[SOLVED] "Forbidden" error after logging in with Google account using CB Connect plugin

4 years 4 weeks ago - 4 years 3 weeks ago #317306 by pdolezel
Unable to register or login, using Google account via CB Connect plugin (similar for Facebook, although they've disabled my app because of this issue so can't test it at the moment).

To reproduce, please:
  1. Visit turnsallyear.org
    Click on My >> Register
    Then sign in with Google account
    After selecting your Google email and password, you'll arrive at a blank page with only a simple error message "Forbidden" and "You don't have access to this resource"
    The URL for this 'blank' page is: turnsallyear.org/components/com_comprofiler/plugin/user/plug_cbconnect/endpoint.php?provider=google&state=5e7af6b515854&code=4%2FxwGvkkCsjMnOH_PMe6TUV8zwYDvd3fxUplH7HfgP2tmAKAJPVkCOcHC5NkJ7GwZ7iqns77LnVq5yCgS0mkE8hUE&scope=email+profile+https%3A%2F%2Fwww.googleapis.com%2Fauth%2Fuserinfo.profile+https%3A%2F%2Fwww.googleapis.com%2Fauth%2Fuserinfo.email+openid&authuser=1&hd=artigma.com&prompt=consent#

Pretty much the same experience (except a slightly different URL) for the login experience

Thank you so much for any pointers. Happy to create admin account/creds for troubleshooting.

Please Log in to join the conversation.

4 years 4 weeks ago #317313 by krileon
"Forbidden" with "You don't have access to this resource" error is a server block. Your server probably has mod_security and a false positive is causing it to block access. You'll need to contact your host for them to take a look at mod_security logs.


Kyle (Krileon)
Community Builder Team Member
Before posting on forums: Read FAQ thoroughly + Read our Documentation + Search the forums
CB links: Documentation - Localization - CB Quickstart - CB Paid Subscriptions - Add-Ons - Forge
--
If you are a Professional, Developer, or CB Paid Subscriptions subscriber and have a support issue please always post in your respective support forums for best results!
--
If I've missed your support post with a delay of 3 days or greater and are a Professional, Developer, or CBSubs subscriber please send me a private message with your thread and will reply when possible!
--
Please note I am available Monday - Friday from 8:00 AM CST to 4:00 PM CST. I am away on weekends (Saturday and Sunday) and if I've missed your post on or before a weekend after business hours please wait for the next following business day (Monday) and will get to your issue as soon as possible, thank you.
--
My role here is to provide guidance and assistance. I cannot provide custom code for each custom requirement. Please do not inquire me about custom development.

Please Log in to join the conversation.

4 years 4 weeks ago - 4 years 4 weeks ago #317321 by pdolezel
Thank you; I'm using Admin Tools on this site, but have the following whitelisted:
turnsallyear.org/components/com_comprofiler/plugin/user/plug_cbconnect/endpoint.php?provider=google

anything else I should whitelist?

Thanks again

Please Log in to join the conversation.

4 years 4 weeks ago #317324 by krileon
Is Admin Tools what was blocking it? mod_security is a server configuration and has nothing to do with Admin Tools. If Admin Tools is what was blocking it then I've no idea as you'd have to ask the developer of Admin Tools about why it's even blocking it to begin with. If it's mod_security you need to contact your host.


Kyle (Krileon)
Community Builder Team Member
Before posting on forums: Read FAQ thoroughly + Read our Documentation + Search the forums
CB links: Documentation - Localization - CB Quickstart - CB Paid Subscriptions - Add-Ons - Forge
--
If you are a Professional, Developer, or CB Paid Subscriptions subscriber and have a support issue please always post in your respective support forums for best results!
--
If I've missed your support post with a delay of 3 days or greater and are a Professional, Developer, or CBSubs subscriber please send me a private message with your thread and will reply when possible!
--
Please note I am available Monday - Friday from 8:00 AM CST to 4:00 PM CST. I am away on weekends (Saturday and Sunday) and if I've missed your post on or before a weekend after business hours please wait for the next following business day (Monday) and will get to your issue as soon as possible, thank you.
--
My role here is to provide guidance and assistance. I cannot provide custom code for each custom requirement. Please do not inquire me about custom development.

Please Log in to join the conversation.

4 years 4 weeks ago #317330 by pdolezel
it was Admin Tools in the end ... had to "whitelist" the directory for this plugin
thanks for your help, @krileon
The following user(s) said Thank You: krileon

Please Log in to join the conversation.

Moderators: beatnantkrileon
Time to create page: 0.199 seconds

Facebook Twitter LinkedIn