Go to main content

Textpattern CMS support forum

You are not logged in. Register | Login | Help

#1 2010-08-19 22:25:03

shayne
Member
From: Toronto
Registered: 2005-02-22
Posts: 34
Website

Form page saving and modsec bug

This problem only occurs in the Presentation – Forms area. I simply can’t save a form, click the save button and it takes you back to the home page with a 404 error. Pages, CSS, other areas are fine. Can edit the database directly without issues. On the suggestion of another forum user, I had the hist disable the modsec rule and this fixed the problem.

What is on the form area of the application that would cause this issue? I don’t want to introduce potential security issues, but I cannot edit the site properly without disabling modsec.

Offline

#2 2010-08-20 00:00:57

Gocom
Developer Emeritus
From: Helsinki, Finland
Registered: 2006-07-14
Posts: 4,533
Website

Re: Form page saving and modsec bug

shayne wrote:

What is on the form area of the application that would cause this issue?

I wouldn’t say there is a problem in Textpattern, more of so the filters are blocking good actions and causing false-positives.

That said, the filters are probably blocking the field name + data content compination the Form’s pane uses. TXP can’t really do much about it than blindly change the field names which doesn’t fix anything as any compination could be blocked.

The fix should be applied to the filters in a form of whitelists, removing the rule that is causing issues, or by disabling the filters for TXP’s admin panel.

Offline

#3 2010-08-20 01:50:54

shayne
Member
From: Toronto
Registered: 2005-02-22
Posts: 34
Website

Re: Form page saving and modsec bug

Thank you, I have escalated at the host and there is some support for what you have suggested.

Offline

Board footer

Powered by FluxBB