I know this is technical, but it'd be great to get some feedback from the sys-admin types. I run the ModSecurity (aka mod_sec or mod_security) on my VPS server, and I have to be really vigilant about it shutting down various manager functions. I added a page to the wiki on how to whitelist rules:
http://rtfm.modx.com/display/revolution20/Installation+on+a+server+running+ModSecurity
My goal here is to come up with a thorough set of rules that can be installed on any server running MODX Revolution. If anyone is running ModSecurity on their servers and can share their white list rules, it'd be great. Stuff like saving PHP snippets, plugins, or saving TVs with @SELECT bindings can often cause ModSecurity to shut down a request, and it can be maddening to figure out why the manager just doesn't seem to work.
So please share your white rules here!