• Hi, Thanks for the excellent plugin!

    When running NinjaFirewall in Full WAF mode, I run into the reasonably well-documented WooCommerce error ‘There was an error getting your inbox. Please try again.’ Clicking the WooCommerce ‘Reload’ button then initiates the unwanted process of setting up the WooCommerce store. Running NinjaFirewall in WordPress WAF mode solves the problem, but I prefer not to miss out on the extra security of Full WAF mode. Suggested solutions for other security plugins (e.g. iThemes Security) are to uncheck ‘Filter Long URL Strings’ or ‘Filter Suspicious Query Strings in the URL’ settings. Is there a setting in NinjaFirewall which will solve the WooCommerce problem but retain an optimal level of security? Thanks.

Viewing 15 replies - 1 through 15 (of 16 total)
  • Plugin Contributor bruandet

    (@bruandet)

    Isn’t that a REST API issue? Can you go to :

    • NinjaFirewall > Firewall Policies > Protect against username enumeration: Did you enable that policy?
    • NinjaFirewall > Firewall Policies > WordPress REST API: Did you enabled the ” Block any access to the API” policy?
    Thread Starter Trevor

    (@twevva)

    Thanks for the reply. I have tried with both of these options checked and unchecked. The problem is there whatever combination I use, but not in WordPress WAF mode. As I say, in WordPress WAF mode there is not an issue, but in Full WAF mode there is.

    Plugin Contributor bruandet

    (@bruandet)

    Did you check the firewall log (NinjaFirewall > Logs) to see if the incident was written to the log ? It would include the reason why it was blocked.

    Thread Starter Trevor

    (@twevva)

    Thanks. I did check. Nothing was written to the log. Strange.

    Plugin Contributor bruandet

    (@bruandet)

    Did you enable one or more options from the “Firewall Policies > Advanced Policies > HTTP response headers” section ?

    Thread Starter Trevor

    (@twevva)

    No, Intermediate and Advanced Policies are set to default values.

    Thread Starter Trevor

    (@twevva)

    I should add that this behaviour began only a few weeks ago – I can’t remember exactly when. Before that, WooCommerce and NinjaFirewall in Full WAF mode behaved fine. I suspect the problem is due to a WooCommerce update.

    Plugin Contributor bruandet

    (@bruandet)

    Can you explain to me how to reproduce the issue, i.e., what steps should I follow until I get that error? Or is it a random issue?

    Thread Starter Trevor

    (@twevva)

    Sure. Select Full WAF mode. Then simply click on WooCommerce (Home) and you will see the Inbox error. If you are unable to reproduce it, I will try to make a more precise diagnosis by disabling plugins and themes. Thanks for looking into this.

    Thread Starter Trevor

    (@twevva)

    Hi again. Update: the problem seems to disappear if I install and activate the LiteSpeed Cache plugin. Is this plugin required for correct implementation of NinjaFirewall Full WAF mode? I don’t use LiteSpeed Cache.

    Plugin Contributor bruandet

    (@bruandet)

    The LiteSpeed Cache is not needed at all.

    I still can’t reproduce the issue. Did you activate some specific options/policies in NinjaFirewall?

    Thread Starter Trevor

    (@twevva)

    No specific options. I’ve been testing on a fresh WordPress install with only NinjaFirewall and WooCommerce installed. No other plugins. I used the default settings and then activated Full WAF mode.

    When activating Full WAF mode, I am asked to ‘Select your HTTP server and your PHP server API (SAPI)’. In the dropdown box I see ‘Litespeed (recommended)’. That is why I wondered whether the LiteSpeed Cache plugin was necessary.

    When I installed the LiteSpeed Cache plugin for testing, the WooCommerce problem went away. If you are unable to reproduce the problem, it is possible that the problem is with my server configuration (Hostinger).

    I seem to be well protected in WordPress WAF mode, so I’ll just accept that Full WAF mode will not work on my WooCommerce sites. Thank you for investigating. Please let me know if you find a solution.

    Plugin Contributor bruandet

    (@bruandet)

    • Can you check your Woocommerce log (WooCommerce > Status > Logs)?
    • Can you check your PHP error log?

    If there was anything in those logs, that could help to find out where is the problem.

    Thread Starter Trevor

    (@twevva)

    Thanks. I’ve done that. There are no logs with a timestamp corresponding to the WooCommerce error. I wish I could be of more help.

    Plugin Contributor bruandet

    (@bruandet)

    I’m still unable to reproduce the problem. If one day you can find anything that could help debugging it, re-open a thread here and we’ll look at it.

Viewing 15 replies - 1 through 15 (of 16 total)

You must be logged in to reply to this topic.