Skip to Content Skip to Menu

403 Access denied when using https and CB Login

  • krileon
  • krileon
  • ONLINE
  • Posts: 48478
  • Thanks: 8282
  • Karma: 1443
10 years 4 months ago #246134 by krileon
I see, you'll need to edit your CB Login modules and set them to force HTTPS. This should allow the IF check to pass and prevent the 403.


Kyle (Krileon)
Community Builder Team Member
Before posting on forums: Read FAQ thoroughly + Read our Documentation + Search the forums
CB links: Documentation - Localization - CB Quickstart - CB Paid Subscriptions - Add-Ons - Forge
--
If you are a Professional, Developer, or CB Paid Subscriptions subscriber and have a support issue please always post in your respective support forums for best results!
--
If I've missed your support post with a delay of 3 days or greater and are a Professional, Developer, or CBSubs subscriber please send me a private message with your thread and will reply when possible!
--
Please note I am available Monday - Friday from 8:00 AM CST to 4:00 PM CST. I am away on weekends (Saturday and Sunday) and if I've missed your post on or before a weekend after business hours please wait for the next following business day (Monday) and will get to your issue as soon as possible, thank you.
--
My role here is to provide guidance and assistance. I cannot provide custom code for each custom requirement. Please do not inquire me about custom development.

Please Log in or Create an account to join the conversation.

  • NFER-ICT
  • NFER-ICT
  • OFFLINE
  • Posts: 44
  • Thanks: 1
  • Karma: 0
10 years 4 months ago #246151 by NFER-ICT
Hi and thanks again for getting back to me.

I've made the change to the CB Login module so that it's now set to "use HTTPS (encrypted) for login and after login" but there's no change... I still get the 403.

In your last post you said...

"edit your CB Login modules and set them to force HTTPS"

I might be missing something here, but I've only got one CB Login module - singular, but you appear to be mentioning multiple CB modules.

if there are others that have HTTPS options, could you please let me now which ones, as I've looked at the current published CB modules and there doesn't appear to be any HTTPS options with those.

Thanks

Dave

Please Log in or Create an account to join the conversation.

  • NFER-ICT
  • NFER-ICT
  • OFFLINE
  • Posts: 44
  • Thanks: 1
  • Karma: 0
10 years 4 months ago #246152 by NFER-ICT
I've just also noticed that if I click on the "Forgot Login" hyperlink under the login button of the CB Login form... that too is getting a 403!

Could it be a folders permission on the server do you think?

Strange.

Please Log in or Create an account to join the conversation.

  • NFER-ICT
  • NFER-ICT
  • OFFLINE
  • Posts: 44
  • Thanks: 1
  • Karma: 0
10 years 4 months ago - 10 years 4 months ago #246156 by NFER-ICT
Okay, just spotted the potential problem here.

My site is in a directory off of the main root, so the URL is in the following format:-

mainwebsite.com/mynewsite/index.php

When trying to login via the CB Login module, the URL of the 403 error page is:-

mainwebsite.com/mynewsite/mynewsite/index.php/component/comprofiler/login

So it's added an extra "mynewsite" directory level, so obviously the rest of the URL after this isn't going to exist... right?

I've now gone back into the CB Login Module and tried all of the following in the "Login Redirection URL" field, but with change in the resulting 403 error.

I've tried:-

1. Leaving the field blank to try and get it to simply stay on the initial page
2. Entering the FULL HTTPS URL to the comprofiler page
3. Using ./index.php/component/comprofiler/login
4. Using ../index.php/component/comprofiler/login

Is there another setting somewhere that you know of that could be adding the extra 'sub-site' directory level?

Dave
Last edit: 10 years 4 months ago by NFER-ICT. Reason: Typo!

Please Log in or Create an account to join the conversation.

  • NFER-ICT
  • NFER-ICT
  • OFFLINE
  • Posts: 44
  • Thanks: 1
  • Karma: 0
10 years 4 months ago #246162 by NFER-ICT
Further update...

I've now used the default Joomla login module to log myself into the site and gain access to the GroupJive pages that I want.

And I've noticed that all links that go to any CB page, add the extra sub-site level, whereas any link that goes to a non-CB page (such as normal menu links to content pages) are fine.

Seems likely that something/setting to do with my Community Builder installation is set to add this extra level to all links.

Probably something I did on installation, but I don't know where to look to fix it :-(

Obviously any pointers would be gratefully received.

Dave

Please Log in or Create an account to join the conversation.

  • krileon
  • krileon
  • ONLINE
  • Posts: 48478
  • Thanks: 8282
  • Karma: 1443
10 years 4 months ago #246172 by krileon
CB doesn't add anything like that to the URLs. It simply adds Joomlas live_site, which should be '' (blank) in configuration.php so Joomla can auto construct it. You appear to be using SEF though and if you're using a 3rd party SEF extension it could just be a broken URL rewrite. Disable all SEF and see if your issue persists.

I've now gone back into the CB Login Module and tried all of the following in the "Login Redirection URL" field, but with change in the resulting 403 error.

Login redirects should never be SEF. Always supply URL parameters as raw non-SEF URLs. Example as follows.

index.php?option=com_comprofiler


Kyle (Krileon)
Community Builder Team Member
Before posting on forums: Read FAQ thoroughly + Read our Documentation + Search the forums
CB links: Documentation - Localization - CB Quickstart - CB Paid Subscriptions - Add-Ons - Forge
--
If you are a Professional, Developer, or CB Paid Subscriptions subscriber and have a support issue please always post in your respective support forums for best results!
--
If I've missed your support post with a delay of 3 days or greater and are a Professional, Developer, or CBSubs subscriber please send me a private message with your thread and will reply when possible!
--
Please note I am available Monday - Friday from 8:00 AM CST to 4:00 PM CST. I am away on weekends (Saturday and Sunday) and if I've missed your post on or before a weekend after business hours please wait for the next following business day (Monday) and will get to your issue as soon as possible, thank you.
--
My role here is to provide guidance and assistance. I cannot provide custom code for each custom requirement. Please do not inquire me about custom development.

Please Log in or Create an account to join the conversation.

Moderators: beatnantkrileon
Powered by Kunena Forum