Hi,
I’m hoping that this may be helpful for people getting 403 (security) errors while editing various types of content in the Manager. I also had marked this as SOLVED, but IMO, it no longer is.
As can be seen in the thread above, I had thought that the problem was solved when the tech made changes to a setting in mod_security.
But I ran into the problem again today on the same box. On the bright side, the tech fixed my own problem immediately! But when I found out what he did to solve it, that’s what concerned me. This time around, I got a little nosier and asked what he had changed.
I had hoped that he would have simply turned off mod_security for that one folder, or at least that he would have given me permission to use the milder mod_security rule overrides that one can find in the MODx wiki and elsewhere.
Apparently he looked at the errors that I was getting, and white-listed some content words. This is a spam filtering component of mod_security, and they’re casting a wide net, IMO. The words involved were "online" and "prescription", not exactly words that are rare or particularly dangerous. I envision some geek locked in a room must be doing statistical analysis of spam words and just chucking them into the mod_security spam filter.
So the problem could occur again whenever an editor bumps into more of these words. It’s lame, IMO, to do a manual fix every time this happens. Anecdotally, I am seeing this problem more and more often on pretty much any CMS system. The cure being as bad as the disease.
Some of you won’t have this limitation. If you’re in charge of the server as root, then you can shut off mod_security if it comes to that. Or you can at least do surgical strikes on where it’s applied, and what it’s doing, for more security safety.
I have also heard that running SUEXEC can help with this, although I don’t know details.
And on many hosts, you can do commands such as "SecFilterScanPOST Off" in .htaccess in the offending folder and have it work, just as advised here.
http://wiki.modxcms.com/index.php/What_is_mod_security_and_how_does_it_affect_me
On Liquidweb shared hosting, evidently this is not allowed.
With any dedicated hosting, I’m guessing that this is easily corrected. But the budgets of my clients are generally not big enough to use dedicated.
Hope this helps someone. When all else fails, I have gone into the database itself to make the updates with the desired content.
Dave