WordPress.org

Ready to get started?Download WordPress

Forums

NinjaFirewall (WP edition)
[resolved] NinjaFirewall blocks the "Preview Changes" button (3 posts)

  1. GermanKiwi
    Member
    Posted 5 months ago #

    Hi, I've just discovered that NinjaFirewall blocks the preview function when editing a post or page.

    When I'm editing a page in WordPress, there is a button on the right called "Preview Changes", near the Publish button. The Preview Changes button will make a new browser window appear with a preview of the page, without saving the page.

    Normally the URL of the preview page looks something like this:
    http://www.example.com/mypage?preview=true&preview_id=123&preview_nonce=22459a24d2

    However, when I clicked this button just now, it opened a new browser window and the URL changed to:
    http://www.ibcstuttgart.de/wp/wp-admin/post.php
    ...And it displayed the standard NinjaFirewall "403" error message ("your request cannot be proceeded").

    I checked the firewall log, and it shows that it's being blocked with rule #100, and it refers to "XSS (HTML tag)". But I don't understand why or what this means.

    I know that I can just disable rule 100, but I'd rather not disable any rules because that might allow a hacker to gain access through whatever feature is being protected by rule 100.

    Is there any way to fix this so that NinjaFirewall does not block the "Preview Changes" button from working? I would have thought, that NinjaFirewall would not block internal features which are part of WP core?

    Thanks!

    http://wordpress.org/plugins/ninjafirewall/

  2. nintechnet
    Member
    Plugin Author

    Posted 5 months ago #

    Hi

    Normally you should not be blocked as long as you are the admin and that the "Do not block WordPress admin" is enabled.
    This looks like an expired PHP session.

    Can you try to log out, log in, then edit/preview your post again?

  3. GermanKiwi
    Member
    Posted 5 months ago #

    Everything seems to be working fine now, thanks!

Reply

You must log in to post.

About this Plugin

About this Topic

Tags

No tags yet.