Support

Admin Tools

#21604 Excluding components from WAF fails when view specified

Posted in ‘Admin Tools for Joomla! 4 & 5’
This is a public ticket

Everybody will be able to see its contents. Do not include usernames, passwords or any other sensitive information.

Environment Information

Joomla! version
n/a
PHP version
n/a
Admin Tools version
n/a

Latest post by dlb on Monday, 01 December 2014 15:36 CST

drjjw
 Hello,

For URL:

en/network/registration/steps/3

which is really:

en/index.php?option=com_easysocial&view=registration&layout=steps&step=3

(en comes from using Falang language component)

I get a 403 for DFI shield.

When specifying a WAF exception using:

component: com_easysocial
view: registration
query: step

I still get a 403. In fact, if leave query blank, I still get a 403. The only way that seems to work is if leaving both view and query blank.

Am I configuring this wrong?

Jodan

dlb
You are doing it right.

The WAF Exception opens up your website security just a crack. In this case, this is required by your component, it is a necessary crack. The more parameters you give the WAF Exception, the smaller the crack is. But it may not be possible to get your extension working with just a small crack, it may need a bigger crack. For example, you may be using multiple views depending on how you enter the page, so a single view on the exception won't work. You can research the component and identify each separate view that requires an exception and set up an exception for each, or you can just leave the view blank, allowing all views for that component to use the exception.

We are not talking about leaving the back door open here. The exception is limited to that one component, so even without the view or query parameters, it is still a very small crack.


Dale L. Brackin
Support Specialist


us.gifEnglish: native


Please keep in mind my timezone and cultural differences when reading my replies. Thank you!


????
My time zone is EST (UTC -5) (click here to see my current time in Philadelphia, PA)

Support Information

Working hours: We are open Monday to Friday, 9am to 7pm Cyprus timezone (EET / EEST). Support is provided by the same developers writing the software, all of which live in Europe. You can still file tickets outside of our working hours, but we cannot respond to them until we're back at the office.

Support policy: We would like to kindly inform you that when using our support you have already agreed to the Support Policy which is part of our Terms of Service. Thank you for your understanding and for helping us help you!