Admin settings: clicking save 403 forbidden page

Post Reply
bdavis
Jr. Bludit
Posts: 7
Joined: Sat Mar 31, 2018 7:08 pm

Thu Jan 17, 2019 4:14 pm

Afternoon everyone.

I've just installed the latest version of Bludit 3.6.1 on one of my shared servers and everything seems to be running great... with one exception. If I attempt to change any settings in /admin/settings (by which I mean any tab - general, advanced, logo etc) clicking save just generates a 403 forbidden page. I don't seem to have any other problem with bludit that I have noticed. I'm able to post content, change theme, add and activate plugins just not modify any settings.

Anyone have any ideas what could be causing this? Or culprit files I could look at? Or file/folder permissions that could be behind this?
User avatar
diego
Site Admin
Posts: 674
Joined: Sat May 16, 2015 2:53 pm
Contact:

Thu Jan 17, 2019 11:42 pm

I saw a similar case with another user, for some reason the hosting was blocking the POST method in that URL. The user contact support, and they fix it... is really strange this behaviour.
bdavis
Jr. Bludit
Posts: 7
Joined: Sat Mar 31, 2018 7:08 pm

Fri Jan 18, 2019 12:42 am

It really is since it isn't affecting anything else. I've just been through all the file permissions and ownership details for all the files involved and... nothing. I will get in touch with my host and see what can be done. Does the users page use the same method as the settings page?

Thanks for getting back to me diego.

Any suggestions for anything else I could check while I wait for their response?

Update:

Turns out this was a mod security false positive. No clear way to avoid this in future on a lot of web hosts (certainly not on mine anyway as I don't have direct access to mod security). Just a bizarre and maddening peculiarity!
User avatar
diego
Site Admin
Posts: 674
Joined: Sat May 16, 2015 2:53 pm
Contact:

Sun Jan 20, 2019 5:08 pm

Yes it's really strange, I been login to one of that hosting and doing testing, also I changed the endpoint /settings for another but still the problem, I don't know exactly why is a security issue and they block the method POST, maybe the lenght.
Post Reply