We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 22446
    • 181 Posts
    I am looking to make a page in modx revolution 2.0.4 secure using SSL. Can anyone help me out in trying to do this?
      • 5340
      • 1,624 Posts
      Here’s a port of the SSL plugin for Evo: http://modxcms.com/extras/package/?package=570

      Basically it works the same
      Create a TV called ’encryption’, make it a checkbox and set the input option value: Yes==1
      Use the following code as a plugin. Check OnWebPageInit in the configuration tab

      <?php
      if ($modx->event->name == 'OnWebPageInit') {
        
        //CONFIGURATION
        // server paths - no trailing slash!
        $secureserver = "https://www.yoursite.com";
        $insecureserver = "http://www.yoursite.com";
       
        
        $resourceId = $modx->resourceIdentifier;
        
        
        //get encryption value
        $document = $modx->getObject('modResource',array('id' => $resourceId));
        
        $document_tvs = $document->getMany('TemplateVars');
        foreach($document_tvs as $document_tv)
          $tv_outputs[$document_tv->get('name')] = $document_tv->renderOutput($document->get('id'));
        
        $fields_to_get = array ('id');
        
        foreach ($fields_to_get as $field_to_get)
          $tv_outputs[$field_to_get] = $document->get($field_to_get);
        
        
        //finally the value
        $encryption = FALSE;
        if($tv_outputs['encryption'] == 1){
          $encryption = TRUE;
        }
       
        $url = $_SERVER['REQUEST_URI'];
        
        $ssl = FALSE;
        if($_SERVER['HTTPS'] == 1)  {
          $ssl =  TRUE;
        } elseif ($_SERVER['HTTPS'] == 'on'){
          $ssl =  TRUE;
        } elseif ($_SERVER['SERVER_PORT'] == 443) {
          $ssl = TRUE;
        }
        
        // switch between http / https if necessary
        // if $secureserver === $insecureserver (eg you are testing locally)
        // then comment out this code block to avoid infinite recursion
        if($encryption && !$ssl) {
          // if SSL off and we are about to access a secure page then redirect
          $modx->sendRedirect($secureserver.$url);
        } else if ($ssl && !$encryption) {
          // if SSL is on and we are about to acccess an unsecure page then redirect
          $modx->sendRedirect($insecureserver.$url);
        }
        
      
      }
      ?>


        • 22446
        • 181 Posts
        Thanks. Works Great.
          • 10702
          • 107 Posts
          We did everything described above in Revo for having a single ssl-site. But now our websites are very slow. Do we have to make any changes for Revo to make it work?

          Gerdi
            • 17883
            • 1,039 Posts
            Needed to secure a single page today and it was a breeze. The above plugin seems to query unnecessarily often, the new API makes it a lot easier. Additionally I added a placeholder for including external scripts (be sure they are available with https). This is important, otherwise your page does is not fully trusted by the browsers (only partial). So:

            [[+urlType]] is "http" or "https" whether you check the "encryption" TV or not. In my case I have custom Google webfonts which are included like this:
            <link href='[[+urlType]]://fonts.googleapis.com/css?family=Droid+Sans:regular,bold&subset=latin' rel='stylesheet' type='text/css'>


            Here is the "revolutionized" plugin (same settings as above, check onWebPageInit and use a TV "encryption" with options yes==1:
            if ($modx->event->name == 'OnWebPageInit') { 
            	//CONFIGURATION
            	// server paths - no trailing slash!
            	$secureserver = "https://fgm-factoring.de";
            	$insecureserver = "http://fgm-factoring.de";
            	$resourceId = $modx->resourceIdentifier;
            	$encryption = FALSE;
            	$urlType = 'http';
            	$doc = $modx->getObject('modResource', $resourceId);
            	$secure = $doc->getTVValue('encryption'); 
            	if($secure=='1') {
            		$encryption = TRUE;
            		$urlType = 'https'; 
            		} 
            	$modx->setPlaceholder('urlType',$urlType);
            	$url = $_SERVER['REQUEST_URI'];
            	$ssl = FALSE;
            	if($_SERVER['HTTPS'] == 1)  {
            		    $ssl =  TRUE;
            	} elseif ($_SERVER['HTTPS'] == 'on'){
            		    $ssl =  TRUE;
            	} elseif ($_SERVER['SERVER_PORT'] == 443) {
            		$ssl = TRUE;
            	}
            	 
            	// switch between http / https if necessary
            	// if $secureserver === $insecureserver (eg you are testing locally)
            	// then comment out this code block to avoid infinite recursion
            	if($encryption && !$ssl) {
            		 // if SSL off and we are about to access a secure page then redirect
            		$modx->sendRedirect($secureserver.$url);
            	} else if ($ssl && !$encryption) {
            		// if SSL is on and we are about to acccess an unsecure page then redirect
            		$modx->sendRedirect($insecureserver.$url);
            	}
            }



            See sample page here: Factoring Vergleich Anfrage
              • 17016
              • 138 Posts
              MadeMyDay´s solution is working fine. The only disadvantage of this method is that the 404-page does not work anymore. Maybe because of the included OnWebPageInit-call which might overwrite the 404-function of MODx?

              Is it maybe possible to add another 404-check at the end of this script making both features (https and 404) work?

              Letti
                • 22303 MODX Staff
                • 10,725 Posts
                I believe this plugin needs to be invoked by OnLoadWebDocument rather than OnWebPageInit. It also can then use $modx->resource rather than querying for the Resource itself. This will ensure that proper ACL permissions are respected and will allow the MODx error_page and unauthorized_page to work properly.
                  • 17016
                  • 138 Posts
                  OpenGeek,

                  thanks a lot. Does this mean that we just have to replace the line
                  if ($modx->event->name == 'OnWebPageInit') {

                  by
                  if ($modx->event->name == 'OnLoadWebDocument') {

                  and
                  $resourceId = $modx->resourceIdentifier;

                  by
                  $resourceId = $modx->resource;


                  Is this correct?
                    • 17016
                    • 138 Posts
                    Ok, how much do we have to pay to make this SSL-plugin work correctly? Is there anybody who can solve this problem and make us an offer?
                      • 5340
                      • 1,624 Posts
                      Can you add

                      $modx->log(modX::LOG_LEVEL_ERROR,’Testing: ’ . $resourceId);

                      after

                      $resourceId = $modx->resourceIdentifier;

                      and send me the output from the console log when the plugin runs on an a 404 page or a page that doesn’t work for you?