We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 49515
    • 184 Posts
    Hello,
    I installed the MODX CMS for a new website, but the red warning won't go away.
    The Dashboard says: Core folder is accessible by web.
    MODX detected that your core folder is (partially) accessible to the public. This is not recommended and a security risk. If your MODX installation is running on a Apache webserver you should at least set up the .htaccess file inside the core folder /home/grocerymaster.com.au/public_html/core/. This can be easily done by renaming the existing ht.access example file there to .htaccess.
    There are other methods and webservers you may use, please read the Hardening MODX Guide for further information about securing your site.
    If you setup everything correctly, browsing e.g. to the Changelog should give you a 403 (permission denied) or better a 404 (not found). If you can see the changelog there in the browser, something is still wrong and you need to reconfigure or call an expert to solve this.


    So, I moved the .htaccess file to /core and renamed to ht.access.

    I tested by checking the Changelog at domain.com/docs/changelog.txt and received error: Not Found. The requested URL /docs/changelog.txt was not found on this server.

    This means the .htaccess file is now inaccessible.
    However, I would like to remove the red warning, which remains and shouldn't.
      • 3749
      • 24,544 Posts
      A file named ht.access only serves as an example. It is ignored by the server, so if you renamed it to ht.access, it's not doing anything.

      I generally prefer to move the whole core above the web root and modify the core/config/config.inc.php file and change the three config.core.php files (in the MODX root, connectors, and manager directories). Then you don't have to worry about the .htaccess file.
        Did I help you? Buy me a beer
        Get my Book: MODX:The Official Guide
        MODX info for everyone: http://bobsguides.com/modx.html
        My MODX Extras
        Bob's Guides is now hosted at A2 MODX Hosting
        • 36551
        • 416 Posts
        I'm seeing this too. I've renamed the core/ht.access to .htaccess. The change log is not accessible (goes to modx 404 page)

        But the error message remains.

        It contains:

        IndexIgnore */*
        <Files *.php>
        Order Deny,Allow
        Deny from all
        </Files>

        I have more than one modx installation running on this server, so I thought perhaps this installation was seeing the htaccess from another folder, so I renamed those as well. No change.
          • 44195
          • 293 Posts
          Yeah I'm thinking this might be a bug. The only way I can get rid of the warning is to move the core folder above the web root.
            I'm lead developer at Digital Penguin Creative Studio in Hong Kong. https://www.digitalpenguin.hk
            Check out the MODX tutorial series on my blog at https://www.hkwebdeveloper.com
            • 45118
            • 123 Posts
            Did you clear the cache?
              • 22840
              • 1,572 Posts
              Change the content to"

              IndexIgnore */*
              <Files *>
              Order Deny,Allow
              Deny from all
              </Files>
                • 36551
                • 416 Posts
                That worked for me!

                Thanks!
                  • 48717
                  • 1 Posts
                  @Paulp Thanks! That worked for me, too.