What type of mod is needed to ensure that the login for modx uses sessions (which requires the header to every page)? Has anyone tried this before? Thanks for any help.
Can you explain what you’re looking for a bit better? As far as I know, the MODx Manager login uses a session cookie to store login info unless you check the Remember Me box on the login screen (which is easy to remove if you like). Are you asking about Manager logins or web user logins?
-
☆ A M B ☆
- 24,524 Posts
Yes, MODx uses session cookies. Which session file to use has to be passed somehow. Using cookies is far more secure than using the URL query string for passing the session ID. Although to a large extent that also depends on your PHP configuration.
If you are really serious about session security, you’ll use "session_save_path" or an entry in your .htaccess file to move the session files out of the default tmp directory (again this default location depends on your PHP configuration), although that means you’ll have to deal with the stale session files yourself, since normal garbage collection won’t remove them. You can even use a database for storing the session data.
Thanks for the clarification. Modx is already making use of sessions, and only using the cookies to send session data. I appreciate the security tip as well. Any other tips for making Modx as secure as possible?
-
☆ A M B ☆
- 24,524 Posts
Host it on a server that uses some form of suexec for PHP so that you don’t have to have any folders or files world-readable. Make sure your config.inc.php and index.php files are read-only. Have intelligent passwords. If you can, store your database login and password off of your web root, and include the file in the config.inc.php file so that you don’t have them anywhere in your web root. Subscribe to the
security mailing list. If you make snippets or modules study up on secure PHP and MySQL coding practices. That’s about all I can come up with off the top of my head...
And of course, make absolutely sure that register_globals is OFF. Don’t use your main account password for your database also. And if your server allows for encrypted FTP connections, always do so to avoid your password being sent in the clear.