We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 48243
    • 12 Posts
    I am trying to prevent a resource from being requested, specifically a resource that calls a snippet which checks for parameters in the REQUEST query. I have recently been receiving exceptions in my error logs and came to the conclusion my resource is being requested DIRECTLY. Before I can solve the issue I would like to know where the request is being made and by whom. I've done my research and read that HTTP_REFERER or REMOTE_ADDR can be unreliable sometimes. Is there a way I can tell if a request was made by within my modx site or externally?

    Here is a function within one of my snippets to generate a custom error message that will show me all the data I will need to know.

    function generate_exception($templateId, $resourceId, $query)
    {
        global $modx;
    	$theme_sites_server = 'MY IP ADDRESS';
        $site_name   = $modx->getOption('site_name');
        $resource    = $modx->makeUrl($resourceId, '', '', 'full');
        $user 		 = is_bot() ? 'BOT' : 'USER';
        $username 	 = $modx->getUser();
    
        if(!empty($templateId)){
    	    $template     = $modx->getObject('modTemplate', $templateId);
    	    $templateName = $template->get('templatename');
    	} else {
    		$templateName = 'Template was not passed';
    	}
    
            //this was an alternate option
    	// if($_SERVER['REMOTE_ADDR'] != $theme_sites_server){
    	// 	$remote_addr = 'DIRECT';
    	// } else {
    	// 	$remote_addr = 'Internal/modX';
    	// }
    
        if ( isset($_SERVER["HTTP_CLIENT_IP"]) ){ 
            $remote_addr = gethostbyaddr($_SERVER["HTTP_CLIENT_IP"]); 
        } else if ( isset($_SERVER["HTTP_X_FORWARDED_FOR"]) ){ 
            $remote_addr = gethostbyaddr($_SERVER["HTTP_X_FORWARDED_FOR"]); 
        } else if ( isset($_SERVER["REMOTE_ADDR"]) ){ 
            $remote_addr = gethostbyaddr($_SERVER["REMOTE_ADDR"]); 
        }
    
        $custom_mssg = array(
                        'Site'           => $site_name,
                        'Referer'        => !empty($_SERVER['HTTP_REFERER']) ? $_SERVER['HTTP_REFERER'] : 'unknown',
                        'Template'       => $templateName,
                        'Requested By'   => $resource,
                        'Requested Page' => $_SERVER['REQUEST_URI'],
                        'Query String'   => $query,
                        'User Agent'     => $_SERVER['HTTP_USER_AGENT'],
                        'USER/BOT'		 => $user == 'USER' ? 'USER: '.$username->get('username') : $user,
                        'Remote Addr'    => $remote_addr
                    );
        return $custom_mssg;
    }

      • 28042 ☆ A M B ☆
      • 24,524 Posts
      If the REFERER is empty, then somebody directly entered the URL. If it was called by MODX or by AJAX, the REFERER will be the page that called it.

        Studying MODX in the desert - http://sottwell.com
        Tips and Tricks from the MODX Forums and Slack Channels - http://modxcookbook.com
        Join the Slack Community - http://modx.org
        • 48243
        • 12 Posts
        thanks for the response sottwell.

        The HTTP_REFERER can be blocked or spoofed by the browser or hidden behind a proxy. What I am mainly trying to figure out is if MODX has something internally stored that identifies the referring resource id and is not unreliable or 'spoofable'
          • 3677
          • 130 Posts
          Does MODX internally store any information about the referring resource id in the $modx object that could be referenced by the snippet as it is loaded? If that info was stored in the object on each MODX request then it would be NULL if the resource was called directly.