We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 51474
    • 27 Posts
    Currently we need login using ModX manager's username and password only we can access manager page and edit our resources,snippet,etc...


    May I know can we disabled the default ModX manager authentication and write our own authentication .php codes?

    The own authentication scripts is using a custom oAuth authentication method that using CURL to connect the database and retrieve sessions via token...


    May I know do ModX capable to do that?
      • 3749
      • 24,544 Posts
      Yes, this is fairly simple, though you'll still need to present a login form first (or use the MODX one).

      You need a plugin that is connected to the OnManagerAuthentication System Event (and OnWebAuthentication if you need it in the front end).

      Set $authenticated to true or false in your code and put this at the end of the plugin:

      $modx->event->_output = (bool) $authenticated;
      return; 
      


      The true case will bypass the MODX authentication process and the user will be logged in. In the false case, the MODX authentication will proceed and will fail unless the user has entered their MODX credentials in the login form.


        Did I help you? Buy me a beer
        Get my Book: MODX:The Official Guide
        MODX info for everyone: http://bobsguides.com/modx.html
        My MODX Extras
        Bob's Guides is now hosted at A2 MODX Hosting
        • 51474
        • 27 Posts
        Quote from: BobRay at Jan 12, 2016, 01:24 PM
        Yes, this is fairly simple, though you'll still need to present a login form first (or use the MODX one).

        You need a plugin that is connected to the OnManagerAuthentication System Event (and OnWebAuthentication if you need it in the front end).

        Set $authenticated to true or false in your code and put this at the end of the plugin:

        $modx->event->_output = (bool) $authenticated;
        return; 
        


        The true case will bypass the MODX authentication process and the user will be logged in. In the false case, the MODX authentication will proceed and will fail unless the user has entered their MODX credentials in the login form.



        Hello Bob,

        I can't search 'OnManagerAuthentication' function on my modx files...

        I'd try to study & modify the class of these 2 files :
        core/model/modx/processors/security/login.class.php

        core/model/modx/modmanagerresponse.class.php


        on modmanagerresponse.class.php, i try to modify public function validateAuthentication 's $isLoggedIn variable,
        when i set to true, I get a 'This webpage has a redirect loop' message...

        May I know on revo 2.4.2-pl , which files / variable do i need to modify to disabled the modx login authentication?

        Thankyou...
          • 3749
          • 24,544 Posts
          Sorry if I wasn't clear. You should *never* modify MODX core files. One of the great things about MODX is that you don't need to. You also rarely want to create .php files, since by default MODX keeps snippet and plugin code in the database.

          If you create a plugin (on the Elements tree in the Manager), on the System Events tab, you'll see a list of all the System Events, including the ones I mentioned above. You just check the ones you want to attach the plugin to.

          The code on this page is not up to date, but the explanation of how plugins work is still current.

          [update] I've fixed the code on the page in the link. [ed. note: BobRay last edited this post 10 years, 8 months ago.]
            Did I help you? Buy me a beer
            Get my Book: MODX:The Official Guide
            MODX info for everyone: http://bobsguides.com/modx.html
            My MODX Extras
            Bob's Guides is now hosted at A2 MODX Hosting
            • 51474
            • 27 Posts
            Quote from: BobRay at Jan 14, 2016, 11:58 PM
            Sorry if I wasn't clear. You should *never* modify MODX core files. One of the great things about MODX is that you don't need to. You also rarely want to create .php files, since by default MODX keeps snippet and plugin code in the database.

            If you create a plugin (on the Elements tree in the Manager), on the System Events tab, you'll see a list of all the System Events, including the ones I mentioned above. You just check the ones you want to attach the plugin to.

            The code on this page is not up to date, but the explanation of how plugins work is still current.

            Hello Bob, Thanks for the tips.
            For now I created a plugin and follow this link ( https://rtfm.modx.com/revolution/2.x/developing-in-modx/basic-development/plugins/system-events/onbeforeweblogin )

            added the code
            $modx->event->output(true);

            and i set the System Event to OnBeforeManagerLogin

            So when I access my manager url http://localhost/modx/manager/,
            By right it will auto redirect to the dashboard instead of login screen.

            After I save my plugin, when i access my manager link, it still remain on the login screen instead of dashboard.
            Am i on the right path? Did I miss out something?

            Thanks, Appreciate your help Bob.
              • 3749
              • 24,544 Posts
              Try this:

              $modx->event->_output = true;
              return;


                Did I help you? Buy me a beer
                Get my Book: MODX:The Official Guide
                MODX info for everyone: http://bobsguides.com/modx.html
                My MODX Extras
                Bob's Guides is now hosted at A2 MODX Hosting
                • 51474
                • 27 Posts
                Quote from: BobRay at Jan 15, 2016, 12:33 AM
                Try this:

                $modx->event->_output = true;
                return;



                I tested both
                $modx->event->output(true);

                &
                $modx->event->_output = true;


                But still can't bypass the modx manager login.

                I delete core's cache files, flush permission & logout all user.

                When I refresh still at the login panel instead of dashboard panel.





                  • 3749
                  • 24,544 Posts
                  I don't know what to tell you, this code worked for me:

                     if ($user->passwordMatches($givenPassword)) {
                          $modx->event->_output = true;
                          return;
                      }
                    Did I help you? Buy me a beer
                    Get my Book: MODX:The Official Guide
                    MODX info for everyone: http://bobsguides.com/modx.html
                    My MODX Extras
                    Bob's Guides is now hosted at A2 MODX Hosting
                    • 17403 ☆ A M B ☆
                    • 183 Posts
                    How do you get manager privilege with (only) cURL? Thats interesting...

                    Manager privilege to list/view/edit/delete resource, etc. [ed. note: lokamaya last edited this post 10 years, 8 months ago.]
                      zaenal.lokamaya
                      • 17403 ☆ A M B ☆
                      • 183 Posts
                      Here the example of custom modUser that integrate MODX with LDAP https://github.com/lokamaya/ModLDAP.

                      So, basically we can integrate MODX with anything, including cURL, for user authentication.

                        zaenal.lokamaya