We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 6705
    • 79 Posts
    MODx users in the European Union will be aware of the EU Directive 2009/136/EC which amends the Privacy and Electronic Communications Regulations such that websites now require user consent to set cookies (except where such cookies are absolutely strictly necessary to the functioning of the website).

    I'm currently reviewing my websites in preparation for the law coming into effect in my country, and I notice that MODx always sets a cookie "SNalphanumeric" whenever a visitor visits one of my sites. I'm assuming that this is a session indicator cookie of some kind.

    Does MODx actually use this cookie for any purpose, or is it only created for the convenience of the web developer, should they need to track a session for a particular reason? Is it possible to disable the creation of this cookie where it is not needed? (Or is it actually necessary for MODx to function properly?)

    (I'm not commenting on cookies set when a site manager logs in, because these presumably are necessary?)


    Thanks for any advice.

      Please don't PM me unless it's absolutely essential: if a technical question is worth asking, it's worth asking in public, so that others can share their experience, and so that all can learn from the answers.
      • 22303 MODX Staff
      • 10,725 Posts
      In the latest version of MODX Revolution (v2.2.1), you can disable sessions for a front-end context, but you will disable any ability to control permissions within or track user sessions in that context. See this blog post for more information.
        • 6705
        • 79 Posts
        Thanks for your reply, opengeek. I presume from what your blog post says that there is not a similar solution for MODx Evolution?

        My sites work fine when visited with cookies disabled (as we don't knowingly use sessions), although of course they are needed to use the site manager area. I'm guessing that it's not realistically possible (without substantial code rewriting) to not set the session cookie when a page is visited normally (when the cookie is not really needed for us) but do set it when the manager area is accessed? That sounds like good enough grounds for "essential to the operation of the website" to me.
          Please don't PM me unless it's absolutely essential: if a technical question is worth asking, it's worth asking in public, so that others can share their experience, and so that all can learn from the answers.
          • 22303 MODX Staff
          • 10,725 Posts
          Quote from: david55 at May 02, 2012, 04:26 AM
          Thanks for your reply, opengeek. I presume from what your blog post says that there is not a similar solution for MODx Evolution?
          AFAIK it is not possible to disable sessions for the site front-end in Evolution (someone correct me if I missed something).
            • 28439
            • 222 Posts
            Quote from: david55 at May 01, 2012, 09:51 AM
            MODx users in the European Union will be aware of the EU Directive 2009/136/EC which amends the Privacy and Electronic Communications Regulations such that websites now require user consent to set cookies (except where such cookies are absolutely strictly necessary to the functioning of the website).

            If you want some features, as login, or language settings, you need the session information.
            There is only one way, to avoid them, by adding everything as parameter to the page call. But then you end up very fast with a length, that is not supported by Microsoft's fantastic IE.
            In the end, you have got two choices: Using cookies, for what they where made for, or cut down features.

            But you simply said the solution: Keep cookies, because you need them for a usable website.

            If that is not enough, file a ticket, or develop the solution by yourself, or ask (and pay) someone to do the job for you.
              Gone away and found a better place to stay
              • 26903
              • 1,336 Posts
              I don't think anyone is saying get rid of cookies, to comply don't we just have to put up a box on the login screen saying 'This site uses cookies, it won't work without them.....' If the user doesn't consent you can't login for instance. The site doesn't have to work if the user doesn't consent as far as I read it.

              ( Butting in here but this has cropped up at work., interested to see what MODX will do if anything.)
                Use MODx, or the cat gets it!
                • 39830
                • 1 Posts
                I have changed config.inc.php so it does not set a session by default.

                It works with a script to prompt to allow cookies as per ico.gov.uk

                It does not seem to to effect the non logged in part and if login is needed then that could be exempt as with the right wording sign-in could be consent.

                // start cms session
                if(!function_exists('startCMSSession')) {
                function startCMSSession(){
                global $site_sessionname;
                session_name($site_sessionname);
                session_start();
                $cookieExpiration= 0;
                if (isset ($_SESSION['mgrValidated']) || isset ($_SESSION['webValidated'])) {
                $contextKey= isset ($_SESSION['mgrValidated']) ? 'mgr' : 'web';
                if (isset ($_SESSION['modx.' . $contextKey . '.session.cookie.lifetime']) && is_numeric($_SESSION['modx.' . $contextKey . '.session.cookie.lifetime'])) {
                $cookieLifetime= intval($_SESSION['modx.' . $contextKey . '.session.cookie.lifetime']);
                }
                if ($cookieLifetime) {
                $cookieExpiration= time() + $cookieLifetime;
                }
                if (!isset($_SESSION['modx.session.created.time'])) {
                $_SESSION['modx.session.created.time'] = time();
                }
                }
                // to be used with checkcookies script
                if (isset($_COOKIE['allowcookies'])) {
                if ($_COOKIE['allowcookies']==true) {
                setcookie(session_name(), session_id(), $cookieExpiration, MODX_BASE_URL);
                }
                }
                }
                }
                  • 3647
                  • 177 Posts
                  Hi Mark

                  This seems great and makes a lot of sense, however even after doing this I am still getting a session cookie set. Did this work for you?

                  what I have also found is that the session.cookie.lifetime value in system_settings is set to
                  604800 (a year) but reducing the setting to 86400 (a week) actually seems to make no difference.