Hello!
two days ago I upgraded to the RC3, then my manager page stopped working! It doesn’t get its data anymore. I get
[tt]{"success":false,"message":"Access denied.","total":0,"data":[],"object":[]}[/tt]
all the time.
I use jquery for everything, not modext. Just now I figured out that the other ajax requests send this HTTP_MODAUTH thing. It must be a new thing in RC3 cause in RC2 it worked fine.
How can I fix this in my script?
I appreciate your help! Thanks JB
Thanks a lot! This is new isn’t it? It would be great if you add this to the manual. Before I’ve compared it to the other ajax requests, I serached quite a while in the source for bugs...
Update: I think it’s mentioned in the manual. This must be the "Secured AJAX requests in manager+connectors" feature. Is there more information about this and how it improves security? I’m just curious.
It mainly shuts down the obscure, but often reported in security sites case where if a user logs into the manager, and then visits a malicious site, the malicious site would use their browser session to run an AJAX request via either JS or a hidden iframe. That request would be targeted at the connectors, which would then allow the malicious site to run any connector in the mgr - including ones that delete resources, files, etc.
The RC-3 fix adds the custom var that is known only by your MODx install, so that a session can’t be ’hijacked’ like above, since no requests without the auth var can go through.
shaun mccormick | bigcommerce mgr of software engineering, former modx co-architect |
github |
splittingred.com
-
☆ A M B ☆
- 24,524 Posts
Can you post some links to more information on this? I’m beginning to use a lot of jQuery and AJAX in my sites, including in modules. Could this become a problem? Or does this only effect Revo with its connectors model?
It only occurs when you try to access the core connectors. If you’re building your own connectors, or sending AJAX requests to MODx Resources, you wont have this issue.
shaun mccormick | bigcommerce mgr of software engineering, former modx co-architect |
github |
splittingred.com
Right; it also applies when you use the core connectors ’index.php’ file, as you are doing there.
Glad to see it working.
shaun mccormick | bigcommerce mgr of software engineering, former modx co-architect |
github |
splittingred.com
-
☆ A M B ☆
- 1,056 Posts
Quote from: splittingred at Jul 12, 2010, 01:38 PM
It was added to prevent middleman attacks on connectors.
It’s a pretty easy fix; just ensure that every request to the connectors passes this PHP variable:
in either:
a) An HTTP header of ’modAuth’
b) or, A REQUEST variable of ’HTTP_MODAUTH’
And that’ll do it.
Awesome news, guys! This is a great addition to Revo!