Support

Admin Tools

#40577 Blocked request in Hikashop checkout

Posted in ‘Admin Tools for Joomla! 4 & 5’
This is a public ticket

Everybody will be able to see its contents. Do not include usernames, passwords or any other sensitive information.

Environment Information

Joomla! version
4.4.3
PHP version
8.1.27
Admin Tools version
Pro 7.4.9

Latest post by nicholas on Tuesday, 16 April 2024 06:47 CDT

marcmarc

Hi,
I've got some issues with admin tools blocking some Hikashop checkout activity.
Reason "Login failure" Target URL "https://mywebsite.com/panier/checkout/submitblock?tmpl=raw"

"tmpl=raw" is in the list of allowed templates (see attachment)

I've tried to add a WAF exception but I don't really know what to do here (yes I've read the doc but… - see attachment)

The checkout works for the majority of customers but there is a small minority who triggers this blocking, I don't understand why.
I'm almost (!) sure this is legitimate behaviour.

Any idea ?
Thanks
Marc

nicholas
Akeeba Staff
Manager

Reason "Login failure"

This means that Joomla! tried, but failed, to log a user in.

I think you should ask Nicolas of HikaShop for help. I have a feeling that this may be an AJAX request which takes place after the user's session has expired.

Nicholas K. Dionysopoulos

Lead Developer and Director

🇬🇷Greek: native 🇬🇧English: excellent 🇫🇷French: basic • 🕐 My time zone is Europe / Athens
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

marcmarc

Hi, I should have tested more thoroughly before but I've been blinded by the unusual form of the url blocked.
I've tested when connected through a vpn so I could test in the public side and see, with my regular IP, what is logged in AdminTools in real time.

The result is that AdminTools blocks users for "login failure" when user exceed what is set in the WAF Auto Ban, so it's just normal behaviour.

The thing is:
- when the connexion is done in the Hikashop's checkout page the url logged by AdminTools is "https://mywebsite.com/panier/checkout/submitblock?tmpl=raw" (without username logged)
- when the connexion is done in the regular joomla login form, the url logged by AdminTools is the standard one "https://mywebsite.com/component/users/?task=user.login&Itemid=101" (with the username logged too, ex. "Username: sfdgsfdgfsdio")

So, sorry, it's just standard behaviour from AdminTools and Hikashop.
I've relaxed the auto-ban rules a little bit and it should do it.

And now we know…

Regards
Marc

nicholas
Akeeba Staff
Manager

No problem! Have a good day :)

Nicholas K. Dionysopoulos

Lead Developer and Director

🇬🇷Greek: native 🇬🇧English: excellent 🇫🇷French: basic • 🕐 My time zone is Europe / Athens
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

Support Information

Working hours: We are open Monday to Friday, 9am to 7pm Cyprus timezone (EET / EEST). Support is provided by the same developers writing the software, all of which live in Europe. You can still file tickets outside of our working hours, but we cannot respond to them until we're back at the office.

Support policy: We would like to kindly inform you that when using our support you have already agreed to the Support Policy which is part of our Terms of Service. Thank you for your understanding and for helping us help you!