We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 46756
    • 7 Posts
    I could use some assistance in directing my attention on user authentication. I need to be able to authenticate a very low-level user. I have a regular MODX user (parent) who is able to register other users (children) under them. Those children need to be related to their parent, related AND restricted and authenticated. I'd like to figure out some sort of persistent mechanism for this. Is this where the remote fields come in on a user profile?

    All these children can do is upload a file to a server, but I need to lock it down as much as possible and it has to be stupid-smart for these children. At the moment I'm looking into my own OAuth server but I'm not sure that's the best way to go about this. Anyone have any suggestions?
      • 3749
      • 24,544 Posts
      I'm not completely clear on what you need to do, but authentication in MODX is the same for all kinds of users. Unless you have some compelling reason for authenticating outside of MODX, I'd recommend just using the Login snippet.

      Children can be related to parents by putting them in a user group named after the parent. The Children can be restricted mainly by creating a Context Access ACL entry for their user group with a policy that contains minimal permissions.

      The difficult part is not restricting the children, it is restricting the parents so they can only create children under them and only set the children's permissions. In the current version of revolution, people either have full rights to the permissions system or none at all and either they can create any kind of user or they can't create any users at all. You can work around this with plugins but it's not a trivial task and there's no built-in solution.
        Did I help you? Buy me a beer
        Get my Book: MODX:The Official Guide
        MODX info for everyone: http://bobsguides.com/modx.html
        My MODX Extras
        Bob's Guides is now hosted at A2 MODX Hosting
        • 46756
        • 7 Posts
        Quote from: BobRay at Dec 18, 2014, 09:19 PM
        I'm not completely clear on what you need to do, but authentication in MODX is the same for all kinds of users. Unless you have some compelling reason for authenticating outside of MODX, I'd recommend just using the Login snippet.

        Children can be related to parents by putting them in a user group named after the parent. The Children can be restricted mainly by creating a Context Access ACL entry for their user group with a policy that contains minimal permissions.

        The difficult part is not restricting the children, it is restricting the parents so they can only create children under them and only set the children's permissions. In the current version of revolution, people either have full rights to the permissions system or none at all and either they can create any kind of user or they can't create any users at all. You can work around this with plugins but it's not a trivial task and there's no built-in solution.

        Thanks for the feedback Bob.

        *** I'm making this way more complicated than it needs to be. I need to make it as hard as possible for anyone not registered to a parent to upload to the server. The children are all on iPads. I need to be able to authenticate a child the first time they access the url. Once they do that I will grab the device ID and use that moving forward. The authentication just needs to check to make sure they have a parent, and that they are indeed a child. I started with just a simple key. The key was sent to the child, then parsed to identify the parent and the record for the child. But that seemed really easy to compromise.
          • 46756
          • 7 Posts
          Apologies if I didn't post this in the right forum. I just thought maybe I should treat modx like a service, and the parent like an app requesting access to the service, hence the question about using custom oauth server. Then the parent would request a new auth token for each child it registers...then again I'm not sure you can do that. It's late, and I am lost as to the best, most effective way of doing minor authentication like this in modx.
            • 3749
            • 24,544 Posts
            You can do almost anything imaginable in MODX, but it's mainly geared to users who are expected to log in. There's nothing to stop you, though, from creating some kind of custom authentication system with MODX, and there are *many* different ways to accomplish that in MODX.
              Did I help you? Buy me a beer
              Get my Book: MODX:The Official Guide
              MODX info for everyone: http://bobsguides.com/modx.html
              My MODX Extras
              Bob's Guides is now hosted at A2 MODX Hosting