i have a site where every page contains a login form. after successful login, this form gets replaced with a link to the members area.
i have looked into the Login-plugin, but can't use that as the customers cannot be administered by modx, as well as these pages cannot have restricted access.
i tried using FormIt and set a cookie after successful login; but this is neither secure as practical, due to the fact that the login-form gets replaced after the next next page-load (not right after submitting the form).
if i set a session-variable, then only the submitted page seems to have access to that session-variable; but not the other pages.
any clues on how this can be achieved? with or without a session-variable (which i would prefer)?
thanks in advance!!
but can't use that as the customers cannot be administered by modx
why not?
I think it would simplyfie things, if your customers would be modx-users.
Can you import/synchronize your customers with the modx-users?
Than you should be able to use login and other extras like personalize to get it done.
thanks for your reply Bruno17, but the customers are managed on a different system and implementing a synchronization does not seem very practical.
-
☆ A M B ☆
- 24,524 Posts
The user submits the login form, which submits to your user management system, then redirects the user back to the MODx page? Is the user management system on the same domain as the MODx installation? Does your user management system offer any kind of API to expose the user's status?
-
☆ A M B ☆
- 24,524 Posts
I don't understand. How do you establish a "successful login"? The form has to post somewhere, to check against the user's credentials.
i am using FormIt and a snippet as the hook for the verification; that snippet should verify the credentials and then set a session-variable on success.
i could check on this session-variable on the following pages to see if the customer has logged in or not.
-
☆ A M B ☆
- 24,524 Posts
Set the $_SESSION['myfield'] value in the hook,
if($success) $_SESSION['myfield'] = 'true';
then use a simple snippet to check that session value and display the form or the link accordingly.
isset($_SESSION['myfield']) ? /* display link */ : /* display form */;
this is what i want to achieve! but as it seems, the session-variable has a scope for only the ressource where it was set! the other pages on the site cannot access that session-variable. it just does not exist on any other pages. if i click back on the page where the variable was set - voila, the login-form will be replaced by the display link as desired.
-
☆ A M B ☆
- 24,524 Posts
The SESSION is valid on all pages within the same domain; are you going from domain.com to www.domain.com or vice verse? Where, exactly, is your FormIt form posting to? And what does that post action do?