403 Forbidden error when updating product
I just started getting an error under one of my cart's categories when I try to update the desciptions of a product under that category. It doesn't give the error under any other categories that I have found yet.
I receive the error:
Forbidden
You don't have permission to access /admin/product.php on this server.
The site is http://www.2griffins.com and it only does it for any products under Products - Desk Accessories > Pens and Pencils > Mont Blanc Pens and Pencils.
I was getting the same error under the Define Page Editor section after installing the SSL certificate on the site. I changed the following back to false for the admin and catalog and that fixed the problem there.
Code:
define('HTTP_SERVER', 'http://www.2griffins.com');
define('HTTPS_SERVER', 'https://www.2griffins.com');
define('HTTP_CATALOG_SERVER', 'http://www.2griffins.com');
define('HTTPS_CATALOG_SERVER', 'https://www.2griffins.com');
// Use secure webserver for catalog module and/or admin areas?
define('ENABLE_SSL_CATALOG', 'false');
define('ENABLE_SSL_ADMIN', 'false');
Any ideas?
- Karen
Re: 403 Forbidden error when updating product
what is the exact description that you are trying to change .... both "from" and "to" ?
I suspect your server may have a mod_security setting active which is trying to protect against the use of any "reserved words". Knowing what you're trying to enter may help...
Re: 403 Forbidden error when updating product
It does it for all products under the category Mont Blanc Pens and Pencils. I don't know exactly what the client was trying to change but I have tried anything for testing.
For example I will try to change the description on http://www.2griffins.com/index.php?m...products_id=47
from "Burl Wood Mont Blanc Pen" to "Burl Wood Pen"
What type of words are blocked? The only words that are in this category that are not in the others is "Mont Blanc"
Re: 403 Forbidden error when updating product
You have a .htaccess file in /admin, right?
So ... try an experiment.
1. make a backup copy of your /admin/.htaccess file. Store it in a safe place.
2. edit the /admin/.htaccess file, and add this to the very bottom:
Code:
SecFilterEngine Off
3. Save the file and upload it to the server ... again, this is ONLY the /admin/.htaccess file
(only in the ADMIN folder ... not in any other place)
Now do your edits work?
If so, then it's a configuration issue related to mod_security that's causing your problems.
Re: 403 Forbidden error when updating product
THANK YOU!!! That did the trick!
I wish I had asked earlier!
Re: 403 Forbidden error when updating product
Just wanted to chime in and say you saved the day. As of today i was getting the same problem but that code fixed it. Thanks!
Re: 403 Forbidden error when updating product
thanks for posting this fix !
Re: 403 Forbidden error when updating product
Heres another curly one - I only get the error in IE and not in Firefox........so it also would appear it has something to do with the way the browsers are interpreting the code!
Re: 403 Forbidden error when updating product
Just read this thread and it's what I've been looking for.......worked like a dream, Thanks Dr Byte:yes:
Re: 403 Forbidden error when updating product
Remember that using the method described by DrByte is temporary.
It allows you to finish what you were doing but then the Hoster should be contacted about the problem. Between the two of you, an exact solution can be worked out and the line can removed from your .htaccess file. Whille that line is there, you are losing the security provided by the Server Firewall, for anything within your Admin dir.