We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 18373 ☆ A M B ☆
    • 3,141 Posts
    You shouldn't have to check manually if the user has access to a resource when you use the MODX API - it wont show up in getCollection or getObject if the user doesn't have the access. If you want to check permission for a specific resource, you could just load it with getObject and if it doesn't come back, it either doesn't exist or the user doesn't have access.

    It sounds like the tricky part is getting the user object and session ready for MODX to look at?
      Mark Hamstra • Developer spending his days working on Premium Extras and a MODX Site Dashboard with the ability to remotely upgrade MODX and extras to make the MODX world a little better.

      Tweet me @mark_hamstra, check my infrequent blog at markhamstra.com, my slightly more frequent ramblings at MODX.today or see code at Github.
      • 26503
      • 620 Posts
      Quote from: markh at Mar 30, 2013, 04:08 PM
      You shouldn't have to check manually if the user has access to a resource when you use the MODX API - it wont show up in getCollection or getObject if the user doesn't have the access. If you want to check permission for a specific resource, you could just load it with getObject and if it doesn't come back, it either doesn't exist or the user doesn't have access.

      It sounds like the tricky part is getting the user object and session ready for MODX to look at?

      I am using the getObject method ... what else could I be missing here?
        *** Not just websites, we also create signage, banners, print, trade show displays and more! ***

        Sean Kimball CLP, CLS.
        Technical Director / Sr. Developer | BigBlock Studios
        ._______________________________________________.
        Bigblock Studios http://www.bigblockstudios.ca Web site design & development.
        27-1300 King Street East. Box 167 Oshawa, Ontario L1H8J4 Canada.
        phone/fax: 905-426-5525
        • 26503
        • 620 Posts
        So I ran a test, just in a little script page, all by it's own:


        define('MODX_API_MODE', true);
        
        require_once('/var/www/vhosts/oncologyeducation.com/httpdocs/index.php');
        
        $modx = new modX();
        
        $modx->initialize('web');
        
        echo $modx->getLoginUserID();
        
        $resource = $modx->getObject('modResource',1838);
        
        echo $resource->get('pagetitle');



        Pretty vanilla, the resource 1838 is definitely restricted to two different user groups, the the loginuserid is returning 0 [anonymous]

        I'm still getting the script returning content from the protected document something is not right here, the getObject will return a resource if the current user [nobody] has no access to it [I tried loading the page in the browser as well & got the access denied page as I should have]


        This is getting really frustrating.
          *** Not just websites, we also create signage, banners, print, trade show displays and more! ***

          Sean Kimball CLP, CLS.
          Technical Director / Sr. Developer | BigBlock Studios
          ._______________________________________________.
          Bigblock Studios http://www.bigblockstudios.ca Web site design & development.
          27-1300 King Street East. Box 167 Oshawa, Ontario L1H8J4 Canada.
          phone/fax: 905-426-5525
          • 3749
          • 24,544 Posts
          I think MODX_API_MODE bypasses the security system because there is no request.

          Try this:


          require_once '/absolute/path/to/modx/config.core.php';
          require_once MODX_CORE_PATH.'model/modx/modx.class.php';
          $modx = new modX();
          $modx->initialize('web');
          $modx->getService('error','error.modError', '', '');
            Did I help you? Buy me a beer
            Get my Book: MODX:The Official Guide
            MODX info for everyone: http://bobsguides.com/modx.html
            My MODX Extras
            Bob's Guides is now hosted at A2 MODX Hosting
            • 26503
            • 620 Posts
            Nope - no luck like that either, the script will still show getObject on the resource id the current user [anonymous] has no access to.

            I don't see any other options other than querying the database etc... even though [Mark] you say it shouldn't be necessary.... huh
              *** Not just websites, we also create signage, banners, print, trade show displays and more! ***

              Sean Kimball CLP, CLS.
              Technical Director / Sr. Developer | BigBlock Studios
              ._______________________________________________.
              Bigblock Studios http://www.bigblockstudios.ca Web site design & development.
              27-1300 King Street East. Box 167 Oshawa, Ontario L1H8J4 Canada.
              phone/fax: 905-426-5525
              • 26503
              • 620 Posts
              kinda looking like I'm going to have to do that - so how do I programatically determine if a user has access to a resource? what tables are involved etc?
                *** Not just websites, we also create signage, banners, print, trade show displays and more! ***

                Sean Kimball CLP, CLS.
                Technical Director / Sr. Developer | BigBlock Studios
                ._______________________________________________.
                Bigblock Studios http://www.bigblockstudios.ca Web site design & development.
                27-1300 King Street East. Box 167 Oshawa, Ontario L1H8J4 Canada.
                phone/fax: 905-426-5525
                • 3749
                • 24,544 Posts
                Easy (if you have the resource object):

                $resource->checkPolicy('permission_name');
                  Did I help you? Buy me a beer
                  Get my Book: MODX:The Official Guide
                  MODX info for everyone: http://bobsguides.com/modx.html
                  My MODX Extras
                  Bob's Guides is now hosted at A2 MODX Hosting
                  • 26503
                  • 620 Posts
                  I tried 'load' and 'view_document' - bot came back true on the restricted resource.

                  require_once('/var/www/vhosts/oncologyeducation.com/httpdocs/config.core.php');
                  
                  require_once(MODX_CORE_PATH.'model/modx/modx.class.php');
                  
                  //require_once('/var/www/vhosts/oncologyeducation.com/httpdocs/index.php');
                  
                  $modx = new modX();
                  
                  $modx->initialize('web');
                  
                  $modx->getService('error','error.modError', '', '');
                  
                  echo $modx->getLoginUserID();
                  
                  $resource = $modx->getObject('modResource',1838);
                  
                  echo $resource->checkPolicy('view_document');
                  
                  echo $resource->checkPolicy('load');
                  
                  echo $resource->get('pagetitle');



                  this should be working, right? because I just tested it on another domain & same results, the script will load the restricted object for the anonymous user.
                    *** Not just websites, we also create signage, banners, print, trade show displays and more! ***

                    Sean Kimball CLP, CLS.
                    Technical Director / Sr. Developer | BigBlock Studios
                    ._______________________________________________.
                    Bigblock Studios http://www.bigblockstudios.ca Web site design & development.
                    27-1300 King Street East. Box 167 Oshawa, Ontario L1H8J4 Canada.
                    phone/fax: 905-426-5525
                    • 3749
                    • 24,544 Posts
                    You haven't set $modx->user, which is what is used for hasPermission() and checkPolicy().

                    You can also do this:

                    if (!$modx->user->hasSessionContext('web')) {
                            die ('Unauthorized Access'); // or send to login page
                    }
                      Did I help you? Buy me a beer
                      Get my Book: MODX:The Official Guide
                      MODX info for everyone: http://bobsguides.com/modx.html
                      My MODX Extras
                      Bob's Guides is now hosted at A2 MODX Hosting
                      • 26503
                      • 620 Posts
                      Quote from: BobRay at Apr 01, 2013, 03:35 PM
                      You haven't set $modx->user,

                      I don't understand? 'set it' ~ I thought once logged in modx was going to assume the 'current user'??

                      also - I'm not sure hasSessionContext('web') will do it - there are about 20 different user groups and levels of permission on any given document. we need to know specifically if they have access to a resource.
                        *** Not just websites, we also create signage, banners, print, trade show displays and more! ***

                        Sean Kimball CLP, CLS.
                        Technical Director / Sr. Developer | BigBlock Studios
                        ._______________________________________________.
                        Bigblock Studios http://www.bigblockstudios.ca Web site design & development.
                        27-1300 King Street East. Box 167 Oshawa, Ontario L1H8J4 Canada.
                        phone/fax: 905-426-5525