We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 27889
    • 415 Posts
    Hello all, I’m back, sorry for the time but I had lot of problem (like loosing my hd, somes problem with my connection) and lot of work. No holidays for me sad

    About SQL injection, I don’t think there is a problem with the url because the fields are NOT used to do sql query but I will escape them, the fields in the forms are escaped to avoid any problem. I adding quote escaping. Tell me if I forgot something.
    Remember that this is a development version and it is not a good things to put on a production site!
    Working on a script parameter which allow to reg script only when the form is diplayed, so if you use tiny the library are only loaded when needed (in edition or add).
    Also I’m waiting for the new 0.9.7 which make the db.class easier and better to use, the package feature will help too.

    @swit4er your snippet looks great but I’ve read on the forum that there is security problem with using the file manager in the front end, can you check that.
    @perrine : I have added the anonymous parameter in the snippet.
    @smashingred : I will add a parameter to choose if the alias must be reset to pagetitle
    @smashingred, @ojt yes the tv must be preceded with "tv", this is in the doc.
    @JazzyNico, the date are stored as integer in the db, I think a small formatting with phx will do the job, I will check that.

    Stay tuned, the new version will come soon.
      MODx Sites & Prestations: http://dp-site.fr [Last MODx Site]
      MODx Repository: [HOME] [MetaTagsExtra] / Current Dev: [xFDM]
      • 22095
      • 30 Posts
      I’ve noted that when used on the same page as a Jot call, "@CODE:" shows up with the buttons. Removing the call to Jot makes the "@CODE:" go away.
        • 27889
        • 415 Posts
        This problem is already solved, wait for the next release, or rename the chunkie class file.
          MODx Sites & Prestations: http://dp-site.fr [Last MODx Site]
          MODx Repository: [HOME] [MetaTagsExtra] / Current Dev: [xFDM]
          • 29039
          • 58 Posts
          @Soda
          litle addition (just checking for array) to fdm.db.class.inc.php for work with may snipet
          	/***********************************************
          	  Setting TV value
          	  Added: Set only if Tv is available
          	************************************************/
          	function SetTV($tv,$value){
          		if(!is_array($this->tvs)) $this->tvs=array();
          		if(!is_array($this->tvNames)) $this->fillTVNames();
          //		if (isset($this->tvNames[$tv])) $this->tvs[$tv]=$value;
          // array check
          		if (isset($this->tvNames[$tv])) 
          		{
          			if (is_array($value)) {
          			$this->tvs[$tv]=implode("||",$value);
          			}
          			else {$this->tvs[$tv]=$value;}
          		}
          	}


          About filemanager. Yes, using default filemanager in fronend is very dangerus. I work for new filemanager snipet for FDM.
            • 22095
            • 30 Posts
            The following modification fixes the problem with publish dates not getting saved.
              /***************************************************
            	  Saving/Updating FdmDocument (escape fields added)
            	****************************************************/	
            	function Save(){ //escape added
            		global $modx;
            		$this->fields['editedon']=time(); 	
            		if($this->fields['pub_date']!=='0')  $this->fields['pub_date'] = strtotime($this->fields['pub_date']);
            		$tablename=$modx->getFullTableName('site_content'); 
              	$escapedFields = array_map(create_function('$n', 'global $modx;return $modx->db->escape($n);'), $this->fields);
            		if($this->isNew){
            			$this->fields['id']=$modx->db->insert($escapedFields, $tablename);
            			$this->isNew = false;
            		} else {
            			$id=$this->fields['id'];
            			$modx->db->update($escapedFields, $tablename, "id=$id");
            		}
            		unset($escapedFields);// free the array
            		if(is_array($this->tvs)) $this->saveTVs();
            	}
            	  


            And then this modification (line 278)
            	  	if (!class_exists('FdmDocument')) include_once($modx->config['base_path'].'assets/snippets/FDM/includes/fdm.db.class.inc.php');
            			$docObj = new FdmDocument($_SESSION['fdm']['source']);
            			$fields=array_merge($fields,$docObj->Gets());
            			unset($docObj);
            			
            			//fix time
            			if (isset($fields['pub_date'])){ 
            				$fields['pub_date'] = strftime("%d-%m-%Y %H:%M:%S", $fields['pub_date']);
            			}
            		
            			// comment modx tags
            			if (isset($fields['content'])){
            				$s=array ('[[','[!','[*','[+','[~','[(','{{','}}',')]',']]','!]','*]','+]','~]');
            				$r=array ('<!-- MODx Uncached Snippet ', '<!-- MODx Cached Snippet ','<!-- MODx Doc field ','<!-- MODx Placeholder ','<!-- MODx Link ','<!-- MODx Config ','<!-- MODx Chunk ',' END MODx Chunk -->',' END MODx Config -->',' END MODx Uncached Snippet -->', ' END MODx Cached Snippet -->',' END MODx Doc field -->',' END MODx Placeholder -->',' END MODx Link -->');
            				$fields['content']=str_replace($s,$r,$fields['content']);
            				debug_run('end mergefield-fields',$fields);
            			}	 
            			return $fields;
            		}

              • 27889
              • 415 Posts
              I will check those modifs.
                MODx Sites & Prestations: http://dp-site.fr [Last MODx Site]
                MODx Repository: [HOME] [MetaTagsExtra] / Current Dev: [xFDM]
                • 22095
                • 30 Posts
                Just one more... wink

                Switched to swedish and FDM didn’t like it.. tongue

                I’ll post once I’ve made the translation.

                PHP error debug
                Error: include_once(assets/snippets/FDM/lang/svenska-utf8.inc.php) [function.include-once]: failed to open stream: No such file or directory
                Error type/ Nr.: Warning - 2
                File: /home/web27463/domains/kulingvarning.nu/public_html/assets/snippets/FDM/includes/fdm.class.inc.php
                Line: 339
                Line 339 source: include_once(’assets/snippets/FDM/lang/’.$_SESSION[’fdm’][’language’].’.inc.php’);
                  • 27889
                  • 415 Posts
                  I want to tell you that I will wait to continue FDM development until the new modx 0.9.7 beta will available (or until I have a SVN access).
                  I don’t want to develop it in the wrong direction and to the same job twice. This new version of modx will help in a more robust FDM particularly for additional field. I hope it come soon, so don’t be afraid and wait.

                  FDM is not dead, just thinking how to be better.
                    MODx Sites & Prestations: http://dp-site.fr [Last MODx Site]
                    MODx Repository: [HOME] [MetaTagsExtra] / Current Dev: [xFDM]
                    • 21279
                    • 13 Posts
                    Hey,

                    I want to be able to manually set the document template without using a model. If I set a hidden field like so:
                    <input type="hidden" name="template" id="template" value="16" />

                    I get an email from eform like this:

                    Document or chunk not found for template id= ’’

                    Any help would be appreciated.

                    Cheers,
                    Ryan
                      • 27889
                      • 415 Posts
                      @Neubreed If you want to send an eform you must have the corresponding report template, see the eForm doc.
                        MODx Sites & Prestations: http://dp-site.fr [Last MODx Site]
                        MODx Repository: [HOME] [MetaTagsExtra] / Current Dev: [xFDM]