We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 25803 ☆ A M B ☆
    • 721 Posts
    Hello,

    Just installed Revo 2.2.7 on a new server and ran into some issues with the installer unable to create certain folders. Filed a report with the admin and they opened up some permissions but want to close them down afterward for security reasons.

    I've found the following threads on the subject:

    https://forums.modx.com/index.php?topic=43923.0
    https://forums.modx.com/thread/77745/folder-permissions-on-operational-site

    The first one contains a link that no longer works (it goes to a Ngnix setup page). I can't really translate what either of these threads say to the server admin because I can't quite grasp what they mean.

    I gather that a php user on the server needs to be able to write to and remove files in certain folders (removal for example when removing packages).

    Content publishers in the system also need to be able to upload/remove files, and create folders (I've used media sources and ACLs to limit non admin users in the back end of MODX to be limited to manipulating files and folders under a folder at root called contentfiles so they never see the full file system, whereas the admin user can see the full file system and would have to be able to update and remove files, such as .css, .js, and images.

    Of course, the ftp user would also have to be able to manually delete the files in core/cache from time to time.

    With all that in mind, how would I explain that technically to the hosting provider?