Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

403 error when setting permalinks to symlinks #131

Open
lachlanphillips opened this issue May 11, 2021 · 3 comments
Open

403 error when setting permalinks to symlinks #131

lachlanphillips opened this issue May 11, 2021 · 3 comments

Comments

@lachlanphillips
Copy link

lachlanphillips commented May 11, 2021

Hi, as the title says, this image gives a hard 403 error if you change the permalink structure from the default to eg "post name"

Repro: wp-admin -> Settings -> Permalinks -> Set to 'post name'.

Are there any workarounds for this at present?

@sych74
Copy link
Collaborator

sych74 commented May 11, 2021

Hi @lachlanphillips
The issue related to mod security rules.
ModSecurity: Access denied with code 403, [Rule: 'REQUEST_BODY|XML:/*' '@validateUrlEncoding'] [id "210380"] [rev "6"] [msg "COMODO WAF: URL Encoding Abuse Attack Attempt"] [logdata "_wpnonce=b108e68f63&_wp_http_referer=/wp-admin/options-permalink.php&selection=/%postname%/&permalink_structure=/%postname%/&category_base=&tag_base=&submit=Save Changes=_wpnonce=b108e68f63&_wp_http_referer=/wp-admin/options-permalink.php&selection=/%postname%/&permalink_structure=/%postname%/&category_base=&tag_base=&submit=Save Changes"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"]

as workarounds please disable WAF before installing cluster
image

or disable WAF on the installed cluster via Change Environment Topology
image
image

we will escalate the issue with COMODO rules to developers and let you know about the results

regards,

@sych74
Copy link
Collaborator

sych74 commented Jun 1, 2021

Hi @lachlanphillips
We have tested the WAF issue with the litespeed development team. This problem is reproduced on the server version 6.0 and it also present in version 6.0.1.
Litespeed developers have prepared a build where this problem has been fixed. We will update the litespeedphp template and after that you can redeploy to a new template and enable the WAF. We will let you know when a new template will be available.

regards,

@sych74
Copy link
Collaborator

sych74 commented Jun 14, 2021

Hi @lachlanphillips
The template Litespeed WEB 6.0.2 has been published. You can redeploy to this version and return the WAF back.

regards,

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants