We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 25028
    • 16 Posts
    I have Rev 2.0pl (just updated to the latest release). This however was happening before with the July 15th pre-release. When I am modifying or creating a new chuck, the SAVE function does not save the chunk back into the db. I’ve tried this on Firefox and Chrome... neither work. I verified the new chuck was not written to the DB. This has been happening for 2 days now.

    Other save functions work.

    Any ideas?



      Regards...

      Rick
      • 28215
      • 4,149 Posts
      Need:

      - PHP/MySQL Version
      - Server
      - OS/Browser
      - Any errors in core/cache/logs/error.log
      - Codemirror installed?
      - Any custom security permissions
      - Any opcode caching systems, such as eAccelerator, APC, etc

      Also, you dont have HTML in the non-content fields of the Chunks, do you?
        shaun mccormick | bigcommerce mgr of software engineering, former modx co-architect | github | splittingred.com
        • 22303 MODX Staff
        • 10,725 Posts
        Sounds like some content in the chunk may be being rejected by mod_security rules implemented in your environment.
          • 25028
          • 16 Posts
          I’ll start to get the data for you.. Of note my error.log file is 139MB . Nearly all of the entries are like this:

          /:/usr/lib/php:/usr/local/lib/php:/tmp)
          [2010-08-03 10:25:26] (ERROR @ /home/daveydev/public_html/tek/core/xpdo/xpdo.class.php : 1668) PHP warning: json_encode() [<a href=’function.json-encode’>function.json-encode</a>]: recursion detected

          MySQL is 5.0.91 community
          PHP is 5.2.13

          Modx is 2.0.0-pl just installed

          System is a Centos x.xx server at my hosting com. liquidweb.com


          The save function does not create that error entry that I can see.

          More info in a bit

            Regards...

            Rick
            • 25028
            • 16 Posts
            If you need to see this, I can provide you credentials. It is a learning site for me while I learn Modx. Then it will become a live site on a different domain when it is done. Just tell me where I can send you the credentials privately.


            Rick
              Regards...

              Rick
              • 3749
              • 24,544 Posts
              Can you save a chunk that has just this name and content (with no HTML tags or quotes):




              Name: MyChunk

              Content: Some Content.


                Did I help you? Buy me a beer
                Get my Book: MODX:The Official Guide
                MODX info for everyone: http://bobsguides.com/modx.html
                My MODX Extras
                Bob's Guides is now hosted at A2 MODX Hosting
                • 25028
                • 16 Posts
                yes. saved fine
                  Regards...

                  Rick
                  • 3749
                  • 24,544 Posts
                  Quote from: rick9004 at Aug 03, 2010, 03:17 PM

                  yes. saved fine

                  Then it’s almost certainly mod_security.

                  See this: http://wiki.modxcms.com/index.php/What_is_mod_security_and_how_does_it_affect_me
                    Did I help you? Buy me a beer
                    Get my Book: MODX:The Official Guide
                    MODX info for everyone: http://bobsguides.com/modx.html
                    My MODX Extras
                    Bob's Guides is now hosted at A2 MODX Hosting
                    • 25028
                    • 16 Posts
                    Yes it was security. And I cannot turn off security for my site I guess. Tried every SecFilterEngine setting but my server throws an error when I try to use any of those commands in .htaccess. Did not try the snippet way yet.

                    I found the offending line in the snippet but it only happens when it is positioned in some part of the chunk file

                    for instance this was the chunk: (I changed a few of the identifiable items)
                    ________________________
                    <div class="softwareIntell">
                    Need to be more informed about Software? Read more on our site

                    <a href="http://www.somewhere.com">Software Intelligencer</a>
                    </div>




                    <a href="http://visitor.constantcontact.com/d.jsp?m=111&amp;p=oi" target="_blank">
                    <img alt="Newsletter sign up" src="/assets/images/NewsLetterSignUp.png" /></a>
                    <!-- BEGIN: Constant Contact Email Updates Button -->
                    <!-- END: Constant Contact Email Updates Button -->




                    <!-- BEGIN: Constant Contact Email Updates Button -->
                    <div class="leftBar">
                    <a href="/crmRestart.php" target="_self">
                    <img alt="CRM Re-Start program" src="/assets/images/crm_re-start.jpg" /></a>




                    </div>


                    _____________________

                    If I move this statement to the beginning of the chunk: <!-- BEGIN: Constant Contact Email Updates Button -->
                    it fails to write. I can’t see what really is the cause, but that line and some other line is failing the security.

                    Thanks everyone...


                      Regards...

                      Rick
                      • 25028
                      • 16 Posts
                      To put this to bed. I ending up working with my hosting company for my server. We made this change to my whitelist file for modsec2 (ip not actual)

                      SecRule REMOTE_ADDR "^192\.168\.0\.101$"
                      phase:1,nolog,allow,ctl:ruleEngine=Off

                      Then re-started Apache and now I can bypass all filtering on my post backs but just for my IP address.

                        Regards...

                        Rick