We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 3749
    • 24,544 Posts
    Am I correct that there are no step-by-step instructions anywhere for upgrading a hardened MODX site with a core above the web root and renamed manager and connectors directories?

    After a lot of searching, the only thing I could find was this:

    updating your site will become more complex: you will have to merge the various component directories one at a time for each MODX update.

    That seems a little sketchy to me.

    There is no mention of the Advanced distribution for this. I think I've read accounts of people using it, but since the config.core.php files contain: define ('MODX_SETUP_KEY', '@traditional');, I would think that would confuse the Advanced setup.

    Will the Traditional distribution setup handle a hardened site if the config files are all correct and the new files are copied to the correct locations?

    Also, I must be going blind, because I downloaded the 2.3.1 Advanced distribution and I can't find the manager directory anywhere in the .zip file, or any source file that might contain it, though it's definitely created when you run setup. [ed. note: BobRay last edited this post 12 years, 1 month ago.]
      Did I help you? Buy me a beer
      Get my Book: MODX:The Official Guide
      MODX info for everyone: http://bobsguides.com/modx.html
      My MODX Extras
      Bob's Guides is now hosted at A2 MODX Hosting
      • 28042 ☆ A M B ☆
      • 24,524 Posts
      The only thing in the Advanced installation is the core. And you have to move it manually to your new location before running Setup.
        Studying MODX in the desert - http://sottwell.com
        Tips and Tricks from the MODX Forums and Slack Channels - http://modxcookbook.com
        Join the Slack Community - http://modx.org
        • 28042 ☆ A M B ☆
        • 24,524 Posts
        Hm. Testing an upgrade from an advanced 2.2.15 to 2.3.1 did not go well. A lot of database errors like

        Error creating table for class modExtensionPackage
        
        Error creating table for class modUserGroupSetting
        
        Error updating table for class modResource
        Array
        (
        [0] => 42000
        [1] => 1061
        [2] => Duplicate key name 'cache_refresh_idx'
        )

        Attempting retry just caused a blank page.
          Studying MODX in the desert - http://sottwell.com
          Tips and Tricks from the MODX Forums and Slack Channels - http://modxcookbook.com
          Join the Slack Community - http://modx.org
          • 28042 ☆ A M B ☆
          • 24,524 Posts
          Updgrade from standard 2.2.15 to standard 2.3.1 went just fine.
            Studying MODX in the desert - http://sottwell.com
            Tips and Tricks from the MODX Forums and Slack Channels - http://modxcookbook.com
            Join the Slack Community - http://modx.org
            • 28042 ☆ A M B ☆
            • 24,524 Posts
            Some oddities on a new install of 2.3.1 advanced, taken from http://modx.com/download/direct/modx-2.3.1-pl-advanced.zip

            Some of the checks don't show correctly or completely.
              Studying MODX in the desert - http://sottwell.com
              Tips and Tricks from the MODX Forums and Slack Channels - http://modxcookbook.com
              Join the Slack Community - http://modx.org
              • 3749
              • 24,544 Posts
              Interesting.

              How about this?

              Will the Traditional distribution setup handle a hardened site if the config files are all correct and the new files are copied to the correct locations?
                Did I help you? Buy me a beer
                Get my Book: MODX:The Official Guide
                MODX info for everyone: http://bobsguides.com/modx.html
                My MODX Extras
                Bob's Guides is now hosted at A2 MODX Hosting
                • 42046
                • 436 Posts
                What exactly are the differences between trad and adv? Not in file structure and zip contents but in the actual code and install script? It's not like the advanced setup script detects the moved core from config.php when upgrading which I thought would be an obvious difference.
                  • 38237
                  • 83 Posts
                  Hi Bob,

                  I've suffered for a while upgrading a hardened 2.2.14 to 2.3, after a while i gave up specially with the amount of bugs in 2.3. When 2.3.1 got released, i thought of giving it another try which succeeded. I used the traditional package(as i usually do), did merge all the folders manually (using cpanel filemanager), then ran the setup which asked me for the core path(expected when core folder is not found), once provided the upgrade went smooth. So far all issues i found were regular 2.3.1 bugs which i found on Github, the only thing which is weird was the console not responding to "$modx->error->success()" and only completing on message "COMPLETE".
                    • 3749
                    • 24,544 Posts
                    @mina-gerges: Thanks. I would have thought that Setup would find the core based on the config.core.php file rather than having to ask you. Did you maybe overwrite the config.core.php files when you copied the files?

                    @dan: I've never seen a complete explanation of how the two distributions differ, what, exactly, they do during the install, or why you'd want to use one over the other.

                    For a long time, I've meant to look at the code and try to figure it out, but I never seem to get around to it.
                      Did I help you? Buy me a beer
                      Get my Book: MODX:The Official Guide
                      MODX info for everyone: http://bobsguides.com/modx.html
                      My MODX Extras
                      Bob's Guides is now hosted at A2 MODX Hosting
                      • 38237
                      • 83 Posts
                      I would have thought that Setup would find the core based on the config.core.php file rather than having to ask you. Did you maybe overwrite the config.core.php files when you copied the files?
                      The setup checks the existence of "core" folder by name, if it is not one level up from the script file then it will ask you about it's location before proceeding further with setup.Even if you modify config.core.php with core location, setup will perform what i just mentioned. I do not remember exactly which files i modified but i have ran through all the config files (manager, core, root, connectors etc. ) to be sure that every thing is correct.

                      index.php will access config.core.php to get core path, then from there it loads modx.class.php
                      manager and connectors have their own config.core.php and go through similar cycle to get into modx.class. important for each part is to be able to define MODX_CORE_PATH where they expect where to find things inside it, i have manipulated with that part as well and changed folders and includes structure for extra hardening (for security researching purposes) i could do that and everything was functioning properly, where my pentesting team got stuck and had no clue where is what, but upgrading such environment was hell, but it was a pentesting environment not production anyway. Sorry for the long story but thought it might be interesting.

                      With regards to the difference between advanced and traditional, i assume you already know about this link: http://rtfm.modx.com/revolution/2.x/getting-started/installation/advanced-installation
                      in short, the advanced package makes it easier and gives "more" options for hardening, but from my testing, i personally prefer the traditional, where everything is in place, and i just have control which files to merge where, in addition, my experience with advanced package wasn't pleasant while performing extra hardening as upgrading ALWAYS failed for me (yes everything can be troubleshooted but for me waste of time if traditional was easier). Thus i decided to be stuck with traditional package. Depending on each person's preference of course, advanced should be easier for basic hardening.