Hello,
I installed the MODX CMS for a new website, but the red warning won't go away.
The Dashboard says: Core folder is accessible by web.
MODX detected that your core folder is (partially) accessible to the public. This is not recommended and a security risk. If your MODX installation is running on a Apache webserver you should at least set up the .htaccess file inside the core folder /home/grocerymaster.com.au/public_html/core/. This can be easily done by renaming the existing ht.access example file there to .htaccess.
There are other methods and webservers you may use, please read the Hardening MODX Guide for further information about securing your site.
If you setup everything correctly, browsing e.g. to the Changelog should give you a 403 (permission denied) or better a 404 (not found). If you can see the changelog there in the browser, something is still wrong and you need to reconfigure or call an expert to solve this.
So, I moved the .htaccess file to /core and renamed to ht.access.
I tested by checking the Changelog at domain.com/docs/changelog.txt and received error: Not Found. The requested URL /docs/changelog.txt was not found on this server.
This means the .htaccess file is now inaccessible.
However, I would like to remove the red warning, which remains and shouldn't.
A file named ht.access only serves as an example. It is ignored by the server, so if you renamed it to ht.access, it's not doing anything.
I generally prefer to move the whole core above the web root and modify the core/config/config.inc.php file and change the three config.core.php files (in the MODX root, connectors, and manager directories). Then you don't have to worry about the .htaccess file.
I'm seeing this too. I've renamed the core/ht.access to .htaccess. The change log is not accessible (goes to modx 404 page)
But the error message remains.
It contains:
IndexIgnore */*
<Files *.php>
Order Deny,Allow
Deny from all
</Files>
I have more than one modx installation running on this server, so I thought perhaps this installation was seeing the htaccess from another folder, so I renamed those as well. No change.
Yeah I'm thinking this might be a bug. The only way I can get rid of the warning is to move the core folder above the web root.
That worked for me!
Thanks!
@Paulp Thanks! That worked for me, too.