We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 50012
    • 12 Posts
    Hi all,

    while upgrading some sites to the newest version of modx, i also want to move the core folder above the web-root to make the sites more secure. But some client provider don't allow me to create folders outside the public web folder.
    So if i get this right, the best way would be to place the core folder like this:

    - html (Domain Root)
        - "all public files"
        - ...
    - core


    If that is not possible: is it any more secure to change the domain-root-folder to a deeper folder and place the core folder above that folder? For example like that:

    - html
        - example.com (Domain Root)
            - "all public files"
            - ...
        - core



    Thanks a lot for your help.

    best regards
    Jan

    This question has been answered by sottwell. See the first response.

    • discuss.answer
      • 28042 ☆ A M B ☆
      • 24,524 Posts
      No, there is no advantage to having the core anywhere else within the web root. The whole point of putting the core outside of the web root is that a web server can only serve files from within its web root (www, public_html, htdocs, etc). The core never needs to be accessed by the web server, all of its files are included through the file system.

      If you cannot create a folder above the web root for the core, the next best thing is to configure the web server to deny all requests to the files in the core. For example, an Apache .htaccess file in the /core/ directory would have
      IndexIgnore */*
      <Files *>
          Order Deny,Allow
          Deny from all
      </Files>
      


      The <Files *> means "any file", and this directive tells the web server to deny all requests to any files. So any request to domain.com/core/<any file> would be denied.
        Studying MODX in the desert - http://sottwell.com
        Tips and Tricks from the MODX Forums and Slack Channels - http://modxcookbook.com
        Join the Slack Community - http://modx.org
        • 50012
        • 12 Posts
        Thank you for your explanation. That helps me a lot, to understand the process of moving the core-folder for security.
        Than i just have to stick to the ".htaccess-change" on some client sites.

        Thanks a lot.