We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 45533
    • 23 Posts
    Hi,

    never done this before, so i'm sure i'd messed up somewhere.

    I want to have 2 different Member Areas - with an Extra Context for each where a subdomain is pointing too...

    So i'd setup 2 extra Context which are called "Internal" and "Friends" - so at all i got 3 Context now.

    Web
    Friends
    Internal

    i've created a switch statement in my Index.php - where depending on the subdomain one of those Context gets initialized.

    Thats all working fine.

    Now i want - that the Usergroup Staff has access to the Internal Context and the Friends Context, while Friends dont have access to Internal (thats staff only).

    My Access Permissions on the Friends context looks like this now:

    (anonymous) 9999 LoadOnly
    Staff 9999 Load,List and View
    Friends 9999 Context

    That seems to be working too - now my Problem is - i want that any unauthorized Call gets redirected to a Page in the Web Context (id 7) - so i'd setup a System Setting unauthorized_page and assigned the value 7.

    That works for the web context - but it does'nt work for the 2 other context. there i only get a default apache 401 page.

    (Just on a sidenote... i tried also to make this unauthorized_page setting for the context's individually in the context settings, that has'nt worked either - then i deleted it there again - which DELETED the whole setting (in the core)... not sure if thats the normal behavior).

    What do i wrong ?

    This question has been answered by aquabug. See the first response.

      • 28042 ☆ A M B ☆
      • 24,524 Posts
      First, the problem with editing or deleting context settings is a known bug, and is fixed in the latest dev version (2.3.3-dev) on github.

      As far as I know, you will need an unauthorized_page for each context. You might possibly be able to use a plugin to redirect the unauthorized user to the web context's unauthorized page, or you could use a weblink for the unauthorized page in your other context.
        Studying MODX in the desert - http://sottwell.com
        Tips and Tricks from the MODX Forums and Slack Channels - http://modxcookbook.com
        Join the Slack Community - http://modx.org
        • 45533
        • 23 Posts
        After playing arround with this issue since 2 hours or something now - i was already going to give the Plugins a shoot...

        One more question to this... at least it totally does'nt matter what i setup in the Access Permissions of the Context - cause his ressources are always Visible to anyone (i've to assign a Ressource to Ressource Group first - to make this working).

        Is there a way to tell modx... "hey - anything beyond this Context should be protected and assigned to whatever i'd setup in your Settings until i tell you otherwise over the Resource Settings" ?

        Cause from my view - the Access Permissions for the Context are somehow pointless like they behave right now (could be that i'd misunderstood something about it... but... they just dont work... )

        For now i will fiddle a Plugin together to solve that not Authorized Issue first - thanks for your Answer so far.
          • 45533
          • 23 Posts
          i'd just made a plugin where i first tried to process the destination ressource to put it out etc... (to keep the uri)... well all crap...

          then i found the sendForward Function in the docs.... so i'd made something like:

          $modx->sendForward($modx->getOption('unauthorized_page'));
          


          for this... (and now it comes)... there needs to be allow_forward_across_contexts setted.
          http://rtfm.modx.com/revolution/2.x/administering-your-site/settings/system-settings/allow_forward_across_contexts

          And this actually makes the Plugin pointless... cause it solves the issue.

          So with that setting... you get the right Non Auth Page smiley

          Still the "issue" with those Access Permissions in the Context.
            • 28042 ☆ A M B ☆
            • 24,524 Posts
            Now that is good to know! I've seen that setting and never thought much about it.

            As far as permissions go, they are a major pain in the head - as in I already have a headache from spending a few minutes toying with it on a multi-context dev site on my localhost. I did get it all working, but now have trouble trying to remember exactly what I did. I do know that I did the following two things:

            1. Created a group for Context2. Gave it load-only permissions to each of the other (non-mgr) contexts as well as Context2.
            2. Removed the permissions for (anonymous) group for Context2, making sure it still had permissions for the other contexts.

            If I recall correctly, that basically blocked all of Context2 to any users that weren't assigned to its group. But it took me a couple of tries to get it working, so I'm not sure if I did something else in between that made it work.

            I don't know if resource permissions override context permissions; I doubt it.
              Studying MODX in the desert - http://sottwell.com
              Tips and Tricks from the MODX Forums and Slack Channels - http://modxcookbook.com
              Join the Slack Community - http://modx.org
              • 45533
              • 23 Posts
              Not sure if i really gave both groups Load Rights to each other... but somehow at least this is working now. I will make deeper Tests once i have the general behavior working. But there is a complete different Problem now - which i figured then with further Testing, after i get the login page when i need it etc.


              I login my Users over the web Context... once they logged in, and there was no Unauthorized Access before they get redirected to the Start Ressource of the according Context (well at least this is the plan).

              i give the login processor in his parameters 'add_contexts' => 'internal, friends' and 'login_context' => 'web', which should log me in to all those 3 Context from my understanding.

              But it does'nt.

              Once i'd logged in - i have a usersession on the web Context - my browser gets cookies for all given contexts - but a simple $modx->user->get('username') in one of the non web contexts gives anonymous.

              Is there any System Setting or something i could have missed ?

                • 3749
                • 24,544 Posts
                If you're doing this in code, you should be able to just do this:

                $modx->user->addSessionContext('web');
                $modx->user->addSessionContext('internal');
                $modx->user->addSessionContext('friends');


                If the user is logging in with the Login snippet, you can do this:

                [[!Login? &contexts=`web,internal,friends`]]



                  Did I help you? Buy me a beer
                  Get my Book: MODX:The Official Guide
                  MODX info for everyone: http://bobsguides.com/modx.html
                  My MODX Extras
                  Bob's Guides is now hosted at A2 MODX Hosting
                  • 45533
                  • 23 Posts
                  i will try to call it once more after i'm logged in... but this function is exactly the one - which the login processor is calling aswell - when you put in the 'add_contexts' field (comma seperated list of context keys). I dont use the login snippet but i was looking into it... contexts gets assigned to the 'add_contexts' parameter aswell there - before the processor call.
                    • 45533
                    • 23 Posts
                    i wrote a Plugin now - which is listening on OnWebLogin:

                    $modx->log(modX::LOG_LEVEL_ERROR, 'User Logged in: '.$user->get('username'));
                    $modx->log(modX::LOG_LEVEL_ERROR, 'Added Contexts: '.var_dump($attributes['addContexts']));
                    $user->addSessionContext('internal');
                    $user->addSessionContext('friends');
                    


                    it gives me the following output after logging in:

                    [2014-12-01 08:51:42] (ERROR @ /index.php) User Logged in: testuser1
                    [2014-12-01 08:51:42] (ERROR @ /index.php) Added Contexts: 
                    [2014-12-01 08:51:42] (ERROR @ /index.php) [OnWebLogin]array(2) {
                      [0]=>
                      string(8) "internal"
                      [1]=>
                      string(8) " friends"
                    }
                    
                    
                    


                    still the same issue - once i'm accessing a page outside of the web context i'm anonymous there. i duplicated my login page to the internal context - made a login there - and it works... i'd made that to be sure there is'nt something terribly wrong with the acls or whatever.


                    What do i wrong ? Why is it not working ?
                      • 45533
                      • 23 Posts
                      just an update - i've set the session_cookie_domain now to .domain.tld like suggested here http://modxcms.com/forums/index.php/topic,57908.msg331246.html#msg331246

                      but it still does'nt work.

                      if i make a user->hasSessionContext('oneofthenonwebkeys') in the web context i always get a true... but hell - i'm still anonymous over in the other context.

                      any ideas would be much appreciated sad