Needed to secure a single page today and it was a breeze. The above plugin seems to query unnecessarily often, the new API makes it a lot easier. Additionally I added a placeholder for including external scripts (be sure they are available with https). This is important, otherwise your page does is not fully trusted by the browsers (only partial). So:
[[+urlType]] is "http" or "https" whether you check the "encryption" TV or not. In my case I have custom Google webfonts which are included like this:
<link href='[[+urlType]]://fonts.googleapis.com/css?family=Droid+Sans:regular,bold&subset=latin' rel='stylesheet' type='text/css'>
Here is the "revolutionized" plugin (same settings as above, check onWebPageInit and use a TV "encryption" with options yes==1:
if ($modx->event->name == 'OnWebPageInit') {
//CONFIGURATION
// server paths - no trailing slash!
$secureserver = "https://fgm-factoring.de";
$insecureserver = "http://fgm-factoring.de";
$resourceId = $modx->resourceIdentifier;
$encryption = FALSE;
$urlType = 'http';
$doc = $modx->getObject('modResource', $resourceId);
$secure = $doc->getTVValue('encryption');
if($secure=='1') {
$encryption = TRUE;
$urlType = 'https';
}
$modx->setPlaceholder('urlType',$urlType);
$url = $_SERVER['REQUEST_URI'];
$ssl = FALSE;
if($_SERVER['HTTPS'] == 1) {
$ssl = TRUE;
} elseif ($_SERVER['HTTPS'] == 'on'){
$ssl = TRUE;
} elseif ($_SERVER['SERVER_PORT'] == 443) {
$ssl = TRUE;
}
// switch between http / https if necessary
// if $secureserver === $insecureserver (eg you are testing locally)
// then comment out this code block to avoid infinite recursion
if($encryption && !$ssl) {
// if SSL off and we are about to access a secure page then redirect
$modx->sendRedirect($secureserver.$url);
} else if ($ssl && !$encryption) {
// if SSL is on and we are about to acccess an unsecure page then redirect
$modx->sendRedirect($insecureserver.$url);
}
}
See sample page here:
Factoring Vergleich Anfrage