Quote from: BobRay at May 23, 2010, 01:34 AM
Would some (or maybe all) of those issues be solved by running an upgrade install after moving the site to the root?
Only some; the bugs I mentioned are related...which is why I described how to manually make the changes to the config file, etc.
Quote from: Everett at May 23, 2010, 12:32 PM
I can taste a tutorial in the works: how to secure your MODx site by putting the manager directory somewhere else on your server for limited access...
Definitely; you can, at install time in the advanced distribution, put your manager directory anywhere you want, and name it what you want. This is why each of the main directories in Revolution uses a config.core.php to locate the core (which can also be located anywhere on the server; putting the core outside the webroot for instance will be a recommended best practice).
Quote from: Everett at May 23, 2010, 12:32 PM
What is going to be recommended best practices here for securing a site in this manner? The manager has to be accessible via the web... say you put it on a domain that’s behind a firewall that only allows connections from your office... are there other tactics that could be deployed to make the manager less vulnerable?
Freedom is the key here; we’re trying to make it so you can secure it in whatever way makes the most sense for your environment. So yes, as long as the web is accessible to the web in some way, you can hide it on internal network domains, and/or obscure it’s location with a crazy folder name, etc. I’d love to hear other ideas as well...
Quote from: Everett at May 23, 2010, 12:32 PM
I think this may be a first for the MODx forums, but I’m posting from South Park, CO.
You bastard! And you didn’t come through Taos?