We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 17499 ☆ A M B ☆
    • 872 Posts
    +1

    I always have a local working copy of my websites.
    I even use MySQLYog or equivalent to have a mirror of the sql database, and sync the data between local and foreign db at will.
      • 3749
      • 24,544 Posts
      Your problem had nothing to do with Evo or Revo (or MODX). Someone installed an add-on that requires LDAP authentication. That’s why you couldn’t log in.

      If you edit the file named in the error message and put one of these at the top:,
      return;
      return 1;
      return 0;

      You may get in.
        Did I help you? Buy me a beer
        Get my Book: MODX:The Official Guide
        MODX info for everyone: http://bobsguides.com/modx.html
        My MODX Extras
        Bob's Guides is now hosted at A2 MODX Hosting
        • 29091
        • 88 Posts
        Quote from: BobRay at Aug 25, 2010, 02:59 PM

        Your problem had nothing to do with Evo or Revo (or MODX). Someone installed an add-on that requires LDAP authentication. That’s why you couldn’t log in.

        If you edit the file named in the error message and put one of these at the top:,
        return;
        return 1;
        return 0;

        You may get in.
        I agree, the problem had nothing to do with the MODx program. However, when I installed MODx it made sure that it could run on my system and went ahead if it could. Since the add-on requires something more than the base platform that MODx is happy running on, either the MODx plug-in installer, or the installer for the plug-in, should have checked to see if it was compatible with my system.

        The reason this is important is because the download and install takes place in the manager and gives no warning of extra requirements in order to run.

        You seem to be so worried about blame. I installed this stuff because of the requirements of the project. Blame me. But MODx Revolution’s add-on installer still needs to be fixed. At the very least it should warn the person downloading, installing & managing (activating) add-ons of any special requirements beyond what is required by the MODx CMS itself. It does NOT. This is a blatant disregard for the Mission Critical nature of anyone’s website (I don’t care if it is only offering info on beanie babies, websites need to be up 100% of the time and this is a huge leap backwards in website uptime and web application dependability). This needs to be addressed as it is a huge freaking design flaw, a complete blackhole in Revolution’s security. And I don’t care if it offends you that I am writing how Revolution is flawed when it works so well for you, this is not meant to offend, it is meant to assist with the development of a huge gapping security hole that needs to be addressed as Revolution is further developed. HOW to address it might not be right, but it really is a designed-in bug that needs to be addressed.

        Remember, I have used Evolution on a couple of sites before. It had won me over because of its ease to design for, method of enabling the designer as a developer, its ease of use, its RELIABILITY, DEPENDABILITY and SECURITY.

        The captcha should not have been allowed to activate upon a simple installation, either.

        Yes, based on my professional experience with MODx, I was confident that MODx would inform me if there was something wrong, at least notify me if something special was required. It did not. Furthermore, it activated these installs without any intervention from me. That is just plain wrong.

        At the very least, I should have seen a "What to Expect Upon Installation" message so that I would know that the captcha would install itself. So that I knew Active Directory would mess-up my login if I did not have LDAP authentication installed, previously.

        I know you are very close to the project, so you are taking these criticisms personally. You should not. Unfortunately, you have established a personal relationship with your baby and I am undermining that relationship by being so very critical of your baby. But my goal is not to strike down your baby, but make you reinvent your baby so that this sort of crap does NOT happen ever again. So that you can’t be offended in such a way, ever again.

        The fact is that because the project is your baby, even if you have no code input, you want to nurture it along and make it better. I have found these huge gapping flaws in it and you see this as an attack on the product. But it isn’t, it is merely me being frustrated because I can’t get the assistance I need. Because the ONLY DOCUMENTATION IS NEVER ONLINE. Because I work at night when (and because) there is no interuptions at all, which is also when everyone else is asleep. Because I started posting asking for help a while back and never got a single response. Because I have to whine like a baby to get ANY response.

        Don’t get me wrong, I’m not yelling at you, BobRay, or lossendae, or virtualgadjo. BobRay, you appear to have finally come-up with the solution that I would’ve needed to continue using Revolution. lossendae, you are right, I cannot run Revolution because I have never (since installing it) EVER seen the documentation. I have a couple books all about Evolution, so I won’t have to worry about some stupid online wiki that NEVER works. And virtualgadjo has pointed out that now technology has changed and I CAN mirror a database on a local system (if I set it up with direct access, which is actually another security hole I have to think about taking). Then again, I don’t have any problems backing up the database from the remote, having to reinstall if something catastrophic occurred to the database and website, because nothing ever has unless it was hacked, in which case I never trusted it again (never wanted to reinstall, had to leave the site down so that no one would get ripped-off/offended and report the whole thing to the authorities, leaving the site down to protect its reputation).

        We all have our ways, and in my own way, I am trying to help. As a designer and a user interface expert, I see huge gaping flaws in the design of this new system. I’ve alerted you. Please do NOT take offense. I think these are real big issues from a usability point-of-view that no one is taking seriously. The lack of access to the wiki documentation alone will destroy any chance the Revolution will ever have of being succeeding, so I am sure you guys are busy trying to fix that, and it isn’t good timing, so you are pretty frustrated too, I bet.

        But just as MODx is your baby, it is mine, too. I make my living on it and I stand on its success or failure. I live or die by it because nothing else has ever worked for me before. MODx does, and it does it briliantly. Well, MODx Evolution did. Revo will, with my help, IF you LISTEN to me.

        Yes, I am taking it personally, too. So I apologize for being so damn insistent, but this is important to me. I know you are listening, but I also know that you aren’t understanding. So I am even more frustrated. I have a stake in the success or failure of MODx ...so of course I need to to work, to act right, do the job well and reliably, securely. Because this is the best thing to come along since php scripting, which is too much for me to get my head around. MODx Evolution works and I need Revolution to do so at least as well. It isn’t, not right now.

        That’s why I removed it. Now I go install Evolution. I will install Revolution on one of my own sites. I won’t install the captcha or active directory add-ons (I did learn something!). The client needs fool-proof 100% reliable dependability that is 100% secure and well documented.

        Seriously, Thanks guys...
        Revolution will Evolve, too.
        -Doug
          Doug Peters, Symbiotic Design. (605) 251-8973
          http://W3DN.com | http://www.DomainHostmaster.com
          • 17499 ☆ A M B ☆
          • 872 Posts
          I’m not frustrated by the fact that you don’t like Revolution, in the contrary, i always try to understand what can be improved (or not) because i’m an enthusiast like many people on this forum.
          MODx is free, and we try to help you for free too.

          Try to see it from an outside point of view:
          - We have no direct access/view to your server
          - Most of us try to guess what could have happened
          - Given the fact that you seem stressed out by soon to be meeting with your client, and your past experience with MODx Evo who seemed to be good, we’re tried to lead you to the most efficient road for your problem with our knowledge and capacity

          On this topic, you should really check the advice from BobRay, since he pointed something that could be interesting (even from an outsider):


          Someone installed an add-on that requires LDAP authentication. That’s why you couldn’t log in.

          If Bobray is wrong, we could search for another solution.
          If Bobray is right, you would have learnt something, and since you’re concerned by security, you could check your server log to see who could have installed an LDAP plugin.

          Don’t take us wrong, we’re really trying to help you here.
            • 3749
            • 24,544 Posts
            Sorry, I didn’t mean to sound defensive -- I was posting from an iPod and couldn’t be as diplomatic as I would have liked. I just wanted to make it clear to anyone reading the thread that the MODx platform itself had no bearing on the problems. That’s the reason that no add-ons are installed with Revolution.

            Any CMS will lock you out if you install a login add-on that won’t work in your environment. And, if you think about it, there’s no way for MODx to know what any add-on is going to do, so it just isn’t possible to refuse to install an add-on that might cause trouble. With non-login addons, you can always uninstall the component, but as you learned, that’s not possible with login components. It’s up to the add-on developer to include any safeguards.

            I’m the author of the Revolution version of CAPTCHA and it could certainly be disabled by default. The thing is that, as soon as you turned it on, you’d be right where you were. The assumption is that you won’t install it unless you want it on and it works fine on over 99% of all platforms. What you saw usually means that the host didn’t enable GD and FreeType, which is fairly rare. If I can figure out how to do it and find some time, I’ll have it check for GD and FreeType during the install and, if they’re not there, disable the plugin and issue a message about it. Short of that, I can’t think of anything that would avoid your issue, and even with that safeguard, it will still lock you out if GD and/or FreeType are misconfigured.

            The LDAP plugin could possibly do the same, but again, it’s not an unreasonable assumption that only people with LDAP support would want to install it. Though I admit that I’m not familiar with that plugin at all.

            I’m sorry I didn’t get my solutions to you sooner.
              Did I help you? Buy me a beer
              Get my Book: MODX:The Official Guide
              MODX info for everyone: http://bobsguides.com/modx.html
              My MODX Extras
              Bob's Guides is now hosted at A2 MODX Hosting
              • 28042 ☆ A M B ☆
              • 24,524 Posts
              This whole discussion is an excellent example of why having a development environment is such a good idea. Nothing should ever be done to a live site until it’s working nicely on the dev environment (whether on a local workstation or a separate MODx installation on the same server as the live site).

              Even then, do a full backup before making any functional changes to a live site; one can never be sure how different server configurations will affect things.
                Studying MODX in the desert - http://sottwell.com
                Tips and Tricks from the MODX Forums and Slack Channels - http://modxcookbook.com
                Join the Slack Community - http://modx.org
                • 29091
                • 88 Posts
                LOL...

                Don’t worry about the timeliness of the solution. It was awesome. I’m the one that is working in the middle of the night, by choice. No one else works when I do. I simply couldn’t get any info with the wiki down and it has been down everytime I tried it since I downloaded Revolution.

                As far as what MODx should and should not know, I think that’s a matter for debate. The idea that it shouldn’t will leave it open to bad plug-ins and user frustration. The idea of a CMS is to hide the design and development aspects and code from the end user, allowing him/her to concentrate solely on content. I think it is important that plug-ins, and their installers, meet specific standards.

                However, note that I did not install any login stuff, I thought I was installing the same stuff as I had previously (including the captcha, which I would use to prevent spam in my contact form) plus the active DIRECTORY, which I understood to be an easy way to manage a links directory of related resources (which was specifically requested by the client).

                Since it is obvious that Evo is more stable and better documented, this needs to be the solution for the client. I did install Revo on one of my own sites and will again on others, as I want to take advantage of it. Unfortunately, I won’t be installing or upgrading any new websites, as it is a sin to me, for a web app (and even if it is a cms, that’s still all it is, a web app) to take a website down for any length of time.

                I would like to know where to go to edit that ugly red alarming message. Then I might re-consider never upgrading a website. But for now, MODx has proven that it is not mission critical by throwing up a proprietary message and interupting the business of the website. That too, should be an option, and it is another design flaw that goes back to Evolution.

                Nevertheless, that’s my take. We, as designers and developers can stay in our separate schools of thought and defend our views, or we can work together to make a better product. That’s all you are trying to do. That’s all I’m trying to do.

                Really though, I do thank you...
                -Doug
                  Doug Peters, Symbiotic Design. (605) 251-8973
                  http://W3DN.com | http://www.DomainHostmaster.com
                  • 3749
                  • 24,544 Posts
                  Good points, and well put. The next version of CAPTCHA will have some protection and will be installed disabled.

                  Thanks for the feedback.
                    Did I help you? Buy me a beer
                    Get my Book: MODX:The Official Guide
                    MODX info for everyone: http://bobsguides.com/modx.html
                    My MODX Extras
                    Bob's Guides is now hosted at A2 MODX Hosting