I have just encountered (and solved) this problem while trying to add the snippet
Quill to my Evo 1.0.12 site.
(Here it is here:
http://modx.com/extras/package/quill).
I noticed that the new snippet would save, just not with its content. I tried adding a comment:
This saved ok.
Then I tried adding the snippet content line by line, eventually finding that the line which triggered the error was the first line:
require_once($modx->config['base_path'].'assets/snippets/quill/quill.class.inc.php');
I changed this to:
include_once($modx->config['base_path'].'assets/snippets/quill/quill.class.inc.php');
and, shocker! It worked!
A wee bit of reading around and I found this page,
http://wiki.modxcms.com/index.php/Creating_Snippets, with this:
Also, use include_once() instead of include(), require() and require_once() to prevent the files from being included many times if snippet is run multiple times on a page. You must use $modx->config['base_path'] in the path to the include file to support enviroments that have open_basedir restriction in effect.
There is an implication here that
require_once is not so good, but no explanation.
Puzzlingly, a few lines further down the same page we see:
For example, a good snippet would have the config parameters in the snippet TPL, include its actual logic in an external PHP file, and be run via a class instantiation and method calls. i.e.:
<?php
require_once($modx->config['base_path']."assets/snippets/paintboard/paintboard.inc.php");
$PaintBoard = new PaintBoard(array(
'width' => 400,
...
so I'm not sure how seriously the problem with
require_once is taken.
This page,
http://wiki.modxcms.com/index.php/What_is_mod_security_and_how_does_it_affect_me, with all the suggested solutions to get round problems caused by the Apache module
mod_security, does not mention this issue with
require_once. Maybe someone could add it as a first thing to check before making changes to .htaccess files?
May I also suggest to authors of older snippets that it would be worth getting in and editing your code to replace
require_once with
include_once? It would help extend their lives a bit.
I hope this saves someone from losing the hours that I lost
A final word:
I opened a snippet that was installed with 1.0.12 (Ditto) and it wouldn't save! I tried another and it did (Jot). Neither contained require_once, so I'm guessing there are other key words in there that
mod_security doesn't like. Is there a list of these dodgy words anywhere?...
[ed. note: Gav last edited this post 12 years, 10 months ago.]