We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 40735
    • 119 Posts
    Hi guys! I'm building a front-end editor so users can edit their content without logging into the manager but I'm having trouble finding the documentation necessary to do it. Can someone point me in the right direction? I've looked at http://rtfm.modx.com/display/revolution20/Developing+in+MODx but none of that seems to address the part of the API that I need. I know there are a couple packages out there like Frontpage (I still remember MS FrontPage and I'm just not sure I can get past that lol) but I want to build a custom editor that will integrate more tightly with my site. Will any of these utilities provide me with the means to update my content without forcing me to use their front-end code?
    Any advice will be appreciated.
    Thanks!
      • 40735
      • 119 Posts
      The modResource class has a setContent method which looks like what I need. Are there any examples or best practices floating around out there that could be helpful to me as I develop this?
        • 40735
        • 119 Posts
        Does anyone know whether the setContent method I mentioned above sanitizes data itself or if I need to do it manually?
          • 4172
          • 5,888 Posts
          you can try formit and a formit-hook like formit2resource (somewhere in the forums) or newspublisher.
            -------------------------------

            you can buy me a beer, if you like MIGX

            http://webcmsolutions.de/migx.html

            Thanks!
            • 38209
            • 26 Posts
            Dave, I suggest you read through a few more general "MODX develop how-to's".

            Doing what you want can be done in many different ways. Using xPDO getting/updating resources is very easy, you won't really need an API...you can script your own in 5 minutes.

            Updating a resource through a snippet might look a little like this:
            <?php
            $id = 15;
            $resource = $modx->getObject('modResource', (int) $id);
            $resource->set('content', 'New content');
            $resource->save();
            ?>


            If you want to know what fields you can update check out:
            /core/model/schema/modx.mysql.schema.xml

            And find the object class="modResource".
              • 40735
              • 119 Posts
              Quote from: scherpontwikkeling at Nov 15, 2012, 09:32 AM
              Dave, I suggest you read through a few more general "MODX develop how-to's".

              Doing what you want can be done in many different ways. Using xPDO getting/updating resources is very easy, you won't really need an API...you can script your own in 5 minutes.

              Updating a resource through a snippet might look a little like this:
              <!--?php
              $id = 15;
              $resource = $modx--->getObject('modResource', (int) $id);
              $resource->set('content', 'New content');
              $resource->save();
              ?>


              If you want to know what fields you can update check out:
              /core/model/schema/modx.mysql.schema.xml

              And find the object class="modResource".

              Yeah, that's what I'm looking at doing with the setContent() method. Correct me if I'm wrong, but is that not part of the MODx API? If it's not an API, what is it?

              I'd still like to know if I need to do my own data sanitization before calling setContent as well.

              Quote from: Bruno17 at Nov 14, 2012, 01:45 PM
              you can try formit and a formit-hook like formit2resource (somewhere in the forums) or newspublisher.

              Thanks for the suggestion! I'm looking into this.
                • 37031
                • 93 Posts
                Yeah, that's what I'm looking at doing with the setContent() method. Correct me if I'm wrong, but is that not part of the MODx API? If it's not an API, what is it?

                I believe it is an API but it's more specifically a database API based on xPDO. Tomato tom-AH-to (FYI: NO ONE says tom-AH-to)

                I'd still like to know if I need to do my own data sanitization before calling setContent as well.

                Yes you will need to do your sanity checks.
                  • 40735
                  • 119 Posts
                  Quote from: jeffmiranda at Nov 16, 2012, 02:53 PM
                  Yeah, that's what I'm looking at doing with the setContent() method. Correct me if I'm wrong, but is that not part of the MODx API? If it's not an API, what is it?

                  I believe it is an API but it's more specifically a database API based on xPDO. Tomato tom-AH-to (FYI: NO ONE says tom-AH-to)

                  I'd still like to know if I need to do my own data sanitization before calling setContent as well.

                  Yes you will need to do your sanity checks.

                  No, I'm not talking about sanity checks. I'm talking about protecting against SQL injection. Do I need to strip slashes, check for and escape special characters, etc.? Data should never be taken from a form and put straight into a database. RedbeanPHP, for instance, does all that for you when you save data to a database using its API. Does xPDO do that as well?

                  Edit:
                  I'll bet it does. Redbean does it with PDO bindings so it seems similar. I'd like to be sure though before I go and skip it.
                    • 37031
                    • 93 Posts
                    No, I'm not talking about sanity checks. I'm talking about protecting against SQL injection. Do I need to strip slashes, check for and escape special characters, etc.? Data should never be taken from a form and put straight into a database. RedbeanPHP, for instance, does all that for you when you save data to a database using its API. Does xPDO do that as well?

                    Edit:
                    I'll bet it does. Redbean does it with PDO bindings so it seems similar. I'd like to be sure though before I go and skip it.

                    I'm not 100% sure but I'd bet it does too considering you can use setContent for a snippet and include a whole bunch of special characters...
                      • 40735
                      • 119 Posts
                      If no sanitization were being done I'd still expect to be able to insert special characters though. I'd expect to be able to insert any and everything in fact.