We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 3749
    • 24,544 Posts
    I don't see anything in your code that logs a user in. When you instantiate MODX, no one is logged in until they fill out a login form or you create a session context for them manually. I know from experience with plugins crashing things that there's no $modx->user when you instantiate $modx. I'm not sure when the (anonymous) user gets to be the user, but I don't think it happens in $modx->initialize.

    You might try this:

    Create a user who has limited permissions ('visitor'). Then, after initializing MODX, do this before the permission tests:

    $user = $modx->getObject('modUser', array('username' => 'visitor'));
    $modx->user =& $user;
      Did I help you? Buy me a beer
      Get my Book: MODX:The Official Guide
      MODX info for everyone: http://bobsguides.com/modx.html
      My MODX Extras
      Bob's Guides is now hosted at A2 MODX Hosting
      • 26503
      • 620 Posts
      Actually there is a function in the file(s) I attached earlier for a user to log in, [and it does work] But I sort of see what you are saying now, but not that we should have to create a 'phantom user' ~ modx already does this when you try to access the web context normally. Can we not call or initialize the 'anonymous' user natively somehow?

      Quote from: BobRay at Apr 01, 2013, 03:58 PM
      I don't see anything in your code that logs a user in. When you instantiate MODX, no one is logged in until they fill out a login form or you create a session context for them manually. I know from experience with plugins crashing things that there's no $modx->user when you instantiate $modx. I'm not sure when the (anonymous) user gets to be the user, but I don't think it happens in $modx->initialize.

      You might try this:

      Create a user who has limited permissions ('visitor'). Then, after initializing MODX, do this before the permission tests:

      $user = $modx->getObject('modUser', array('username' => 'visitor'));
      $modx->user =& $user;
        *** Not just websites, we also create signage, banners, print, trade show displays and more! ***

        Sean Kimball CLP, CLS.
        Technical Director / Sr. Developer | BigBlock Studios
        ._______________________________________________.
        Bigblock Studios http://www.bigblockstudios.ca Web site design & development.
        27-1300 King Street East. Box 167 Oshawa, Ontario L1H8J4 Canada.
        phone/fax: 905-426-5525
        • 26503
        • 620 Posts
        do you suppose that I am running into issues because the anonymous user actually does have permission to load a protected resource, but is actually redirected to a 404 page normally, i.e. there is some other check/thing I need to do after loading the resource?
          *** Not just websites, we also create signage, banners, print, trade show displays and more! ***

          Sean Kimball CLP, CLS.
          Technical Director / Sr. Developer | BigBlock Studios
          ._______________________________________________.
          Bigblock Studios http://www.bigblockstudios.ca Web site design & development.
          27-1300 King Street East. Box 167 Oshawa, Ontario L1H8J4 Canada.
          phone/fax: 905-426-5525
          • 3749
          • 24,544 Posts
          I'm just guessing here based on your symptoms. Is it possible that the resource is not really protected? To be protected it has to be in a resources group and the resource group has to be connected with a Resource Group Access ACL entry to a user group that the current user is not a member of.

            Did I help you? Buy me a beer
            Get my Book: MODX:The Official Guide
            MODX info for everyone: http://bobsguides.com/modx.html
            My MODX Extras
            Bob's Guides is now hosted at A2 MODX Hosting
            • 26503
            • 620 Posts
            Quote from: BobRay at Apr 02, 2013, 01:57 PM
            I'm just guessing here based on your symptoms. Is it possible that the resource is not really protected? To be protected it has to be in a resources group and the resource group has to be connected with a Resource Group Access ACL entry to a user group that the current user is not a member of.


            Yes - I've scrutinized that possibility very carefully. I tested verified by trying to view the resource in a different browser [anonymously] & got the correct 404 response.
              *** Not just websites, we also create signage, banners, print, trade show displays and more! ***

              Sean Kimball CLP, CLS.
              Technical Director / Sr. Developer | BigBlock Studios
              ._______________________________________________.
              Bigblock Studios http://www.bigblockstudios.ca Web site design & development.
              27-1300 King Street East. Box 167 Oshawa, Ontario L1H8J4 Canada.
              phone/fax: 905-426-5525
              • 3749
              • 24,544 Posts
              I've never actually tested this running outside of MODX. In theory, if $modx->user is the (anonymous) user and you retrieve the resource object, $resource->checkPolicy() should return true if the user has the permission and false if not.


              You might try checking if $modx->user->get('username') == '(anonymous)'. The parentheses around anonymous are necessary.

              You could also just echo $modx->user->get('username'), or if this is a plugin:


              $modx->log(MODX::LOG_LEVEL_ERROR, 'USERNAME: ' . $modx->user->get('username')


              and look in the error log.

                Did I help you? Buy me a beer
                Get my Book: MODX:The Official Guide
                MODX info for everyone: http://bobsguides.com/modx.html
                My MODX Extras
                Bob's Guides is now hosted at A2 MODX Hosting
                • 26503
                • 620 Posts
                it will return the user name & the user object will load without errors however, the test I ran:



                require_once('/var/www/vhosts/domain.com/httpdocs/config.core.php');
                
                require_once(MODX_CORE_PATH.'model/modx/modx.class.php');
                
                //require_once('/var/www/vhosts/oncologyeducation.com/httpdocs/index.php');
                
                $modx = new modX();
                
                $modx->initialize('web');
                
                $modx->getService('error','error.modError', '', '');
                
                $user = $modx->getObject('modUser', array('username' => '(anonymous)'));
                
                //$modx->user =& $user;
                
                echo $modx->getLoginUserID();
                
                echo '<br />check web = '.$modx->checkSession('web');
                
                echo '<br />check mgr = '.$modx->checkSession('mgr');
                
                echo '<br /> username = '.$modx->user->get('username');
                
                $resource = $modx->getObject('modResource',1055);
                
                echo '<br />'.$resource->get('pagetitle');
                
                echo '<br />'.$resource->get('content');
                
                echo '<br />.........done...........';



                echos the correct userid ~ 0
                doesn't echo anything for the the checkSessions
                echos (anonymous) for the get username

                1055 is a protected resource (definitely) but both page title & content are returned. the script will still load the protected object for the anonymous user. I've tested this on other domains with the same results.

                I really don't know where to go from here.

                  *** Not just websites, we also create signage, banners, print, trade show displays and more! ***

                  Sean Kimball CLP, CLS.
                  Technical Director / Sr. Developer | BigBlock Studios
                  ._______________________________________________.
                  Bigblock Studios http://www.bigblockstudios.ca Web site design & development.
                  27-1300 King Street East. Box 167 Oshawa, Ontario L1H8J4 Canada.
                  phone/fax: 905-426-5525
                  • 3749
                  • 24,544 Posts
                  OK, it's a step in the right direction that $modx->user is set correctly. I think Mark may be wrong about getObject() respecting permissions.

                  See what happens if you add this at the bottom:

                  echo '<br />PUBLISH PERMISSION: ' . $resource->checkPolicy('publish');


                    Did I help you? Buy me a beer
                    Get my Book: MODX:The Official Guide
                    MODX info for everyone: http://bobsguides.com/modx.html
                    My MODX Extras
                    Bob's Guides is now hosted at A2 MODX Hosting
                    • 26503
                    • 620 Posts
                    Yes - publish permission returns true (1)

                    It's kind of looking that way (that Mark was wrong) ~ however he said something about the user and session being the tricky part. something has to be left out here


                    As another test - If I place the following in a snippet and run it from a page within modx ~ the anonymous user can still view the resource being loaded.



                    echo $modx->getLoginUserID();
                    
                    echo '<br />check web = '.$modx->checkSession('web');
                    
                    echo '<br />check mgr = '.$modx->checkSession('mgr');
                    
                    echo '<br /> username = '.$modx->user->get('username');
                    
                    $resource = $modx->getObject('modResource',1838);
                    
                    echo '<br />'.$resource->get('pagetitle');
                    
                    echo '<br />'.$resource->get('content');
                    
                    echo '<br />.........done...........';
                      *** Not just websites, we also create signage, banners, print, trade show displays and more! ***

                      Sean Kimball CLP, CLS.
                      Technical Director / Sr. Developer | BigBlock Studios
                      ._______________________________________________.
                      Bigblock Studios http://www.bigblockstudios.ca Web site design & development.
                      27-1300 King Street East. Box 167 Oshawa, Ontario L1H8J4 Canada.
                      phone/fax: 905-426-5525
                      • 26503
                      • 620 Posts
                      ok - something very strange is going on here, I can use getResources to grab and display content from a protected resource:

                      [[!getResources? &parents=`-1` &resources=`1838` &tpl=`testTpl` &includeContent=`1`]]


                      will show the content, but if I try to view the 1838 resource normally [anonymously] I get the [correct] 404 page!

                      Testing this on a different site, getResources does not show the protected content.


                      Now that's really confusing, Wayfinder seems to work, hiding resources with no permissions... ?
                        *** Not just websites, we also create signage, banners, print, trade show displays and more! ***

                        Sean Kimball CLP, CLS.
                        Technical Director / Sr. Developer | BigBlock Studios
                        ._______________________________________________.
                        Bigblock Studios http://www.bigblockstudios.ca Web site design & development.
                        27-1300 King Street East. Box 167 Oshawa, Ontario L1H8J4 Canada.
                        phone/fax: 905-426-5525