I don't see anything in your code that logs a user in. When you instantiate MODX, no one is logged in until they fill out a login form or you create a session context for them manually. I know from experience with plugins crashing things that there's no $modx->user when you instantiate $modx. I'm not sure when the (anonymous) user gets to be the user, but I don't think it happens in $modx->initialize.
You might try this:
Create a user who has limited permissions ('visitor'). Then, after initializing MODX, do this before the permission tests:
$user = $modx->getObject('modUser', array('username' => 'visitor'));
$modx->user =& $user;
Actually there is a function in the file(s) I attached earlier for a user to log in, [and it does work] But I sort of see what you are saying now, but not that we should have to create a 'phantom user' ~ modx already does this when you try to access the web context normally. Can we not call or initialize the 'anonymous' user natively somehow?
Quote from: BobRay at Apr 01, 2013, 03:58 PMI don't see anything in your code that logs a user in. When you instantiate MODX, no one is logged in until they fill out a login form or you create a session context for them manually. I know from experience with plugins crashing things that there's no $modx->user when you instantiate $modx. I'm not sure when the (anonymous) user gets to be the user, but I don't think it happens in $modx->initialize.
You might try this:
Create a user who has limited permissions ('visitor'). Then, after initializing MODX, do this before the permission tests:
$user = $modx->getObject('modUser', array('username' => 'visitor'));
$modx->user =& $user;
*** Not just websites, we also create signage, banners, print, trade show displays and more! ***
Sean Kimball CLP, CLS.
Technical Director / Sr. Developer | BigBlock Studios
._______________________________________________.
Bigblock Studios
http://www.bigblockstudios.ca Web site design & development.
27-1300 King Street East. Box 167 Oshawa, Ontario L1H8J4 Canada.
phone/fax: 905-426-5525
do you suppose that I am running into issues because the anonymous user actually does have permission to load a protected resource, but is actually redirected to a 404 page normally, i.e. there is some other check/thing I need to do after loading the resource?
*** Not just websites, we also create signage, banners, print, trade show displays and more! ***
Sean Kimball CLP, CLS.
Technical Director / Sr. Developer | BigBlock Studios
._______________________________________________.
Bigblock Studios
http://www.bigblockstudios.ca Web site design & development.
27-1300 King Street East. Box 167 Oshawa, Ontario L1H8J4 Canada.
phone/fax: 905-426-5525
I'm just guessing here based on your symptoms. Is it possible that the resource is not really protected? To be protected it has to be in a resources group and the resource group has to be connected with a Resource Group Access ACL entry to a user group that the current user is not a member of.
Quote from: BobRay at Apr 02, 2013, 01:57 PMI'm just guessing here based on your symptoms. Is it possible that the resource is not really protected? To be protected it has to be in a resources group and the resource group has to be connected with a Resource Group Access ACL entry to a user group that the current user is not a member of.
Yes - I've scrutinized that possibility very carefully. I tested verified by trying to view the resource in a different browser [anonymously] & got the correct 404 response.
*** Not just websites, we also create signage, banners, print, trade show displays and more! ***
Sean Kimball CLP, CLS.
Technical Director / Sr. Developer | BigBlock Studios
._______________________________________________.
Bigblock Studios
http://www.bigblockstudios.ca Web site design & development.
27-1300 King Street East. Box 167 Oshawa, Ontario L1H8J4 Canada.
phone/fax: 905-426-5525
I've never actually tested this running outside of MODX. In theory, if $modx->user is the (anonymous) user and you retrieve the resource object, $resource->checkPolicy() should return true if the user has the permission and false if not.
You might try checking if $modx->user->get('username') == '(anonymous)'. The parentheses around anonymous are necessary.
You could also just echo $modx->user->get('username'), or if this is a plugin:
$modx->log(MODX::LOG_LEVEL_ERROR, 'USERNAME: ' . $modx->user->get('username')
and look in the error log.
it will return the user name & the user object will load without errors however, the test I ran:
require_once('/var/www/vhosts/domain.com/httpdocs/config.core.php');
require_once(MODX_CORE_PATH.'model/modx/modx.class.php');
//require_once('/var/www/vhosts/oncologyeducation.com/httpdocs/index.php');
$modx = new modX();
$modx->initialize('web');
$modx->getService('error','error.modError', '', '');
$user = $modx->getObject('modUser', array('username' => '(anonymous)'));
//$modx->user =& $user;
echo $modx->getLoginUserID();
echo '<br />check web = '.$modx->checkSession('web');
echo '<br />check mgr = '.$modx->checkSession('mgr');
echo '<br /> username = '.$modx->user->get('username');
$resource = $modx->getObject('modResource',1055);
echo '<br />'.$resource->get('pagetitle');
echo '<br />'.$resource->get('content');
echo '<br />.........done...........';
echos the correct userid ~ 0
doesn't echo anything for the the checkSessions
echos (anonymous) for the get username
1055 is a protected resource (definitely) but both page title & content are returned. the script will still load the protected object for the anonymous user. I've tested this on other domains with the same results.
I really don't know where to go from here.
*** Not just websites, we also create signage, banners, print, trade show displays and more! ***
Sean Kimball CLP, CLS.
Technical Director / Sr. Developer | BigBlock Studios
._______________________________________________.
Bigblock Studios
http://www.bigblockstudios.ca Web site design & development.
27-1300 King Street East. Box 167 Oshawa, Ontario L1H8J4 Canada.
phone/fax: 905-426-5525
OK, it's a step in the right direction that $modx->user is set correctly. I think Mark may be wrong about getObject() respecting permissions.
See what happens if you add this at the bottom:
echo '<br />PUBLISH PERMISSION: ' . $resource->checkPolicy('publish');
Yes - publish permission returns true (1)
It's kind of looking that way (that Mark was wrong) ~ however he said something about the user and session being the tricky part. something has to be left out here
As another test - If I place the following in a snippet and run it from a page within modx ~ the anonymous user can still view the resource being loaded.
echo $modx->getLoginUserID();
echo '<br />check web = '.$modx->checkSession('web');
echo '<br />check mgr = '.$modx->checkSession('mgr');
echo '<br /> username = '.$modx->user->get('username');
$resource = $modx->getObject('modResource',1838);
echo '<br />'.$resource->get('pagetitle');
echo '<br />'.$resource->get('content');
echo '<br />.........done...........';
*** Not just websites, we also create signage, banners, print, trade show displays and more! ***
Sean Kimball CLP, CLS.
Technical Director / Sr. Developer | BigBlock Studios
._______________________________________________.
Bigblock Studios
http://www.bigblockstudios.ca Web site design & development.
27-1300 King Street East. Box 167 Oshawa, Ontario L1H8J4 Canada.
phone/fax: 905-426-5525
ok - something very strange is going on here, I can use getResources to grab and display content from a protected resource:
[[!getResources? &parents=`-1` &resources=`1838` &tpl=`testTpl` &includeContent=`1`]]
will show the content, but if I try to view the 1838 resource normally [anonymously] I get the [correct] 404 page!
Testing this on a different site, getResources does not show the protected content.
Now that's really confusing, Wayfinder seems to work, hiding resources with no permissions... ?
*** Not just websites, we also create signage, banners, print, trade show displays and more! ***
Sean Kimball CLP, CLS.
Technical Director / Sr. Developer | BigBlock Studios
._______________________________________________.
Bigblock Studios
http://www.bigblockstudios.ca Web site design & development.
27-1300 King Street East. Box 167 Oshawa, Ontario L1H8J4 Canada.
phone/fax: 905-426-5525