We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 32234
    • 6 Posts
    I'm pretty new to modx but am really enjoying the flexibility.

    I have set up a website for my daughter's kindergarten and want to allow the teachers to log in to the front end to edit the text on the pages. Initially I installed 2.2.4-pl (traditional) on my test server and used TinyMCE (4.3.3) and NewsPublisher (1.4.2). This works great. I can log in to the front-end (using Login), see an edit button and then click on this to get a rich-text editing environment with just the page content visible.

    Now that everyone is happy with the website I have moved it to the kindergarten's account. I took the opportunity to upgrade to 2.2.8-pl (traditional) following the instructions in the wiki. Now, however, when I edit a page that has some modx code in it, the tags are removed when I click submit. TinyMCE and NewsPublisher are the same versions and I have copied the database and install from one account to another.

    Are there new settings in 2.2.8-pl that I should be aware of or is this issue unrelated to the version upgrade?

    Any help would be much appreciated. I'd really like to get the website up and fully functional before my daughter leaves the kindergarten smiley

    Thanks for your help,

    Graham
      • 28042 ☆ A M B ☆
      • 24,524 Posts
      I think that's the System Setting 'Allow tags in post'. It's set to 'No' by default.

      If false, all POST variables will be stripped of HTML script tags, numeric entities, and MODX tags. MODX recommends to leave this set to false for Contexts other than mgr, where it is set to true by default.

      That sounds backwards for some reason, but anyway try setting that value to Yes.
        Studying MODX in the desert - http://sottwell.com
        Tips and Tricks from the MODX Forums and Slack Channels - http://modxcookbook.com
        Join the Slack Community - http://modx.org
        • 3749
        • 24,544 Posts
        You should be aware that setting Allow Tags in Post to true has some security implications. I don't think they affect NewsPublisher, but since it's a global setting, any forms on the site that use post as a method and don't properly sanitize their input might allow people to execute snippets on your site or expose system settings.

        You might try adding this code at line 234 of the core\components\newspublisher\model\newspublisher\newspublisher.class.php file:

        if (!$this->modx->hasPermission('allow_modx_tags')) {
            $this->modx->SetOption('allow_tags_in_post', true);
        }


        That would change the setting just for NewsPublisher. I'm not sure it would work, but it might.

        If you try it, let me know.
          Did I help you? Buy me a beer
          Get my Book: MODX:The Official Guide
          MODX info for everyone: http://bobsguides.com/modx.html
          My MODX Extras
          Bob's Guides is now hosted at A2 MODX Hosting
          • 32234
          • 6 Posts
          Thanks for the suggestions. Since I posted I realised that I could use a TV to set whether the snippet is required or not and that way the modx tags don't feature in the RTE editor. This is preferable in this situation but only really works because the web page is so simple. I'll have a look at trying both suggestions with another website that I'm setting up and report back.

          Thanks again for your help,

          Welly

          Update: Setting the allow_tags_in_post worked but the NewsPublisher change didn't. Thanks for the heads up about the security issue, I'll bear that in mind when I'm designing this next site. [ed. note: welly last edited this post 13 years, 3 months ago.]
            • 3749
            • 24,544 Posts
            Oops, I pasted that code from another section and didn't notice the exclamation point. It should be:

            if ($this->modx->hasPermission('allow_modx_tags')) {
                $this->modx->SetOption('allow_tags_in_post', true);
            }


            I'd really appreciate it if you'd give that a try.

              Did I help you? Buy me a beer
              Get my Book: MODX:The Official Guide
              MODX info for everyone: http://bobsguides.com/modx.html
              My MODX Extras
              Bob's Guides is now hosted at A2 MODX Hosting
              • 32234
              • 6 Posts
              Quote from: BobRay at Jul 03, 2013, 04:07 PM
              Oops, I pasted that code from another section and didn't notice the exclamation point.

              I should have looked more closely as well! I'll have a try this evening and get back to you.

              Cheers

              Graham
                • 32234
                • 6 Posts
                Quote from: BobRay at Jul 03, 2013, 04:07 PM
                I'd really appreciate it if you'd give that a try.

                Just tried and it still didn't work, thanks for the suggestion. I'm going to use a TV to remove this piece of code from the content area to get around the issue.

                Thanks again to both of you for you quick response.

                Cheers

                Graham