We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 25551 ☆ A M B ☆
    • 1,231 Posts
    How can I edit my htaccess to force the use of HTTPS on every page as well as url rewrite for forcing people to arrive at https://www. if trying to access http://mysite or https://mysite

    Thanks!

      Ross Sivills - MD AugmentBLU Edinburgh, Scotland UK
      AugmentBLU - MODX Partner

      BLUcart - MODX Revolution E-Commerce & Shopping Cart
      • 26016
      • 561 Posts
      Hi,
      In the root of your MODx install, you’ll see a file called ht.access. This is an example .htaccess file which can be renamed. Take a look at those, and there’s example code for forcing "WWW..."

      For forcing HTTPS for your whole site, here’s an example of code would go in your .htaccess:

      RewriteEngine On
      RewriteCond %{SERVER_PORT} 80
      RewriteRule ^(.*)$ https://www.example.com/$1 [R,L]


      Of course, this assumes that you’re not using a Windows server, and that mod_rewrite is operating on your host. You may need to check with host tech support to ascertain that.

      Good luck, Dave
        MODx and Wordpress development
        Linux, PHP 5.2, MySQL 5.0, Evo 1.05, Revo 2.08-pl, Firefox 4
        • 5340
        • 1,624 Posts
        Just in case you want to secure only a few pages take a look at SSL Plugin + a secured manager .

        There’s also a fix for quick manager to work on a secure connection. Let me know if you need it.
          • 25551 ☆ A M B ☆
          • 1,231 Posts
          Thanks but how can I rewrite urls that do not include www. to force www. to be included. This is what I cannot get to work with forcing SSL.

          I have

          RewriteEngine On
          RewriteCond %{SERVER_PORT} 80
          RewriteRule ^(.*)$ https://www.example.com/$1 [R,L]

          but I want to stop the duplicate content issue with google.
            Ross Sivills - MD AugmentBLU Edinburgh, Scotland UK
            AugmentBLU - MODX Partner

            BLUcart - MODX Revolution E-Commerce & Shopping Cart
            • 25551 ☆ A M B ☆
            • 1,231 Posts
            Can someone help? I have SSL being forced but you can still access the site from https://site and https://www.
              Ross Sivills - MD AugmentBLU Edinburgh, Scotland UK
              AugmentBLU - MODX Partner

              BLUcart - MODX Revolution E-Commerce & Shopping Cart
              • 5340
              • 1,624 Posts

              Try this

              RewriteEngine on
              RewriteCond %{HTTP_HOST} !^www.your_domain.com$
              RewriteRule ^(.*)$ http://www.your_domain.com/$1 [R=301]
                • 25551 ☆ A M B ☆
                • 1,231 Posts
                Thanks Cipa but it’s not what I’m after.

                My current htaccess is like this.

                # For full documentation and other suggested options, please see
                # http://svn.modxcms.com/docs/display/MODx096/Friendly+URL+Solutions
                # including for unexpected logouts in multi-server/cloud environments
                # and especially for the first three commented out rules

                #php_flag register_globals Off
                #AddDefaultCharset utf-8
                #php_value date.timezone Europe/Moscow

                Options +FollowSymlinks
                RewriteEngine On
                RewriteBase /

                # Fix Apache internal dummy connections from breaking [(site_url)] cache
                RewriteCond %{HTTP_USER_AGENT} ^.*internal\ dummy\ connection.*$ [NC]
                RewriteRule .* - [F,L]

                # Rewrite domain.com -> www.domain.com -- used with SEO Strict URLs plugin
                RewriteCond %{HTTP_HOST} .
                RewriteCond %{SERVER_PORT} 80
                RewriteRule ^(.*)$ https://www.mysite.com/$1 [R=301,L]

                # Exclude /assets and /manager directories and images from rewrite rules
                RewriteRule ^(manager|assets)/*$ - [L]
                RewriteRule \.(jpg|jpeg|png|gif|ico)$ - [L]

                # For Friendly URLs
                RewriteCond %{REQUEST_FILENAME} !-f
                RewriteCond %{REQUEST_FILENAME} !-d
                RewriteRule ^(.*)$ index.php?q=$1 [L,QSA]

                # Reduce server overhead by enabling output compression if supported.
                #php_flag zlib.output_compression On
                #php_value zlib.output_compression_level 5


                This is forcing HTTPS like I want but it’s not redirecting those who try to access the site without www.

                I know there is no condition there to redirect those without using www. but everything I have tried has failed. It works if I use the default modx htacess settings but I want to use HTTPS on every page, this is what I cannot work out. The HTTPS snippet is of no use either as it does not work with SSL correctly, the padlock in the browser does not show so it doesn’t show as properly encrypted. Also the snippet messes with links as well so I want to control the HTTPS using htaccess so it does exactly what I want.
                  Ross Sivills - MD AugmentBLU Edinburgh, Scotland UK
                  AugmentBLU - MODX Partner

                  BLUcart - MODX Revolution E-Commerce & Shopping Cart