We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 40122
    • 330 Posts
    I am getting the 'Core folder is accessible by web' message on a new install (2.4.1).

    I have renamed the ht.access file to .htaccess as suggested but still get the message. Currently, the permissions on this directory are 755.

    Ideally, what should they be?

    Many thanks
      • 28042 ☆ A M B ☆
      • 24,524 Posts
      The .htaccess file needs to be edited. Where it says *.php, get rid of the .php so that it just says *
        Studying MODX in the desert - http://sottwell.com
        Tips and Tricks from the MODX Forums and Slack Channels - http://modxcookbook.com
        Join the Slack Community - http://modx.org
        • 47401
        • 295 Posts
        I use 0772 on the main folders in a LAMP stack Environment
          • 44922
          • 131 Posts
          Not got my head around 2.4 yet, but on 2.3 we had core as 755 then export / packages / cache / commponents on 777.

          If you SSH into your root web folder (httpdocs / publick_html etc) the following line sorts the whole site on permissions after set up:

          chmod -R 777 assets/ manager/ connectors/ core/packages/ core/cache/ core/export core/components/ core/config/config.inc.php
            • 47401
            • 295 Posts
            dont use 777. your giving public access FULL read, write and execute to the components folder!

            Quote from: lancipoos at Oct 01, 2015, 09:41 AM
            Not got my head around 2.4 yet, but on 2.3 we had core as 755 then export / packages / cache / commponents on 777.

            If you SSH into your root web folder (httpdocs / publick_html etc) the following line sorts the whole site on permissions after set up:

            chmod -R 777 assets/ manager/ connectors/ core/packages/ core/cache/ core/export core/components/ core/config/config.inc.php

            Absolutely do not give 777 access to any of the above files/folders. Yes you can do for testing, but no on a live environment
              • 13373
              • 70 Posts
              Quote from: sottwell at Sep 27, 2015, 10:45 PM
              The .htaccess file needs to be edited. Where it says *.php, get rid of the .php so that it just says *
              Thank you thank you, Susan. This has been driving me mad since the updates to 2.4.x, when my clients log in and see that big glaring warning message!

              Hopefully, the next point release will include a better ht.access file template in the core directory.
                • 2528
                • 8 Posts
                Quote from: sottwell at Sep 27, 2015, 10:45 PM
                The .htaccess file needs to be edited. Where it says *.php, get rid of the .php so that it just says *

                Thanks Susan. Never would have caught that on my own.