We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 37286
    • 160 Posts
    Session id's change when logging in and out of modx in the web context. I want to capture that session id before it changes on a login event and logout event so I can update a table, changing the field from the old session id to the new session id. I have two plugins, a login and logout, to process the db transactions, I'm just not sure how to get the old id.

    For example, on the OnWebLogin event. If I call session_id(), I retrieve the new session id. How can I get the old session id?
      • 28042 ☆ A M B ☆
      • 24,524 Posts
      Perhaps OnBeforeWebLogout?


        Studying MODX in the desert - http://sottwell.com
        Tips and Tricks from the MODX Forums and Slack Channels - http://modxcookbook.com
        Join the Slack Community - http://modx.org
        • 37286
        • 160 Posts
        That makes sense, but if I do the work in OnBeforeWebLogin and OnBeforeWebLogout how do I get the new session id? Or how do I pass the old session id to the other plugin so I have both?
          • 28042 ☆ A M B ☆
          • 24,524 Posts
          You'll have to use a function with OnBeforeWebLogout to capture the session ID and store it. I don't see what this is going to accomplish, since the session is completely gone after logout. If you look at core/model/modx/processors/security/logout.php you'll see
          $modx->user->removeSessionContext($loginContext);
          if (!empty($addContexts)) {
              foreach ($addContexts as $addCtx) {
                  $modx->user->removeSessionContext($addCtx);
              }
          }
          


          Going to core/model/modx/moduser.class.php in the removeSessionContext() function you'll find
          if (empty($this->sessionContexts)) {
              $this->endSession();

          And the endSession() function
          public function endSession() {
          ...
                  $_SESSION = array();
                  if (ini_get("session.use_cookies")) {
                      $params = session_get_cookie_params();
                      setcookie(
                          session_name(),
                          '',
                          time() - 42000,
                          $params["path"],
                          $params["domain"],
                          $params["secure"],
                          $params["httponly"]
                      );
                  }
                  session_destroy();
              }
          

          So the session array and the cookie are both destroyed.
            Studying MODX in the desert - http://sottwell.com
            Tips and Tricks from the MODX Forums and Slack Channels - http://modxcookbook.com
            Join the Slack Community - http://modx.org
            • 37286
            • 160 Posts
            This is why I need to get the old session ID and pass it to a function with the new session ID so I can update the record in the table from the old session to the new session. What I'm essentially trying to do is build a "hit counter" to track the number of views on specific pages. I'm using the session to prevent multiple hits from the same person refreshing a page. Using the session means, after logging into the website, that person goes back to the previous page the hit count goes up again. This may be more work than is needed and I should just let the hit count increase after a login event, I just thought it would be nice to make it a little more accurate by having a unique visitor stat.