We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 21819
    • 6 Posts
    Free.fr is a very popular adsl provider in france. It offer free web hosting with php and mysql.

    Free had some security limitation wich make modx unable to run properly. Some french people had made patches for a few modx versions 0.9.6rc3 and 0.9.2.1 , but are not easily found on the web, theses modx versions are not downloadable (only on CVS!), and modx appear to depend on hypothetic home made patches maintained or not by few independant peoples. Users will be afraid !

    Despite, joomla (a very popular CMS in France) had built in feature that allow him to work out of the box on free.fr.

    With minimal changes on modx code, it will work on free and could become popular

    Free.fr deactivate set_include_path and ini_set. For coders, it wouldn’t be very painfull to use explicit relative path to avoid php being unable to find included files in the right folder.
    Could you implement this. It would be more secure to be done by coder with good knowledge of modx, than with php beginners trying to patch only lines, without considering the whole code.

    Thanks for negatives or positives replies
    I could help to do some part of the job
      • 25663 MODX Staff
      • 12,272 Posts
      If this doesn’t have any detrimental impact to the installed base, we’d be happy to implement a patch to the core to make this work. Can you provide a location of the patched version of MODx so we can evalutate them?
        Ryan Thrash, MODX Co-Founder
        Follow me on Twitter at @rthrash or catch my occasional unofficial thoughts at thrash.me
        • 21819
        • 6 Posts
        Thanks for your reply

        Resolving the probleme consist to modify the use of include_once.
        Normally the include, if the string do not start with ./, will search fist in the include_path and secondly in the script folder itself.
        Modx uses many include_once() without ./ at start.
        With free.fr and probably many other providers, ini_set and set_includepath are disabled.
        So the files located in the manager/include folder are not reachable.
        ex of error in manager/index.php
        Warning: include_once(quotes_stripper.inc.php) [function.include-once]: failed to open stream: No such file or directory in /mnt/147/sdb/f/b/[i][user_login][/i]/modx0961/manager/index.php on line 90
        
        Warning: include_once() [function.include]: Failed opening 'quotes_stripper.inc.php' for inclusion (include_path='/mnt/147/sdb/f/b/[i][user_login][/i]/include:.:/usr/php5/lib/php') in /mnt/147/sdb/f/b/user.login/modx0961/manager/index.php on line 90


        There the line 90 wich is:
        include_once "quotes_stripper.inc.php";

        sould be modified to:
        include_once "./includes/quotes_stripper.inc.php";

        In fact modx should work without lines 80 to 85 of manager/inde.php:
        $incPath = str_replace("\\","/",dirname(__FILE__)."/includes/"); // Mod by Raymond
        if(version_compare(phpversion(), "4.3.0")>=0) {
            set_include_path($incPath); // this now works, above code did not?
        } else {
            ini_set("include_path", $incPath); // include path the old way
        }

        I wanted to change every include without ./ but i wonder if it would stay hidden errors that i couldn’t find (i’m a beginner in php and in modx). So could you help me doing this job !

        So modx would work with provider which disable setting php.
        I’m not a php specialist but this modif don’t seem to be hard to handle and it could help many people and make modx more stable in difficult environnement

        You can found post related to this topic and link to différents patches there: http://modxcms.com/forums/index.php/topic,4992.0.html ou http://modxcms.com/forums/index.php/topic,19316.0.html.
        Here the oldest topic about this:
        http://modxcms.com/forums/index.php?topic=1527.0
        davidm seem to be the patch maintener for france, but no fonctionnal release since 0.9.6

        direct link to a zipped patched files for 0.9.6 version: http://modxcms.com/forums/index.php?action=dlattach;topic=19316.0;attach=6013
          • 25663 MODX Staff
          • 12,272 Posts
          This would need to be thoroughly tested and could affect modules as well, meaning they might need to be updated in order to be compatible with this modification. It probably makes sense to do this as a separate feature branch and test the heck out of this before releasing to the broader community.
            Ryan Thrash, MODX Co-Founder
            Follow me on Twitter at @rthrash or catch my occasional unofficial thoughts at thrash.me
            • 10487 MODX Staff
            • 1,535 Posts
            Why:
            include_once "./includes/quotes_stripper.inc.php";
            And not:
            include_once MODX_BASE_PATH.'manager/includes/quotes_stripper.inc.php';

            Would that solve that particular issue?
              Garry Nutting
              Senior Developer
              MODX, LLC

              Email: [email protected]
              Twitter: @garryn
              Web: modx.com
              • 21819
              • 6 Posts
              I prefer the second way it is more safe and consistant !(i’m php and modx beginner, my opininon hasn’t much experience !)
              For lazy coder why don’t use shorter way ?

              include_once MODX_MANAGER_PATH.'includes/quotes_stripper.inc.php';
              

              The biggest work is to find every include_once or require, which rely on the php setting include_path, and to replace it.


              To my opinion, modx will work fine for everyone with this modif, it will be just a little longer to type
               MODX_MANAGER_PATH.'includes/
              
              after require or include.
              The settings of the include_path code (found in manager/index.php) could be maintained for compatibility with other modules.
              Other modules, dependant on include_path, won’t work, but only on set_include_path disabled servers, which is already the case. The net gain will be that modx will work out of the box for this kind of server.
              Secondly, other modules could be corrected.

              In fact i don’t know how modx development is managed, if there is a guide to unify coding methods.

              What do u think of it ?

                • 22303 MODX Staff
                • 10,725 Posts
                MODX_MANAGER_PATH . ’includes/...’ is definitely the correct way to do this. I’ll set-up a branch for these changes shortly; will someone make sure there is a JIRA ticket that covers this change and where we can track progress, testing, etc.?