Support

Admin Tools

#32113 Frontend users get 403 error and cannot access page/window for submitting a K2 article

Posted in ‘Admin Tools for Joomla! 4 & 5’
This is a public ticket

Everybody will be able to see its contents. Do not include usernames, passwords or any other sensitive information.

Environment Information

Joomla! version
n/a
PHP version
n/a
Admin Tools version
n/a

Latest post by on Saturday, 08 February 2020 17:17 CST

icinfo
Hello,
we are using K2 component to let some users a possibility to submit articles. It worked fine earlier, but now with Admin tools, our frontend users that submit articles, cannot access the K2 frontend submit article page/window.

They get the 403 error and cannot access the windows where they should be able to send an article for review.

Here are some of the Security Exceptions Log lines:


12345678910
2019-12-11 13:42:43 EET 82.203.141.226 template= in URL https://www.kuudesaisti.net/component/k2/item/add?tmpl=component&template=system&context=modalselector
2019-12-11 13:42:02 EET 82.203.141.226 template= in URL https://www.kuudesaisti.net/vilja-j/item/add?tmpl=component&template=system
2019-12-11 13:41:52 EET 82.203.141.226 template= in URL https://www.kuudesaisti.net/component/k2/item/add?tmpl=component&template=system&context=modalselector
2019-12-11 13:41:33 EET 82.203.141.226 Login failure https://www.kuudesaisti.net/jata-uusi-artikkeli?task=user.login
2019-12-11 13:36:48 EET 82.203.141.226 template= in URL https://www.kuudesaisti.net/component/k2/item/add?tmpl=component&template=system
2019-12-11 13:36:13 EET 82.203.141.226 template= in URL https://www.kuudesaisti.net/component/k2/item/add?tmpl=component&template=system&context=modalselector
2019-12-11 13:34:28 EET 82.203.141.226 template= in URL https://www.kuudesaisti.net/component/k2/item/add?tmpl=component&template=system&context=modalselector
2019-12-11 13:30:30 EET 82.203.141.226 template= in URL https://www.kuudesaisti.net/component/k2/item/add?tmpl=component&template=system&context=modalselector
2019-12-11 13:30:07 EET 82.203.141.226 Login failure https://www.kuudesaisti.net/jata-uusi-artikkeli?task=user.login
2019-12-11 13:29:01 EET 82.203.141.226 template= in URL https://www.kuudesaisti.net/component/k2/item/add?tmpl=component&template=system&context=modalselector
2019-12-11 13:28:53 EET 82.203.141.226 template= in URL https://www.kuudesaisti.net/component/k2/item/add?tmpl=component&template=system
2019-12-11 13:28:08 EET 82.203.141.226 template= in URL https://www.kuudesaisti.net/component/k2/item/add?tmpl=component&template=system&context=modalselector
2019-12-11 13:27:48 EET 82.203.141.226 template= in URL https://www.kuudesaisti.net/component/k2/item/add?tmpl=component&template=system&context=modalselector
2019-12-11 11:23:32 EET 82.203.141.226 Admin Query String https://www.kuudesaisti.net/administrator/index.php


I as an admin do not have problems with login in and adding an article with a bloggers-username, but then I have my IP address added as a safe IP address via Admin Tools. This is not the case with these frontend users, we have not added their IP addresses to the Never block this IP list.

What are we doing wrong? How can we prevent this 403 to show up for users that are successfully logged in with their user-details and who we have set the right to submit a K2 article?

Greetings, Anne

tampe125
Akeeba Staff
Hello,

what's the reason for the block? You should see it inside the Security Exception Log.
I suspect the reason is template= in URL. Can you please get inside the Configure WAF, Cloacking tab and enable the option Allow site templates?
That should do the trick.

Davide Tampellini

Developer and Support Staff

🇮🇹Italian: native 🇬🇧English: good • 🕐 My time zone is Europe / Rome (UTC +1)
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

icinfo
Thank you! We will test this out!

T. Anne

System Task
system
This ticket has been automatically closed. All tickets which have been inactive for a long time are automatically closed. If you believe that this ticket was closed in error, please contact us.

Support Information

Working hours: We are open Monday to Friday, 9am to 7pm Cyprus timezone (EET / EEST). Support is provided by the same developers writing the software, all of which live in Europe. You can still file tickets outside of our working hours, but we cannot respond to them until we're back at the office.

Support policy: We would like to kindly inform you that when using our support you have already agreed to the Support Policy which is part of our Terms of Service. Thank you for your understanding and for helping us help you!