We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!

Answered URL parameters

    • 40967
    • 17 Posts
    OK, I'm running revo 2.2.10. Have been using MODx for a while, but only at a basic level. I've spent some time researching this question, but I can't quite put the pieces together on how to do it from "a to z". I can follow/insert PHP examples, but I am not a PHP programmer.

    I want to include parameters in URL's sent to the MODx engine. So, for example, I want to add parameters to a basic URL displaying a resource (page) such as:
    mydomain.com/modx-install-directory/index.php?id=2
    (I know... I have not implemented friendly URL's even though I am comfortable modifying .htaccess. They are not important for this case, unless they are needed in order to add additional parameters.)

    Here's what I want to know:

      (1) What should the format of the URL be that contains additional parameters?
    • I've read docs on linking to resources, but am having trouble figuring it all out

      (2) What code snippet should I use to retrieve named parameters?
    • I would like to put them into template variables with the same name. Is this possible?
    • I've found getUrlParam: is this a revo extra that is a good choice in this case?

      (3) If I can get the named parameters into template variables, then I assume that I can use TV substitutions where I need them.
    • If it's not possible, then I need to know how to retrieve the parameter values and insert them into the chunks where I need them.

      (4) I have wondered if it's a good idea to parse out the parameters in .htaccess and assign them to environment variables.
    • If this is a good idea, how do you retrieve environment variable values to insert into the chunks where I need them?

    Thanks very much for any help you can give me on this. For my current project, it would be VERY helpful to be able to do this.

    This question has been answered by multiple community members. See the first response.

    [ed. note: ride2719 last edited this post 12 years, 10 months ago.]
      • 5160
      • 118 Posts

      1. Parameters can be passed following a question mark in the URL eg. index.php?id=1
        http://moz.com/blog/seo-cheat-sheet-anatomy-of-a-url
      2. I've not used getUrlParam but it may be a good starting point if you're new to MODX and PHP.

        If you want to do some work yourself, and there's not much involved in this example, take a look at Ralph Zelf's post at:
        https://forums.modx.com/thread/84752/tip-use-querystring-in-getresources
      3. I think you want to get the URL parameters into Placeholders, not TVs.
      4. I'm not familiar with Apache but this sounds like more more work than is required

      If you just need to grab one variable from the querystring you can do it on one line with a snippet:

      <?php
      return $_GET['manufacturer'];

      Would return: ford when the URL of the page calling the snippet was: /index.php?manufacturer=ford
      • discuss.answer
        • 28042 ☆ A M B ☆
        • 24,524 Posts
        You can very easily get the query string values using the fastField extra. It adds a new MODx tag, [[#...]] for getting all kinds of things, from regular resource fields or TVs of specified resources to the GET, POST, etc. PHP-supplied arrays.

        http://rtfm.modx.com/extras/revo/fastfield

        Just be careful, the GET parameters are passed raw, with no validation, so you'll need to make sure they are checked before you use them in code, for example to access the database.
        CAUTION: It is dangerous to use raw global variables on the page. For example, use :stripTags output filter to prevent XSS-attacks (eg. [[!#get.name:stripTags]])!

        http://rtfm.modx.com/revolution/2.x/making-sites-with-modx/structuring-your-site/resources#Resources-URLParametersforResourceTags

          Studying MODX in the desert - http://sottwell.com
          Tips and Tricks from the MODX Forums and Slack Channels - http://modxcookbook.com
          Join the Slack Community - http://modx.org
          • 40967
          • 17 Posts
          Thanks very much, chris.dempsey78 and sottwell. These have helped me figure a lot out that I did not know before. I'm still not quite there, however, and would like clarification on a specific example. With the complexity of the documentation I'm still not catching on to something...

          I decided to use fastField, and downloaded and installed it.

          I am testing the following URL:
          http://mydomain/mdx/index.php?id=7&bgcolor=#ffffcc (where mdx is the install directory for MODx)

          As I understand this, $_get will contain the value for bgcolor.
          I have a chunk for CSS definitions which contains the following line:
          body {background-color:[[!#get.bgcolor]];}

          I also tried [[!#request.bgcolor]] which also did not work.

          When the page with id=7 is rendered, it is correct except that the value of bgcolor is not there.
          This is what I get:
          body {background-color:;}

          So, I'm stuck: please advise what I missed.
          TIA, Rick.
          • discuss.answer
            • 5160
            • 118 Posts
            The hash symbol # in the URL indicates a named anchor.

            It should work if you remove the # from the URL:
            http://mydomain/mdx/index.php?id=7&bgcolor=ffffcc

            And manually add the # in the code:

            #[[!request.bgcolor]]
              • 40967
              • 17 Posts
              Quote from: chris.dempsey78 at Dec 02, 2013, 09:56 AM
              The hash symbol # in the URL indicates a named anchor.

              It should work if you remove the # from the URL:
              http://mydomain/mdx/index.php?id=7&bgcolor=ffffcc

              And manually add the # in the code:
              #[[!request.bgcolor]]

              YES!! thanks chris.dempsey78 for your help. I got it to work.
              Since I marked the previous response from chris.dempsey78 as an answer, I thought I'd clarify that the tag value he used needs to have a # character, i.e.: #[[!#request.bgcolor]]

              This is dumb, but I don't know how to mark this thread as "answered". How to you close a thread? [ed. note: ride2719 last edited this post 12 years, 10 months ago.]
                • 5160
                • 118 Posts
                If you edit your first post on this thread you can set it to be a Discussion or Question with buttons at the top left of the page.

                When it's a Question you get the option to mark one of the responses as the answer by hovering at the right side of the title and selecting the Flag as Answer star.
                  • 40967
                  • 17 Posts

                  Just be careful, the GET parameters are passed raw, with no validation, so you'll need to make sure they are checked before you use them in code, for example to access the database.

                  CAUTION: It is dangerous to use raw global variables on the page. For example, use :stripTags output filter to prevent XSS-attacks (eg. [[!#get.name:stripTags]])!

                  In addition to giving me the hint about fastField, sottwell made a good suggestion about filtering the values you get from $_GET, etc. I thought I would share my solution to this since it goes a step further than sottwell's suggestion.

                  I am passing CSS values via the URL, so that those who use it can adjust some of the basic styling values. One is for a picture that is floating in a <div> with text that wraps around it. The most important parameter to control is the width, since the total width of the <div> is variable.

                  The URL looks like this (simplified by removing the other parameters):
                  http://mydomain/mdx/index.php?id=7&picsize=150
                  which displays the page with resource id 7.

                  The CSS entry looks like this:
                  img.picclass {border:0; float:left; clear:both; overflow:auto; padding-right:5px; width:[[!#request.picsize:len:gt=`4`:then=``:else=`[[!#request.picsize:stripTags]]`:default=`100`]]px;}

                  You will see that I used stripTags per suggestion, but also limited the total length of the input string to four characters. This will make some kind of html or javascript injection much more difficult. If the parameter is blank (or when it is over 4 chars) a default of 100 is assigned.

                  I would like suggestions on other ways to filter input parameters to enhance security, and anything on the limitations or caveats to the method I used.

                  Thanks, Rick
                    • 5160
                    • 118 Posts
                    One option, if you were writing your own snippet to get the querystring value, is to perform a regex check on the value retreived to see if it matched the correct pattern:
                    http://stackoverflow.com/questions/1636350/how-to-identify-a-given-string-is-hex-color-format

                    You could make a custom output modifier to do the regex HEX colour format part and chain it to your existing [[!#request.picsize:stripTags]] fastField call, see Creating a Custom Output Modifier at:
                    http://rtfm.modx.com/revolution/2.x/making-sites-with-modx/customizing-content/input-and-output-filters-(output-modifiers)

                    Not sure how that would work out if the value didn't convert to a valid HEX code though.

                    For checking the image dimensions you could check the value is_numeric http://us1.php.net/manual/en/function.is-numeric.php as part of a custom snippet.

                    I'm not suggesting these are bullet proof but they go some way to sanitising the input.