We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 20371
    • 58 Posts
    Hey MODx guru's.. I just wanted your thoughts on the best way to implement single sign on between modx and a few other opensource php products.

    At this point the project is in it's very early stages, I haven't even locked down the different projects I'm going to use, as the final decision may well depend on which one is the easiest to integrate.

    Presently I'm looking at MODx, osTickets (support ticketing), and pydio (browser based file management). The actual required functionality from each project will be fairly well balanced between them. There will also be a considerable amount of additional user fields / user meta data which isn't directly required by any of the three projects.

    The way I look at it my options are sessions, oAuth, or LDAP.

    Re sessions..
    I guess there's a few options here.. for example I could use the MODx Login extension to auth a user against the MODx user table, and then load the osTicket & pydio API's externally and call an auth function in those APIs too.

    My question here I suppose is how I would auth a user in MODx if I loaded the MODx API externally. I had a flick through the MODx API login extension source expecting to see a function like $modx->authUser($name, $pass) but sadly it doesn't seem anywhere near that simple. I did see $modx->addSessionContext($context) but I'm not entirely sure if that's what I'm looking for.

    To be honest, rather than using one of the three projects to sort of be the 'master user manager'.. I'd be interested to use a separate project like user cake or something.

    The downsides to this option are; it seems like a lot of work to set up, seems like it might be prone to breaking on upgrading of any of the required projects (but maybe unlikely).

    Re oAuth..
    I've used oAuth to access API's before, but never set up an oAuth system. I have no idea how complicated it would be to set up. It doesn't look like there's oAuth plugins for any of the projects I intend to use, beyond perhaps allowing a google login via oAuth or something.

    So with that in mind, if I was to use oAuth I'd need to do all the same work accessing API's as I would do with the sessions option, plus set up the oAuth system itself.

    Re LDAP..
    I don't know much about LDAP, every time I've seen it before I've just thought "oh that's a microsoft thing". But of course, it's quite well supported in linux. Interestingly, there's LDAP plugins for all three of the relevant projects, as well as several reasonable looking ldap management ui's which would also be pretty handy.

    So that's pretty much as far as I've gotten. I'm really interested to hear from any of you who set up single sign on with MODx before, or anyone who has any input at all really. How did you set it up? What problems am I going to run into? Which method should I look into in more detail?

    Thanks in advance! [ed. note: Mr5o1 last edited this post 12 years, 4 months ago.]
      • 20371
      • 58 Posts
      Turns out it's really easy to do with the session.. because I'll be authorizing from an external script, I just get a modx instance, get the user, and call addSessionContext

      <?php
      //require 'modx/assets/kint/Kint.class.php';
       
      require_once __DIR__ . '/modx/config.core.php';
      require_once MODX_CORE_PATH.'model/modx/modx.class.php';
      $modx = new modX();
      $modx->initialize('web');
      $modx->getService('error','error.modError', '', '');
      
      $user = $modx->getObject('modUser', array('username' => 'Mr5o1'));
      $user->addSessionContext('mgr');
      
      //dd($user->get('username'));
      


      Props to the handy forum guy (you know who you are) that worked it out for me.
        • 46756
        • 7 Posts
        Had a couple questions related to detail...

        - Are you authenticating a MODX user outside of the core site and then using the success of that action to log the user into the other projects? Do I have that right?

        I'm trying to figure out a way to authenticate "sub" users. Not sure how else to describe them. Basically if MODX was an office, each Supervisor would be a MODX user. And each Supervisor could register/manage/update an employee with their workgroup. The employee is on the road a lot so I was hoping to figure out some sort of way to authenticate without username/password. You may have given me a couple ideas....