We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!

Answered Securing files

    • 28042 ☆ A M B ☆
    • 24,524 Posts
    I've noticed that while Revo comes with an ht.access file in the /core/ directory with directives to deny all .php files in the core directory, there's no way to deal with this in the Cloud. It's an easy addition to the nginx configuration, but that's not accessible. Can this be done at all in the Cloud?

    {edit} Well, that's weird... I just checked this about an hour ago and the config.inc.php file was accessible. Now, checking it again, I'm getting a 403 forbidden error, which is what I had in mind. Hm.

    This question has been answered by opengeek. See the first response.

    [ed. note: sottwell last edited this post 13 years, 2 months ago.]
      Studying MODX in the desert - http://sottwell.com
      Tips and Tricks from the MODX Forums and Slack Channels - http://modxcookbook.com
      Join the Slack Community - http://modx.org
    • discuss.answer
      • 22303 MODX Staff
      • 10,725 Posts
      I believe there are rules in place in MODX Cloud already to prevent direct access to the /core/ directory.
        • 28042 ☆ A M B ☆
        • 24,524 Posts
        Yes, there are. I have to presume that I must have been looking at another site somewhere else. It's been one of those days all day...
          Studying MODX in the desert - http://sottwell.com
          Tips and Tricks from the MODX Forums and Slack Channels - http://modxcookbook.com
          Join the Slack Community - http://modx.org