Support

Admin Tools

#21384 SP Staging WAF Exception

Posted in ‘Admin Tools for Joomla! 4 & 5’
This is a public ticket

Everybody will be able to see its contents. Do not include usernames, passwords or any other sensitive information.

Environment Information

Joomla! version
n/a
PHP version
n/a
Admin Tools version
n/a

Latest post by tampe125 on Wednesday, 05 November 2014 09:07 CST

victorwooten
 Hello,

I am using SP Staging to update several websites.
All websites (even on the same host) are working fine with admin tools AND sp staging. Unfortunately one site wont update via sp staging. Problem is admin tools.
SP Staging will be blocked.

All Preferences are entered correctly. Secret URL parameter and so on...

Anyway the reason is "Admin Query String".

You can find this URL in the Admin Tools WAF:
http://domain.de/administrator/index.php?option=com_spstgsrv&view=redirect&tmpl=component&format_cyend=install&task_cyend=installer.update&extension_id=12345&sec=xxxxxx


I tried to put "com_spstgsrv" in the WAF exception, but it wont work.

Can you tell me how I can configure the WAF Exception correctly so that SP staging can update this site? (all infos above (admin tools version, database version etc...) are not actual, because site isnt updated yet)

Thanks

tampe125
Akeeba Staff
Hello Frank,

as reported in the WAF exception page, setting them up will only bypass the following features: Bad Behaviour, SQLiShield, XSSShield, MUAShield, CSRFShield, RFIShield, DFIShield, UploadShield and Bad Words Filtering.
As you can see the Admin Query string protection is still active.

You have to remove the secret word or inform the developer of that extension to add an option for adding the secret word in the url

Davide Tampellini

Developer and Support Staff

🇮🇹Italian: native 🇬🇧English: good • 🕐 My time zone is Europe / Rome (UTC +1)
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

victorwooten
ah ok. thanks a lot.

SP Staging HAS an option for the secret URL parameter and (as i told in my first post) it is entered correctly. other sites are working fine with sp staging and admin tools (with secret URL parameter).

So do you have another idea why admin tools will block sp staging? although the secret url parameter is added?

thanks a lot.

tampe125
Akeeba Staff
We simply check if the secret param is inside the url, so you should contact the SP Staging developers to double check your situation.

Davide Tampellini

Developer and Support Staff

🇮🇹Italian: native 🇬🇧English: good • 🕐 My time zone is Europe / Rome (UTC +1)
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

victorwooten
ok, thanks a lot.
i hope we will solve that

tampe125
Akeeba Staff
You're welcome!

Davide Tampellini

Developer and Support Staff

🇮🇹Italian: native 🇬🇧English: good • 🕐 My time zone is Europe / Rome (UTC +1)
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

Support Information

Working hours: We are open Monday to Friday, 9am to 7pm Cyprus timezone (EET / EEST). Support is provided by the same developers writing the software, all of which live in Europe. You can still file tickets outside of our working hours, but we cannot respond to them until we're back at the office.

Support policy: We would like to kindly inform you that when using our support you have already agreed to the Support Policy which is part of our Terms of Service. Thank you for your understanding and for helping us help you!