We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 24714
    • 19 Posts
    In doodles tutorial there’s a line:
    Don’t ever paste or share with anyone your $modx->siteId or HTTP_MODAUTH key. It keeps your site secure.

    I m a bit paranoic about this =) as if I hire content manager for a month or so, he will have hell lot of restrictions in manager, but all these restrictions are zero efficient as he can have HTTP_MODAUTH key by simply examinig the page in Firebug (or else) and after all parse with curl any propriety...

    Even if it is not possible, still anyone who hava access to manager can hook the HTTP_MODAUTH key.
      • 26903
      • 1,336 Posts
      You still have to be logged in to use it, you can’t just take the site id and inject requests to the manager using it alone, the attacker must first log in as a user.
        Use MODx, or the cat gets it!
        • 24714
        • 19 Posts
        That was clear from the session cookie - the question is -> can the user with limited rights inject request to the things he has no permission?
          • 28215
          • 4,149 Posts
          Quote from: Redjik at May 19, 2011, 09:08 AM

          That was clear from the session cookie - the question is -> can the user with limited rights inject request to the things he has no permission?
          No. All HTTP_MODAUTH does is prevent middleman attacks - someone hijacking your user session to run processors via connectors.
            shaun mccormick | bigcommerce mgr of software engineering, former modx co-architect | github | splittingred.com