`]]


    Placeholders set:
    [+var1.myinput+] => $_GET[’var1’]
    [+var2.myinput+] => $_POST[’var2]
    [+var3.myinput+] => $_REQUEST[’var3’]

    Because this snippet gets input directly from the client, there exists the possibility for SQL/code injection if the retrieved placeholders are being passed to other snippets. Whether or not the vulnerabilities exist in the 3rd party snippet will depend on how the parameter is used and/or whether the necessary checking is done. I recommend filtering the input using PHx (example below). Users who are uncomfortable with PHP and CGI security should probably not use this snippet.

    [[GetExtern]]

    <?php
    $varList = trim($varList);
    	// Comma separated list of variables to retrieve
    	// In the format VARNAME:REQTYPE
    	// REQTYPE is optional can be: POST, GET, SERVER, SESSION, COOKIE, or REQUEST (default)
    
    $varTag = (isset($varTag)) ? trim($varTag) : '';
    	// Optional placeholder tag, placeholders will be set as: varname.vartag (useful if using multiple times on a page)
    
    ///////////////////////////////////////////////////////////////////
    
    if (!$varList) return;
    $varTag = ($varTag) ? '.' . $varTag : '';
    
    foreach (explode(',', $varList) as $var)
    {
    	if (strpos($var, ':'))
    	{
    		list($varName, $varType) = explode(':', $var);
    		switch (strtoupper($varType))
    		{
    			case "POST":
    				$value = $_POST[$varName];
    				break;
    			case "GET":
    				$value = $_GET[$varName];
    				break;
    			case "SERVER":
    				$value = $_SERVER[$varName];
    				break;
    			case "SESSION":
    				$value = $_SESSION[$varName];
    				break;
    			case "COOKIE":
    				$value = $_COOKIE[$varName];
    				break;
    			default:
    				$value = $_REQUEST[$varName];
    		}
    	}
    	else
    	{
    		$varName = $var;
    		$value = $_REQUEST[$varName];
    	}
    
    	$modx->setPlaceholder($varName.$varTag, $value);
    }
    ?>


    Example using the snippet to retrieve jot comments from a specific page ID.

    Call page via: http://yoursite/page.html?post_id=X (where x is the numeric doc id)

    Snippet calls (within chunk/template):

    [[GetExtern? &varList=`post_id:GET` &varTag=`request`]]
    [[Jot? &docid=`[+post_id.request+]`]]

    Validation:

    PHx could be used for sanitizing/validating the placeholder before use.

    1) Create a new snippet called "phx:intval" and enter the following php code:

    <?php
    return intval($output);
    ?>


    2) Modify the placeholder call:

    [[Jot? &docid=`[+post_id.request:intval+]`]]
      • 23491 ☆ A M B ☆
      • 1,056 Posts
      Thanks, Apoxx. This came in handy for outputting DB values stored in SESSION-scope. It was as simple as running the snippet, and placing my placeholder... I even did both on the same doc, and it works just great.

      Very handy!
        Mike Reid - www.pixelchutes.com
        MODx Ambassador / Contributor
        [Module] MultiMedia Manager / [Module] SiteSearch / [Snippet] DocPassword / [Plugin] EditArea / We support FoxyCart
        ________________________________
        Where every pixel matters.