When I try to submit a post or comment containing the string [slash]etc[slash] passwd, the submit button goes into a loading state and spins indefinitely. The request is blocked by Cloudflare with status code 403. I can’t even search for the forbidden string. You have to check dev tools to find out what went wrong, this error is not handled in the UI at all.

So, if you’ve ever tried to reply to a tech issue and the UI just won’t let you, maybe this is why.

  • usernamesAreTricky
    link
    fedilink
    English
    arrow-up
    27
    ·
    edit-2
    5 months ago

    This smells like something being blocked by Cloudflare’s WAF (Web Application Firewall) rules. I’d imagine there might be a rule there to try to block requests that look like they could involve sensitive files like the passwd file

    https://developers.cloudflare.com/waf/

    The UI should probably alert you of there being an issue posting after getting a 403 response

    • eco_game@discuss.tchncs.de
      link
      fedilink
      English
      arrow-up
      5
      ·
      5 months ago

      Damn even though you explained the abbreviation I still read it as Wife Approval Factor for a second and was very confused