-
☆ A M B ☆
- 3,141 Posts
You shouldn't have to check manually if the user has access to a resource when you use the MODX API - it wont show up in getCollection or getObject if the user doesn't have the access. If you want to check permission for a specific resource, you could just load it with getObject and if it doesn't come back, it either doesn't exist or the user doesn't have access.
It sounds like the tricky part is getting the user object and session ready for MODX to look at?
Quote from: markh at Mar 30, 2013, 04:08 PMYou shouldn't have to check manually if the user has access to a resource when you use the MODX API - it wont show up in getCollection or getObject if the user doesn't have the access. If you want to check permission for a specific resource, you could just load it with getObject and if it doesn't come back, it either doesn't exist or the user doesn't have access.
It sounds like the tricky part is getting the user object and session ready for MODX to look at?
I am using the getObject method ... what else could I be missing here?
*** Not just websites, we also create signage, banners, print, trade show displays and more! ***
Sean Kimball CLP, CLS.
Technical Director / Sr. Developer | BigBlock Studios
._______________________________________________.
Bigblock Studios
http://www.bigblockstudios.ca Web site design & development.
27-1300 King Street East. Box 167 Oshawa, Ontario L1H8J4 Canada.
phone/fax: 905-426-5525
So I ran a test, just in a little script page, all by it's own:
define('MODX_API_MODE', true);
require_once('/var/www/vhosts/oncologyeducation.com/httpdocs/index.php');
$modx = new modX();
$modx->initialize('web');
echo $modx->getLoginUserID();
$resource = $modx->getObject('modResource',1838);
echo $resource->get('pagetitle');
Pretty vanilla, the resource 1838 is definitely restricted to two different user groups, the the loginuserid is returning 0 [anonymous]
I'm still getting the script returning content from the protected document something is not right here, the getObject will return a resource if the current user [nobody] has no access to it [I tried loading the page in the browser as well & got the access denied page as I should have]
This is getting really frustrating.
*** Not just websites, we also create signage, banners, print, trade show displays and more! ***
Sean Kimball CLP, CLS.
Technical Director / Sr. Developer | BigBlock Studios
._______________________________________________.
Bigblock Studios
http://www.bigblockstudios.ca Web site design & development.
27-1300 King Street East. Box 167 Oshawa, Ontario L1H8J4 Canada.
phone/fax: 905-426-5525
I think MODX_API_MODE bypasses the security system because there is no request.
Try this:
require_once '/absolute/path/to/modx/config.core.php';
require_once MODX_CORE_PATH.'model/modx/modx.class.php';
$modx = new modX();
$modx->initialize('web');
$modx->getService('error','error.modError', '', '');
Nope - no luck like that either, the script will still show getObject on the resource id the current user [anonymous] has no access to.
I don't see any other options other than querying the database etc... even though [Mark] you say it shouldn't be necessary....
*** Not just websites, we also create signage, banners, print, trade show displays and more! ***
Sean Kimball CLP, CLS.
Technical Director / Sr. Developer | BigBlock Studios
._______________________________________________.
Bigblock Studios
http://www.bigblockstudios.ca Web site design & development.
27-1300 King Street East. Box 167 Oshawa, Ontario L1H8J4 Canada.
phone/fax: 905-426-5525
kinda looking like I'm going to have to do that - so how do I programatically determine if a user has access to a resource? what tables are involved etc?
*** Not just websites, we also create signage, banners, print, trade show displays and more! ***
Sean Kimball CLP, CLS.
Technical Director / Sr. Developer | BigBlock Studios
._______________________________________________.
Bigblock Studios
http://www.bigblockstudios.ca Web site design & development.
27-1300 King Street East. Box 167 Oshawa, Ontario L1H8J4 Canada.
phone/fax: 905-426-5525
Easy (if you have the resource object):
$resource->checkPolicy('permission_name');
I tried 'load' and 'view_document' - bot came back true on the restricted resource.
require_once('/var/www/vhosts/oncologyeducation.com/httpdocs/config.core.php');
require_once(MODX_CORE_PATH.'model/modx/modx.class.php');
//require_once('/var/www/vhosts/oncologyeducation.com/httpdocs/index.php');
$modx = new modX();
$modx->initialize('web');
$modx->getService('error','error.modError', '', '');
echo $modx->getLoginUserID();
$resource = $modx->getObject('modResource',1838);
echo $resource->checkPolicy('view_document');
echo $resource->checkPolicy('load');
echo $resource->get('pagetitle');
this should be working, right? because I just tested it on another domain & same results, the script will load the restricted object for the anonymous user.
*** Not just websites, we also create signage, banners, print, trade show displays and more! ***
Sean Kimball CLP, CLS.
Technical Director / Sr. Developer | BigBlock Studios
._______________________________________________.
Bigblock Studios
http://www.bigblockstudios.ca Web site design & development.
27-1300 King Street East. Box 167 Oshawa, Ontario L1H8J4 Canada.
phone/fax: 905-426-5525
You haven't set $modx->user, which is what is used for hasPermission() and checkPolicy().
You can also do this:
if (!$modx->user->hasSessionContext('web')) {
die ('Unauthorized Access'); // or send to login page
}
Quote from: BobRay at Apr 01, 2013, 03:35 PMYou haven't set $modx->user,
I don't understand? 'set it' ~ I thought once logged in modx was going to assume the 'current user'??
also - I'm not sure hasSessionContext('web') will do it - there are about 20 different user groups and levels of permission on any given document. we need to know specifically if they have access to a resource.
*** Not just websites, we also create signage, banners, print, trade show displays and more! ***
Sean Kimball CLP, CLS.
Technical Director / Sr. Developer | BigBlock Studios
._______________________________________________.
Bigblock Studios
http://www.bigblockstudios.ca Web site design & development.
27-1300 King Street East. Box 167 Oshawa, Ontario L1H8J4 Canada.
phone/fax: 905-426-5525