I have a site set up on 2.2.6 with the login module enabled. Some pages are only visible to users who have logged in to the system. They login only with their username (password is the same for all users, and is coded as a hidden field in the login tpl. Not very secure, but in this case no ploblem).
Now I am sending a email newsletter to my registered users, and I would like to have some links in there that go directly to the secure pages, but with their username (it is in the mailing database) as an url variable, so they don't have to login, but are logged in automatically, and taken to the 'secure' page without having to login themselves.
The link would look something like this:
www.domain.com/pagetoview?user=myUsername
Any ideas? I googled for several hours now, but can't find a solution...
Solved this one. I dug into the Login plugin, and modified some lines there to achieve what I wanted. Of course this bears some severe security issues, but that is not a real thread in this case...
I am not a real programmer, so I may have seriously done some harm to the existing code, but it works for me.
In case someone is interested in my modifications...
In the login controller I modified:
line 69 added:
if (!empty($_REQUEST['nbUser'])) {
$this->handleRequest();
}
Line 172 added:
elseif (isset($_GET['nbUser']) && !$this->isAuthenticated) {
$this->login();
}
Line 253 added:
if(isset($_GET['nbUser'])){
if($_GET['nbUser'] != ''){
$c = array(
'username' => $_GET['nbUser'],
'password' => 'PWDGOESHERE'
);
}
}
Line 334 added:
if(isset($_GET['nbUser'])){
$url_zonder_param = explode("?", $_SERVER['REQUEST_URI']);
$this->modx->sendRedirect($url_zonder_param[0]);
}else{