This thing is driving me mad! It seems that I’m the only one with this problem, but I have this problem again and again, and it makes me unable to run my sites... it’s a very very big problem for me!
The situation is always the same: sometimes, with some websites, hitting the SAVE button of a snippet, a template or even a page, redirect the manager (or, better, the "central frame") to the initial page of the website (i.e. the frontend!). I cannot figure out what the hell is happening, I have tried lots of things, it seems that the problem appears when saving a lot of text (e.g. the snippet code, the page content, etc), but it is not a problem of field size, because I am able to save the same record using phpMyAdmin.
Please! can someone help?
Daniele "MadMage" Calisi
-
☆ A M B ☆
- 24,524 Posts
Sounds like a problem with the server’s mod_security setting. If you’re uploading something via POST that it doesn’t like, it will abort the upload, resulting in different server errors, depending on the server’s configuration. Try turning mod_security off in your .htaccess file.
http://modxcms.com/forums/index.php/topic,4399.msg32090.html#msg32090
-
MODX Staff
- 12,272 Posts
Turn it off just for the manager in the htaccess file in the manager folder... leave it on for the main htaccess in the site root. Maybe?
Ryan Thrash, MODX Co-Founder
Follow me on Twitter at @rthrash or catch my occasional unofficial thoughts at thrash.me
-
☆ A M B ☆
- 24,524 Posts
I really don’t know that much about it, but what I did was look around and get a hosting company that has php running as cgi and suexec, so I don’t have any folders/files with world-writable permissions. Also make sure anything you write that will access the database is validated and then run through $modx->db->escape() before using it in a query. And make sure that the php register_globals is off. I also set my config.inc.php file to read-only, so even scripts running as my user can’t mess with it. If I need to do anything with it, I go in with my ftp client and change the permissions, do what needs to be done, then set it back to read-only. Not all hosting companies allow that; I deal with two sites that insist on having the permissions set to read/write for owner.
Another thing I’ve done is to take the time and find out exactly what is bothering the mod_security. Usually it’s something like a variable named $cc for mailing. If that’s all it is, I just change the variable name.
And that’s a good idea, only setting it off for the manager folder.