I could use some assistance in directing my attention on user authentication. I need to be able to authenticate a very low-level user. I have a regular MODX user (parent) who is able to register other users (children) under them. Those children need to be related to their parent, related AND restricted and authenticated. I'd like to figure out some sort of persistent mechanism for this. Is this where the remote fields come in on a user profile?
All these children can do is upload a file to a server, but I need to lock it down as much as possible and it has to be stupid-smart for these children. At the moment I'm looking into my own OAuth server but I'm not sure that's the best way to go about this. Anyone have any suggestions?
I'm not completely clear on what you need to do, but authentication in MODX is the same for all kinds of users. Unless you have some compelling reason for authenticating outside of MODX, I'd recommend just using the Login snippet.
Children can be related to parents by putting them in a user group named after the parent. The Children can be restricted mainly by creating a Context Access ACL entry for their user group with a policy that contains minimal permissions.
The difficult part is not restricting the children, it is restricting the parents so they can only create children under them and only set the children's permissions. In the current version of revolution, people either have full rights to the permissions system or none at all and either they can create any kind of user or they can't create any users at all. You can work around this with plugins but it's not a trivial task and there's no built-in solution.
Apologies if I didn't post this in the right forum. I just thought maybe I should treat modx like a service, and the parent like an app requesting access to the service, hence the question about using custom oauth server. Then the parent would request a new auth token for each child it registers...then again I'm not sure you can do that. It's late, and I am lost as to the best, most effective way of doing minor authentication like this in modx.
You can do almost anything imaginable in MODX, but it's mainly geared to users who are expected to log in. There's nothing to stop you, though, from creating some kind of custom authentication system with MODX, and there are *many* different ways to accomplish that in MODX.