Support

Admin Tools

#27924 CSRFShield and yootheme pro

Posted in ‘Admin Tools for Joomla! 4 & 5’
This is a public ticket

Everybody will be able to see its contents. Do not include usernames, passwords or any other sensitive information.

Environment Information

Joomla! version
n/a
PHP version
n/a
Admin Tools version
n/a

Latest post by dlb on Monday, 12 June 2017 08:27 CDT

user88951
Hi,
Yootheme pro builder fails to load with 403 error if WAF CSRFShield is enabled - even in basic mode. Is there an exception for yootheme pro that I can set that can allow CSRFShield to be enabled ?

Thanks

dlb
Since it is a WAF exception, there should be an entry in the Security Exceptions Log. Please copy and paste that and it will give the information needed to create the exception. Or you can check the documentation here: https://www.akeebabackup.com/documentation/admin-tools/wafexceptions.html.


Dale L. Brackin
Support Specialist


us.gifEnglish: native


Please keep in mind my timezone and cultural differences when reading my replies. Thank you!


????
My time zone is EST (UTC -5) (click here to see my current time in Philadelphia, PA)

user88951
Hi Dale,

There wasn't any relevant info in the log - just said CSRFShield and the site index page. I tried quickly to set up an exception using the documentation but it didn't work. However, I tried setting the CSRFShield > Advance and surprisingly it didn't create the error - I think there might be me something amiss between the two settings ?

Thanks

dlb
The technique used by the Advanced setting is more accurate and less likely to give false positives. But it is slower and can't be used for very high traffic sites. So if everything works as expected with the Advanced setting, it's fixed. If you notice the site slowing down, we need to go back to the Basic setting and take another look at the WAF Exception.


Dale L. Brackin
Support Specialist


us.gifEnglish: native


Please keep in mind my timezone and cultural differences when reading my replies. Thank you!


????
My time zone is EST (UTC -5) (click here to see my current time in Philadelphia, PA)

Support Information

Working hours: We are open Monday to Friday, 9am to 7pm Cyprus timezone (EET / EEST). Support is provided by the same developers writing the software, all of which live in Europe. You can still file tickets outside of our working hours, but we cannot respond to them until we're back at the office.

Support policy: We would like to kindly inform you that when using our support you have already agreed to the Support Policy which is part of our Terms of Service. Thank you for your understanding and for helping us help you!