We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 17016
    • 138 Posts
    @bertoost
    I don´t know why but your snippet doesn´t work on our sites while the snippet above works. Are there any adaptions necessary to make it work? As far as I understand it correctly you changed a couple of lines from the first snippet above (e. g. if($modx->event->name == ’OnLoadWebDocument’))
    Is this code-line better than "if ($modx->event->name == ’OnWebPageInit’)"?
      • 3186 ☆ A M B ☆
      • 279 Posts
      Quote from: Letti at Mar 03, 2011, 06:48 AM

      @bertoost
      I don´t know why but your snippet doesn´t work on our sites while the snippet above works. Are there any adaptions necessary to make it work? As far as I understand it correctly you changed a couple of lines from the first snippet above (e. g. if($modx->event->name == ’OnLoadWebDocument’))
      Is this code-line better than "if ($modx->event->name == ’OnWebPageInit’)"?

      See the comments above.. Thats why I changed the event. Notice that you need to check that event instead of ’OnWebPageInit’.

      The above plugin code (not a snippet) wasn’t working correctly for me and the current resource was queried again ($modx->getObject(...)), that isn’t needed because it’s in $modx->resource. So that’s why I changed some things. It makes it a lot easier and shorter too!

      [edit]

      also the defined URL’s are not needed because $modx->makeUrl(); generates this when you give the fourth parameter with ’http’ or ’https’.. I changed this because I don’t want to setup the URL’s, this must be automatic because we’re working with a local, test and live envoirement.
        MODX Ambassador (NL) & Professional MODX developer
        Follow me on Twitter | Visit my page on Facebook | View my code on Github | View my script posts
        MODX e-commerce solution SimpleCart
        • 5340
        • 1,624 Posts
        @beerhost

        Can you explain why you changed the event? I took that part from the Evo version.

        Thanks
          • 3186 ☆ A M B ☆
          • 279 Posts
          Quote from: OpenGeek at Dec 06, 2010, 01:15 PM

          I believe this plugin needs to be invoked by OnLoadWebDocument rather than OnWebPageInit. It also can then use $modx->resource rather than querying for the Resource itself. This will ensure that proper ACL permissions are respected and will allow the MODx error_page and unauthorized_page to work properly.

          Because OpenGeek has write this! I think he knows what he’s talking about!
            MODX Ambassador (NL) & Professional MODX developer
            Follow me on Twitter | Visit my page on Facebook | View my code on Github | View my script posts
            MODX e-commerce solution SimpleCart
            • 5340
            • 1,624 Posts
            :)
              • 21740
              • 17 Posts
              Hello everyone,

              I was wondering if there is a built-in or more "stable" option available as of now for securing single documents with SSL?

              Thanks,
              Andreas
                • 21740
                • 17 Posts
                Sorry, just saw that the last posts are from March 2011 smiley It works like a charm!

                Thanks,
                Andreas
                  • 17403 ☆ A M B ☆
                  • 183 Posts
                  Another solution without adding TV to resources.

                  First, go to system settings (or context setting)

                  • add force_ssl key (default value = 0)
                  • add force_ssl_ids, and let the value empty for now
                  • if your https domain/subdomain is different from site_url, add ssl_site_url key (value = 'www.httpsdomain.com')

                  Back to above setting, if you want to force HTTPS for all pages, set force_ssl value to 1, otherwise you can add any pages id to force_ssl_ids key (comma separated id, ex. 3,30,60).

                  Second, create a plugin "makeSSL" and attach OnLoadWebDocument event to it.

                  <?php
                  //name: makeSSL plugin
                  //event: OnLoadWebDocument 
                  $https_port= $modx->getOption('https_port','none',443); 
                  $isSecure= ($_SERVER['SERVER_PORT'] == $https_port || (isset($_SERVER['HTTPS']) && strtolower($_SERVER['HTTPS'])=='on')) ? 1 : 0;
                  if ($isSecure) return;
                  
                  if ($modx->context->get('key') != 'mgr') {
                      $force_ssl = (int)$modx->getOption('force_ssl', 0, 0);
                      $force_ssl_ids = $modx->getOption('force_ssl_ids', null, null);
                      if ($force_ssl_ids) {
                          $force_ssl_id = explode(",", $force_ssl_ids);
                      }
                  
                      //return if secure or no ssl
                      if (!$force_ssl && !$force_ssl_ids) return;
                  
                      $cID = $modx->resourceIdentifier;
                      $site_url = $modx->getOption('site_url', '', '');
                      $ssl_site_url = $modx->getOption('ssl_site_url', '', $site_url);
                      if ($site_url == $ssl_site_url) {
                          $sslUrl = $modx->makeUrl($cID,'','','https');
                      } else {
                          $sesName = session_name();
                          $sesId   = session_id();
                          $sslUrl = 'https:' . '//' . $ssl_site_url.$modx->makeUrl($cID,array($sesName=>$sesId),'','');
                      }
                  
                      if ($force_ssl) {
                          $modx->sendRedirect($sslUrl);
                      } elseif (in_array($cID, $force_ssl_id)) {
                          $modx->sendRedirect($sslUrl);
                      }
                  } else {
                      $force_ssl_manager = $modx->getOption('force_ssl_manager', '', '');
                      if (empty($force_ssl_manager)) return;
                      //$sslUrl = $modx->makeUrl(-1,'','','https');
                      //if ($force_ssl_manager == 'all') {
                      //    $modx->sendRedirect($sslUrl);???
                      //} elseif ($force_ssl_manager == 'login' && $modX->user->isAuthenticated('mgr') ) {
                      //    $modx->sendRedirect($sslUrl);???
                      //}
                  }
                  


                  @zaenal

                  Note: I think many of us using shared SSL, and it should be more easier if (just "if") modx->makeURL() function could recognize site_url for http and ssl_site_url for https. [ed. note: lokamaya last edited this post 14 years, 11 months ago.]
                    zaenal.lokamaya
                    • 31902
                    • 342 Posts
                    Okay, brain-fart time. The plugin is sending the page over to the secure side okay, correct URL but with HTTPS, but it is showing up as a 404. Something simple going wrong there... any suggestions?
                      • 6357
                      • 10 Posts
                      I've read through the available threads on revoSSL. I installed revossl-1.0-pl2.

                      I can sink the Manager in HTTPS but can't get a single web page to do likewise. I followed the recommendation to change the trigger event to OnLoadWebDocument by modifying ssl.php in core/components/revoSSL/elements/plugins.

                      I also forced my test page to load fresh every time per this: https://forums.modx.com/?action=thread&thread=66876&i=1.

                      ModX's error logs contain nothing, so I'm a bit perplexed. Is anyone else experiencing this or have a fix?