We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 37815
    • 25 Posts
    Hi I have just started making my first site in Modx Evolution, version 1.0.5, running on windows win 7. Everything works fine except for when I try to save a new snippet or chunk I get the error above. I have checked and it is not a permission issue as I am logged in as administrator and I am they only user at present. I even tried re installing it in case it was an error with the installation but no luck. Can any one else suggest what the problem might be please? Thanks.

    This question has been answered by bridgetdesigns. See the first response.

      • 28042 ☆ A M B ☆
      • 24,524 Posts
      Sounds like an issue with the server's mod_security or suhosin security settings. http://wiki.modxcms.com/index.php/What_is_mod_security_and_how_does_it_affect_me
        Studying MODX in the desert - http://sottwell.com
        Tips and Tricks from the MODX Forums and Slack Channels - http://modxcookbook.com
        Join the Slack Community - http://modx.org
        • 37815
        • 25 Posts
        I found this article earlier and tried everything it suggests but with no success...
          • 37815
          • 25 Posts
          Actually, I have checked and I can save chunks, just not snippets.
          • discuss.answer
            • 37815
            • 25 Posts
            This has now been sorted. I contacted my host who changed some settings and it works perfectly now.
              • 10525
              • 247 Posts
              I have just encountered (and solved) this problem while trying to add the snippet Quill to my Evo 1.0.12 site.
              (Here it is here: http://modx.com/extras/package/quill).

              I noticed that the new snippet would save, just not with its content. I tried adding a comment:
              <?php
              //Hello
              ?>
              This saved ok.

              Then I tried adding the snippet content line by line, eventually finding that the line which triggered the error was the first line:
              require_once($modx->config['base_path'].'assets/snippets/quill/quill.class.inc.php');
              

              I changed this to:
              include_once($modx->config['base_path'].'assets/snippets/quill/quill.class.inc.php');
              
              and, shocker! It worked!

              A wee bit of reading around and I found this page, http://wiki.modxcms.com/index.php/Creating_Snippets, with this:
              Also, use include_once() instead of include(), require() and require_once() to prevent the files from being included many times if snippet is run multiple times on a page. You must use $modx->config['base_path'] in the path to the include file to support enviroments that have open_basedir restriction in effect.
              There is an implication here that require_once is not so good, but no explanation.

              Puzzlingly, a few lines further down the same page we see:

              For example, a good snippet would have the config parameters in the snippet TPL, include its actual logic in an external PHP file, and be run via a class instantiation and method calls. i.e.:

              <?php
                  require_once($modx->config['base_path']."assets/snippets/paintboard/paintboard.inc.php");
                   
                  $PaintBoard = new PaintBoard(array(
                  'width' => 400,
                  ...

              so I'm not sure how seriously the problem with require_once is taken.

              This page, http://wiki.modxcms.com/index.php/What_is_mod_security_and_how_does_it_affect_me, with all the suggested solutions to get round problems caused by the Apache module mod_security, does not mention this issue with require_once. Maybe someone could add it as a first thing to check before making changes to .htaccess files?

              May I also suggest to authors of older snippets that it would be worth getting in and editing your code to replace require_once with include_once? It would help extend their lives a bit.

              I hope this saves someone from losing the hours that I lost smiley

              A final word:
              I opened a snippet that was installed with 1.0.12 (Ditto) and it wouldn't save! I tried another and it did (Jot). Neither contained require_once, so I'm guessing there are other key words in there that mod_security doesn't like. Is there a list of these dodgy words anywhere?... [ed. note: Gav last edited this post 12 years, 10 months ago.]
                • 10525
                • 247 Posts
                Going back to http://wiki.modxcms.com/index.php/What_is_mod_security_and_how_does_it_affect_me, I tried every suggested fix and all of them broke my site. I'm guessing that none of these were allowed by my shared hosting.

                For those out there that get a "fix" from their hosting company, such as bridgetdesigns above, beware what it is that they are actually doing. Ask them. More relevant info on this issue here:

                https://forums.modx.com/thread/12975/403-error-when-editing-in-the-manager-mod-security#dis-post-72305