Error 406

More
13 years 7 months ago #26779 by rottenberg
Error 406 was created by rottenberg
Hello

I have uploaded the last verrion 2.0.1568

One more I have the 406 error when I create an article.

I can't find the origin as the error is random. I may create some articles correctly and then after 2 or 3 articles the 406 error arrives. I can't do nothing more than close the site, clean the browser cache and reopen the site.

I don't think it's a right on file or directory problem as sometime I can create an article.

I never got the 406 error problem in Joomla 1.5.


It's only arriving on articles not on categories.

It's a very hard problem as once it's arrived I need to desinstall Flexicontent and to use Joomla artlcie management which is not so good as Flexicontent.

Another problem which is not so hard : The JCE editor is not loaded on modifying an article. I get it only on creation. As suggested in a previous mail I have updated the description field, but it continues to be wrong.

What can I do to solve the problem ?
thanks for help

Michel

Please Log in or Create an account to join the conversation.

More
13 years 7 months ago #26781 by ggppdk
Replied by ggppdk on topic Error 406
I think mod_security is enabled on your web-server and one of mod_security rules was triggered.

Maybe contact your web-server provider asking them which security rule was triggered.

I have no way easy of knowing which rule was triggered.

Regards


-- Flexicontent is Free but involves a big effort on our part.
Like the our support? (for a bug-free FC, despite having a long list of functions) Like the features? Like the ongoing development and future commitment to FLEXIcontent?
-- Add your voice to the FLEXIcontent JED listing with a 5-star review. Thanks!

Please Log in or Create an account to join the conversation.

More
13 years 5 months ago #28107 by conticreative
Replied by conticreative on topic Error 406
I have just installed Flexicontent on a test site on my server and almost immediately while poking around the program I got banned with the same error 406. While that was happening I was on a online meeting with a collaborator so I asked him to login and see if he could operate the site.
He had no problems until he too got banned after trying to use flexicontent.

Most definitely it seems the FC triggers mod_security somehow. I have a dedicated server, but it's managed and I have no idea how to find out how mod_security was triggered. However, the fact that there are two users with the same error I think makes it more of a FC issue than a mod_security one. Something in FC is triggering mod_security.

We are looking at FC for an upcoming project and it seems a good candidate, but not if we can secure our server.

Please Log in or Create an account to join the conversation.

More
13 years 5 months ago #28108 by ggppdk
Replied by ggppdk on topic Error 406
The mod_security is your server is giving a false positive.

It is impossible for me to "fix" this as i have no idea what rules they have inside their configuration, and which rule is triggered

Please try disabling mod_security in your server by add this in your .htaccess file of joomla root folder:
Code:
<IfModule mod_security.c> SecFilterEngine Off SecFilterScanPOST Off </IfModule>

or ask them to remove the rule that is being triggered,
see this too
activeblogging.com/info/406-error-wordpress/


-- Flexicontent is Free but involves a big effort on our part.
Like the our support? (for a bug-free FC, despite having a long list of functions) Like the features? Like the ongoing development and future commitment to FLEXIcontent?
-- Add your voice to the FLEXIcontent JED listing with a 5-star review. Thanks!

Please Log in or Create an account to join the conversation.

More
13 years 5 months ago #28109 by conticreative
Replied by conticreative on topic Error 406
I placed a ticket with my server administrators and I am going to let you know what we find.

By the way, of course I wouldn't expect you to "fix" something like this without access to a server that produces the error, but it definitely it is something you should not consider an isolated incident, even if it is a false positive. If it was only one user with the issue I would understand, but since there is now at least two of us it is more likely there is something in the FC code that triggers this. And I mean "Possible" not certain.

Depending on what they say, I'll be happy to give you guys access to my server if you want to look into it. Just let me know.

By the way, I doubt I can use htaccess to deactivate mod_security. In my experience no htaccess script works on suPHP servers. I always have to use a php.ini file if I don;t want to edit the actual php.ini

Please Log in or Create an account to join the conversation.

More
13 years 5 months ago #28110 by ggppdk
Replied by ggppdk on topic Error 406
I meant that someone can write any mod_security rule,

e.g. imagine a rule that bans the word "apple" from the URLs,


or a rule that will disallow Unicode URLs,

if it is a real security issue i will be happy to try to improve FLEXIcontent, but without information it is impossible to do something


-- Flexicontent is Free but involves a big effort on our part.
Like the our support? (for a bug-free FC, despite having a long list of functions) Like the features? Like the ongoing development and future commitment to FLEXIcontent?
-- Add your voice to the FLEXIcontent JED listing with a 5-star review. Thanks!

Please Log in or Create an account to join the conversation.

More
13 years 5 months ago #28111 by conticreative
Replied by conticreative on topic Error 406
No problem, I realize that. My hosting guys are looking into it and I gave them access to the test build were I got the error. I also asked them to provide a report I can give you if they think the issue is on your side. If instead it is our security not configured properly I'll just fix it and let you know.

Please Log in or Create an account to join the conversation.

More
13 years 5 months ago #28112 by ggppdk
Replied by ggppdk on topic Error 406
OK i imagine they will give you URL that triggered the mod_security,

but do you remember which FLEXIcontent page you visited when the error occurred,

Frontend item view? category view?

Backend view?


-- Flexicontent is Free but involves a big effort on our part.
Like the our support? (for a bug-free FC, despite having a long list of functions) Like the features? Like the ongoing development and future commitment to FLEXIcontent?
-- Add your voice to the FLEXIcontent JED listing with a 5-star review. Thanks!

Please Log in or Create an account to join the conversation.

More
13 years 5 months ago #28113 by conticreative
Replied by conticreative on topic Error 406
I was in the backend and I was poking around, most likely trying to create a field someplace. One of the objectives of our project is to have a product catalog and a list of recipients that can subscribe to each product and receive alerts via email about one or more of the products contained in the catalog. What we are looking for is a CCK that handles custom fields in a way that it is easier for us to create custom queries and extract the data. So far we have tried K2, Sobi and a couple of others but the way they handle custom fields would not work for us. So we are looking around to find a CCK that may be closer to what we need.

Regardless, I found that FC has a feature we need for the regular news area of the site, so we are interested in using it.

Maybe I'll open another thread to explain what we need in terms of the catalog that may more more sense. But we would still love to use FC for the news part anyway so fixing it would be great.

it'll probably be tomorrow before I hear back from my server guys.

Please Log in or Create an account to join the conversation.

More
13 years 5 months ago #28114 by conticreative
Replied by conticreative on topic Error 406
But instead they got back to me right now. Just when I was about to close shop.

According to them, they managed to trigger mod_security by creating a new item and then clicking "cancel".

Now I remember that the very same thing happened to me. I created a new item, but when I went to add some text the text area (introtext) would not show up (with or without the text editor) so I clicked "cancel" and that's when mod_security kicked me off.

I forgot because we have been doing similar things all day in a number of scripts and we were chatting at the same time.

Tomorrow I will continue working with it and see if I trigger it again. If not, you may want to look at what may be causing that in your code, if you think it can be traced there. If you like, I can ask for further clarification from the guys.

Please Log in or Create an account to join the conversation.

Moderators: vistamediajoomlacornerggppdk
Cookies user preferences
We use cookies to ensure you to get the best experience on our website. If you decline the use of cookies, this website may not function as expected.
Accept all
Decline all
Essential
These cookies are needed to make the website work correctly. You can not disable them.
Display
Accept
Analytics
Tools used to analyze the data to measure the effectiveness of a website and to understand how it works.
Google Analytics
Accept
Decline
Save