We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 24917
    • 2 Posts
    What type of mod is needed to ensure that the login for modx uses sessions (which requires the header to every page)? Has anyone tried this before? Thanks for any help.
      • 33372
      • 1,611 Posts
      Can you explain what you’re looking for a bit better? As far as I know, the MODx Manager login uses a session cookie to store login info unless you check the Remember Me box on the login screen (which is easy to remove if you like). Are you asking about Manager logins or web user logins?
        "Things are not what they appear to be; nor are they otherwise." - Buddha

        "Well, gee, Buddha - that wasn't very helpful..." - ZAP

        Useful MODx links: documentation | wiki | forum guidelines | bugs & requests | info you should include with your post | commercial support options
        • 28042 ☆ A M B ☆
        • 24,524 Posts
        Yes, MODx uses session cookies. Which session file to use has to be passed somehow. Using cookies is far more secure than using the URL query string for passing the session ID. Although to a large extent that also depends on your PHP configuration.

        If you are really serious about session security, you’ll use "session_save_path" or an entry in your .htaccess file to move the session files out of the default tmp directory (again this default location depends on your PHP configuration), although that means you’ll have to deal with the stale session files yourself, since normal garbage collection won’t remove them. You can even use a database for storing the session data.
          Studying MODX in the desert - http://sottwell.com
          Tips and Tricks from the MODX Forums and Slack Channels - http://modxcookbook.com
          Join the Slack Community - http://modx.org
          • 24917
          • 2 Posts
          Thanks for the clarification. Modx is already making use of sessions, and only using the cookies to send session data. I appreciate the security tip as well. Any other tips for making Modx as secure as possible?
            • 28042 ☆ A M B ☆
            • 24,524 Posts
            Host it on a server that uses some form of suexec for PHP so that you don’t have to have any folders or files world-readable. Make sure your config.inc.php and index.php files are read-only. Have intelligent passwords. If you can, store your database login and password off of your web root, and include the file in the config.inc.php file so that you don’t have them anywhere in your web root. Subscribe to the security mailing list. If you make snippets or modules study up on secure PHP and MySQL coding practices. That’s about all I can come up with off the top of my head... wink
              Studying MODX in the desert - http://sottwell.com
              Tips and Tricks from the MODX Forums and Slack Channels - http://modxcookbook.com
              Join the Slack Community - http://modx.org
              • 33372
              • 1,611 Posts
              And of course, make absolutely sure that register_globals is OFF. Don’t use your main account password for your database also. And if your server allows for encrypted FTP connections, always do so to avoid your password being sent in the clear.
                "Things are not what they appear to be; nor are they otherwise." - Buddha

                "Well, gee, Buddha - that wasn't very helpful..." - ZAP

                Useful MODx links: documentation | wiki | forum guidelines | bugs & requests | info you should include with your post | commercial support options