We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 36434
    • 33 Posts
    Hi i have a strange issue with my spform. Only in the beginnig when I fill it in, submit gives me a page with unauthorized in it. When i refresh the page and do the same thing, it works perfectly!

    The only thing I can find about the 'unauthorized'-issue is that I have to correct my formprocAllowedReferers

    but this is correct

    i can send you the website by request
      • 3749
      • 24,544 Posts
      Try this: look at the URL in the browser's address line for both accesses to the page. If they are different, it should give you a clue about how to change the allowed referrers.
        Did I help you? Buy me a beer
        Get my Book: MODX:The Official Guide
        MODX info for everyone: http://bobsguides.com/modx.html
        My MODX Extras
        Bob's Guides is now hosted at A2 MODX Hosting
        • 36434
        • 33 Posts
        only the domain right with and without www..?

        the add-on allready did that for me and that is correct

        the page with the contactform is :
        http://www.mywebsite.nl/contact/
        thank you page:
        http://www.mywebsite.nl/contact/bedankt/

        formProcAllowedReferers:
        www.mywebsite.nl,mywebsite.nl
          • 3749
          • 24,544 Posts
          Do you see a different domain name when it doesn't work?

          Try uncommenting the section in .htaccess that forces all URLs to www.mywebsite.nl (or the opposite).
            Did I help you? Buy me a beer
            Get my Book: MODX:The Official Guide
            MODX info for everyone: http://bobsguides.com/modx.html
            My MODX Extras
            Bob's Guides is now hosted at A2 MODX Hosting
            • 36434
            • 33 Posts
            when I clear my cookies, the first reaction on my contact submit =

            Unauthorized Access in spformproc

            PHPSESSID=6bf09cc7db76c46300ec4cee149b2fa1
            ================================================

            I have acces to my htaccess but I don't now which part you mean, and do I have to remove the # to activate it?:

            # MODX supports Friendly URLs via this .htaccess file. You must serve web
            # pages via Apache with mod_rewrite to use this functionality, and you must
            # change the file name from ht.access to .htaccess.
            #
            # Make sure RewriteBase points to the directory where you installed MODX.
            # E.g., "/modx" if your installation is in a "modx" subdirectory.
            #
            # You may choose to make your URLs non-case-sensitive by adding a NC directive
            # to your rule: RewriteRule ^(.*)$ index.php?q=$1 [L,QSA,NC]
            
            RewriteEngine On
            RewriteBase /
            
            
            
            # Rewrite www.domain.com -> domain.com -- used with SEO Strict URLs plugin
            #RewriteCond %{HTTP_HOST} .
            #RewriteCond %{HTTP_HOST} !^example-domain-please-change\.com [NC]
            #RewriteRule (.*) http://example-domain-please-change.com/$1 [R=301,L]
            #
            # or for the opposite domain.com -> www.domain.com use the following
            # DO NOT USE BOTH
            #
            #RewriteCond %{HTTP_HOST} .
            #RewriteCond %{HTTP_HOST} !^www\.example-domain-please-change\.com [NC]
            #RewriteRule (.*) http://www.example-domain-please-change.com/$1 [R=301,L]
            
            
            
            # Rewrite secure requests properly to prevent SSL cert warnings, e.g. prevent 
            # https://www.domain.com when your cert only allows https://secure.domain.com
            #RewriteCond %{SERVER_PORT} !^443
            #RewriteRule (.*) https://example-domain-please-change.com.com/$1 [R=301,L]
            
            
            
            # The Friendly URLs part
            RewriteCond %{REQUEST_FILENAME} !-f
            RewriteCond %{REQUEST_FILENAME} !-d
            RewriteRule ^(.*)$ index.php?q=$1 [L,QSA]
            
            
            
            # Make sure .htc files are served with the proper MIME type, which is critical
            # for XP SP2. Un-comment if your host allows htaccess MIME type overrides.
            
            #AddType text/x-component .htc
            
            
            
            # If your server is not already configured as such, the following directive
            # should be uncommented in order to set PHP's register_globals option to OFF.
            # This closes a major security hole that is abused by most XSS (cross-site
            # scripting) attacks. For more information: http://php.net/register_globals
            #
            # To verify that this option has been set to OFF, open the Manager and choose
            # Reports -> System Info and then click the phpinfo() link. Do a Find on Page
            # for "register_globals". The Local Value should be OFF. If the Master Value
            # is OFF then you do not need this directive here.
            #
            # IF REGISTER_GLOBALS DIRECTIVE CAUSES 500 INTERNAL SERVER ERRORS :
            #
            # Your server does not allow PHP directives to be set via .htaccess. In that
            # case you must make this change in your php.ini file instead. If you are
            # using a commercial web host, contact the administrators for assistance in
            # doing this. Not all servers allow local php.ini files, and they should
            # include all PHP configurations (not just this one), or you will effectively
            # reset everything to PHP defaults. Consult www.php.net for more detailed
            # information about setting PHP directives.
            
            #php_flag register_globals Off
            
            
            
            # For servers that support output compression, you should pick up a bit of
            # speed by un-commenting the following lines.
            
            #php_flag zlib.output_compression On
            #php_value zlib.output_compression_level 5
            
            
            
            # The following directives stop screen flicker in IE on CSS rollovers. If
            # needed, un-comment the following rules. When they're in place, you may have
            # to do a force-refresh in order to see changes in your designs.
            
            #ExpiresActive On
            #ExpiresByType image/gif A2592000
            #ExpiresByType image/jpeg A2592000
            #ExpiresByType image/png A2592000
            #BrowserMatch "MSIE" brokenvary=1
            #BrowserMatch "Mozilla/4.[0-9]{2}" brokenvary=1
            #BrowserMatch "Opera" !brokenvary
            #SetEnvIf brokenvary 1 force-no-vary
            
              • 36434
              • 33 Posts
              the phpsessID issue can be solved by adding:

              <?php
              
              ini_set('session.use_trans_sid', 0);
              
              ini_set(‘session.use_only_cookies’, 1);
              
              ?>


              but which config file should contain this? and where do I put it?

              and adding:
              php_flag session.use_trans_sid off
              
              php_flag session.use_only_cookies on


              this gave me an error page (500)
                • 3749
                • 24,544 Posts
                Many hosts don't allow PHP directive in the .htaccess file. You may be able to accomplish the same thing in a php.ini file.

                As for .htaccess, I meant to uncomment (by removing the #) one of the following sections (but not both)
                # Rewrite www.domain.com -> domain.com -- used with SEO Strict URLs plugin
                #RewriteCond %{HTTP_HOST} .
                #RewriteCond %{HTTP_HOST} !^example-domain-please-change\.com [NC]
                #RewriteRule (.*) <a href="http://example-domain-please-change.com/$1" target="_blank" rel="nofollow">http://example-domain-please-change.com/$1</a>  [R=301,L]
                #
                # or for the opposite domain.com -> www.domain.com use the following
                # DO NOT USE BOTH
                #
                #RewriteCond %{HTTP_HOST} .
                #RewriteCond %{HTTP_HOST} !^www\.example-domain-please-change\.com [NC]
                #RewriteRule (.*) <a href="http://www.example-domain-please-change.com/$1" target="_blank" rel="nofollow">http://www.example-domain-please-change.com/$1</a>  [R=301,L]


                Note that the directives should each be on one line, not wrapped as shown here.
                  Did I help you? Buy me a beer
                  Get my Book: MODX:The Official Guide
                  MODX info for everyone: http://bobsguides.com/modx.html
                  My MODX Extras
                  Bob's Guides is now hosted at A2 MODX Hosting
                  • 36434
                  • 33 Posts
                  ok i had contact with my provider and it says i can't edit the serveroptions

                  but i can try to add
                  ini_set('session.use_only_cookies', true);
                  ini_set('session.use_trans_sid', false);

                  but where?

                  in the head of my template?

                  <?php
                  ini_set('session.use_only_cookies', true);
                  ini_set('session.use_trans_sid', false);


                  should be with the php tag right?
                    • 3749
                    • 24,544 Posts
                    No, that won't work. It would have to go either in index.php or in a snippet with a tag for that snippet in the template. IOW, put this in the template:

                    [[FixCookies]]


                    And create a snippet called FixCookies with the code you posted above. In index.php, it could go as you posted it, but altering index.php is not recommended because it may be overwritten when you upgrade MODX. [ed. note: BobRay last edited this post 14 years, 9 months ago.]
                      Did I help you? Buy me a beer
                      Get my Book: MODX:The Official Guide
                      MODX info for everyone: http://bobsguides.com/modx.html
                      My MODX Extras
                      Bob's Guides is now hosted at A2 MODX Hosting