I'll probably be sorry I mentioned this, but it's possible to create a login form that asks for username, password, and email. You use the user's email address to validate them, and then save the password they enter when logging in as their permanent password. This assumes that you've imported them into the MODX DB (and the WP database includes their email addresses) -- *and* you've made sure the salt field is empty in the MODX DB *and* you've set the hash_class field for all users to hashing.modPBKDF2. You'll also need to be sure each user has a profile, but that should happen during the import.
This is all transparent to the users as long as they enter the correct username, password, and email. You just have to tell them to be sure they use the same email address WP has because it will be part of the initial authentication.
You'd attach a plugin with code like this (untested) to OnManagerAuthentication and/or OnWebAuthentication:
$givenPassword = $password;
$givenEmail = $_POST['email'];
$username = $user->get('username');
$authenticated = false;
$salt = $user->get('salt');
/* I think this will work: */
$email = $user->Profile->get('email');
/* If not:
$profile = $user->getOne('Profile');
if ($profile) {
$email = $profile->get('email');
}
*/
/* Checking the salt bypasses this all once they're properly registered */
if (empty($salt)) {
if ( (!empty ($givenEmail)) && (!empty($email)) ) {
if ($givenEmail === $email) {
$authenticated = true;
$user->set('password', $givenPassword);
$user->save();
}
}
}
$modx->event->_output = (bool) $authenticated;
return '';
BTW, if you need a more secure solution and you don't mind spelunking in the WordPress code, you can find the WP hashing algorithm and use it rather than the email to do the initial authentication.
[ed. note: BobRay last edited this post 11 years, 3 months ago.]