We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 19872
    • 1,078 Posts
    Just did a new install of MODx 2.2.8 on Apache/2.2.3 (CentOS).

    Few bumps here and there, most notably now is that when I navigate to my domain.com/manager, I see the index of the manager directory instead of the login page. If I click on index.php I do get the login, and all seems to be working fine. I can create a template, create a resource, etc. etc. all seems normal.

    I'm also used to the MODx site_start page being the default page that loads into the browser window. At the moment, the existing web site's index.html page still loads.

    Bit confused here as to whether this is a MODx install issue, or an issue with the server.

    I'm not getting any errors, and after a few tweaks to folder permissions here and there, all passed inspections. I'm installing this on a virtual server, so have spent the day learning a lot of server stuff that is a bit over my head.

    If anyone has any ideas, suggestions, reasons, they would be well-received, and greatly appreciated.
      • 19872
      • 1,078 Posts
      Hmmm?

      Perhaps I need to change ht.access to .htaccess

      Is this the reason why instead of the login page I see the entire contents of the manager directory?

        • 28042 ☆ A M B ☆
        • 24,524 Posts
        Your VPS web server configuration needs to have its index page setting allow index.php; it probably only has index.html right now. What is the web server? Apache?

        DirectoryIndex index.php index.html


        You can also set this in the .htacess file
          Studying MODX in the desert - http://sottwell.com
          Tips and Tricks from the MODX Forums and Slack Channels - http://modxcookbook.com
          Join the Slack Community - http://modx.org
          • 19872
          • 1,078 Posts
          Thank you. I saw reference to that in the ht.access that installed with MODx. So if I change the name to .htaccess I should be go to go?

          Question though. In that ht.access that installed with MODx is reference to register_globals OFF. I checked my site info, and register globals is OFF. So, I probably don't need the line included in the htaccess file right? Do I just delete that section from the htaccess. Is there harm in leaving it?

          This is that section:
          # If your server is not already configured as such, the following directive
          # should be uncommented in order to set PHP's register_globals option to OFF.
          # This closes a major security hole that is abused by most XSS (cross-site
          # scripting) attacks. For more information: http://php.net/register_globals
          #
          # To verify that this option has been set to OFF, open the Manager and choose
          # Reports -> System Info and then click the phpinfo() link. Do a Find on Page
          # for "register_globals". The Local Value should be OFF. If the Master Value
          # is OFF then you do not need this directive here.
          #
          # IF REGISTER_GLOBALS DIRECTIVE CAUSES 500 INTERNAL SERVER ERRORS :
          #
          # Your server does not allow PHP directives to be set via .htaccess. In that
          # case you must make this change in your php.ini file instead. If you are
          # using a commercial web host, contact the administrators for assistance in
          # doing this. Not all servers allow local php.ini files, and they should
          # include all PHP configurations (not just this one), or you will effectively
          # reset everything to PHP defaults. Consult www.php.net for more detailed
          # information about setting PHP directives.

          #php_flag register_globals Off
            • 28042 ☆ A M B ☆
            • 24,524 Posts
            If it's not necessary you can remove it. Or just leave it commented out.
              Studying MODX in the desert - http://sottwell.com
              Tips and Tricks from the MODX Forums and Slack Channels - http://modxcookbook.com
              Join the Slack Community - http://modx.org
              • 28042 ☆ A M B ☆
              • 24,524 Posts
              I've never seen the DirectoryIndex directive in the ht.access that comes with MODx.
                Studying MODX in the desert - http://sottwell.com
                Tips and Tricks from the MODX Forums and Slack Channels - http://modxcookbook.com
                Join the Slack Community - http://modx.org
                • 19872
                • 1,078 Posts
                Hi Susan:
                Yes, when I install MODx, there is a file included named ht.access. I changed the filename to .htaccess and then all was working fine.

                I can send you a copy if you like. It has a bunch of statements various bits of instructions with explainations as to what they do or why you might or might not need them.

                As I have now learned, there are many items that can be controlled through the servers master config. For example, folders without and index.html file would display the index of that directory. I was going to write Options -Indexes in the .htaccess file, but the support tech suggested they handle it at a higher level in the server config file.

                So far all seems to be working just perfect. I do have anxiousness about setting several folders to 777 as a means of getting the install to successfully complete. I probably need to read up a bit more and figure out if any of these pose a security risk. The following all had to be changed from 757 to 777 in order for the install to successfully complete.
                core/export
                core/packages
                mydomain.com/assets/
                mydomain.com/assets/components/
                mydomain.com/core/components/
                  • 19872
                  • 1,078 Posts
                  Here is the contents of the ht.access that appears after unpacking the MODx archive on the server.


                  # MODX supports Friendly URLs via this .htaccess file. You must serve web
                  # pages via Apache with mod_rewrite to use this functionality, and you must
                  # change the file name from ht.access to .htaccess.
                  #
                  # Make sure RewriteBase points to the directory where you installed MODX.
                  # E.g., "/modx" if your installation is in a "modx" subdirectory.
                  #
                  # You may choose to make your URLs non-case-sensitive by adding a NC directive
                  # to your rule: RewriteRule ^(.*)$ index.php?q=$1 [L,QSA,NC]

                  RewriteEngine On
                  RewriteBase /



                  # Rewrite www.domain.com -> domain.com -- used with SEO Strict URLs plugin
                  #RewriteCond %{HTTP_HOST} .
                  #RewriteCond %{HTTP_HOST} !^example-domain-please-change\.com [NC]
                  #RewriteRule (.*) http://example-domain-please-change.com/$1 [R=301,L]
                  #
                  # or for the opposite domain.com -> www.domain.com use the following
                  # DO NOT USE BOTH
                  #
                  #RewriteCond %{HTTP_HOST} .
                  #RewriteCond %{HTTP_HOST} !^www\.example-domain-please-change\.com [NC]
                  #RewriteRule (.*) http://www.example-domain-please-change.com/$1 [R=301,L]



                  # Rewrite secure requests properly to prevent SSL cert warnings, e.g. prevent
                  # https://www.domain.com when your cert only allows https://secure.domain.com
                  #RewriteCond %{SERVER_PORT} !^443
                  #RewriteRule (.*) https://example-domain-please-change.com/$1 [R=301,L]



                  # The Friendly URLs part
                  RewriteCond %{REQUEST_FILENAME} !-f
                  RewriteCond %{REQUEST_FILENAME} !-d
                  RewriteRule ^(.*)$ index.php?q=$1 [L,QSA]



                  # Make sure .htc files are served with the proper MIME type, which is critical
                  # for XP SP2. Un-comment if your host allows htaccess MIME type overrides.

                  #AddType text/x-component .htc



                  # If your server is not already configured as such, the following directive
                  # should be uncommented in order to set PHP's register_globals option to OFF.
                  # This closes a major security hole that is abused by most XSS (cross-site
                  # scripting) attacks. For more information: http://php.net/register_globals
                  #
                  # To verify that this option has been set to OFF, open the Manager and choose
                  # Reports -> System Info and then click the phpinfo() link. Do a Find on Page
                  # for "register_globals". The Local Value should be OFF. If the Master Value
                  # is OFF then you do not need this directive here.
                  #
                  # IF REGISTER_GLOBALS DIRECTIVE CAUSES 500 INTERNAL SERVER ERRORS :
                  #
                  # Your server does not allow PHP directives to be set via .htaccess. In that
                  # case you must make this change in your php.ini file instead. If you are
                  # using a commercial web host, contact the administrators for assistance in
                  # doing this. Not all servers allow local php.ini files, and they should
                  # include all PHP configurations (not just this one), or you will effectively
                  # reset everything to PHP defaults. Consult www.php.net for more detailed
                  # information about setting PHP directives.

                  #php_flag register_globals Off



                  # For servers that support output compression, you should pick up a bit of
                  # speed by un-commenting the following lines.

                  #php_flag zlib.output_compression On
                  #php_value zlib.output_compression_level 5



                  # The following directives stop screen flicker in IE on CSS rollovers. If
                  # needed, un-comment the following rules. When they're in place, you may have
                  # to do a force-refresh in order to see changes in your designs.

                  #ExpiresActive On
                  #ExpiresByType image/gif A2592000
                  #ExpiresByType image/jpeg A2592000
                  #ExpiresByType image/png A2592000
                  #BrowserMatch "MSIE" brokenvary=1
                  #BrowserMatch "Mozilla/4.[0-9]{2}" brokenvary=1
                  #BrowserMatch "Opera" !brokenvary
                  #SetEnvIf brokenvary 1 force-no-vary
                    • 10208 ☆ A M B ☆
                    • 1,780 Posts
                    Try turning off compress_css and compress_js in the system_settings table in the db.
                      Frogabog- MODX Websites in Portland Oregon
                      "Do yourself a favor and get a copy of "MODX - The Official Guide" by Bob Ray. Read it.
                      Having server issues? These guys have MODX Hosting perfected - SkyToaster
                      • 28042 ☆ A M B ☆
                      • 24,524 Posts
                      What permissions are needed depend on how the server is configured. If the server invokes PHP as an Apache module, the .php file (in our case the index.php file) is run as the Apache user (usually "apache", "nobody" or "www"), not as your user. This means that the files and directories that you uploaded as your user can't be written to or deleted by the Apache user, so permissions have to be set to 777 for directories and 666 for files, which means that everybody can write to them (as in moving uploaded images into place, automatically editing configuration files or writing cache files). This also leads to cases where MODx has uploaded or automatically written files as the Apache user, so you can't edit or delete these files from your FTP client, since you aren't the file's owner, the Apache user is. This is common with Gallery type add-ons.

                      If some form of "suexec" is used, then the user is switched (Switch User EXECute) to exectute the PHP file to be the user of whoever owns the file (your FTP user). In this case, permissions of 755 for directories and 644 for files is used; only the owner can write, while all other users (such as the Apache user) can only read the files and directories. This is obviously much safer, and many hosting providers now use it and configure their servers to throw an error if 777 or 666 permissions are used. For several years I have checked hosting to make sure that it uses suexec of some kind.
                        Studying MODX in the desert - http://sottwell.com
                        Tips and Tricks from the MODX Forums and Slack Channels - http://modxcookbook.com
                        Join the Slack Community - http://modx.org