WordPress.org

Forums

All In One WP Security & Firewall
forbidden (403) error from iOS app? (15 posts)

  1. elbowglitter
    Member
    Posted 11 months ago #

    I have been unable to connect to my blog via the iOS app, and am wondering if this is connected to a setting in AIO WP Security. Has anyone else had this problem and can anyone advise? Thanks!

    https://wordpress.org/plugins/all-in-one-wp-security-and-firewall/

  2. mbrsolution
    Member
    Plugin Contributor

    Posted 11 months ago #

    Hi elbowglitter what iOS app are you using to connect?

  3. wpsolutions
    Member
    Plugin Author

    Posted 11 months ago #

    Hi,
    Do you have Enable Pingback Protection active? (check the Firewall menu in "Basic Firewall Rules" page)
    If so that will be the cause of what you are seeing.

  4. elbowglitter
    Member
    Posted 11 months ago #

    I'm using the standard WordPress app.

    I don't have Pingback Protection enabled, and have never enabled it.

  5. mbrsolution
    Member
    Plugin Contributor

    Posted 11 months ago #

    Hi @elbowglitter have you enabled any of the Brute Force features?

  6. elbowglitter
    Member
    Posted 11 months ago #

    Just the rename login page.

  7. mbrsolution
    Member
    Plugin Contributor

    Posted 11 months ago #

    Do you use the secret word URL when you try to login through the mobile app?

  8. elbowglitter
    Member
    Posted 11 months ago #

    I don't, I just use the standard URL when I try to add my blog. I just tried adding it using the secret word URL and it said it couldn't find a WP blog there. So it clearly finds that there is a WP blog at my standard URL, I just can't log in.

  9. mbrsolution
    Member
    Plugin Contributor

    Posted 11 months ago #

    If you don't use the secret URL then you will not be able to login even through the App. That is the purpose of using this security feature.

    Unfortunately I don't have the app installed in my mobile phone to test it further.

    Regards

  10. elbowglitter
    Member
    Posted 11 months ago #

    As I said, though, there isn't a way in the app to use the secret URL for login.

    I tried turning that feature off and still get the same error from the app.

  11. kylaroma
    Member
    Posted 6 months ago #

    I'm also having this issue. I've set up the security plugin and love how it works, but I can't log into the iOS app on any device now.

    I've looked into this with the WordPress iOS developers and this was their response:

    The app only uses the wp-login URL for a few things (like previewing posts). The majority of the app's communication with your site is performed via XML-RPC calls which use a different mechanism for authentication. The worst case scenario is a few minor features would stop working. However, as long as its new location is properly reported as a part of the site's meta data everything should be fine.

    I've linked to that URL when I try to loginto the app (http://www.kylaroma.com/xmlrpc.php) but the iOS app still can't detect my blog.

    Is there anything in the plugin settings that block the XML-RPC calls? From what I've seen this is a fairly common in security plugins but it hasn't had a workaround suggested for AIO WP Security yet.

  12. kylaroma
    Member
    Posted 6 months ago #

    Just to clarify, I've tried to get the WP iOS app to login using:
    - my top level domain name
    - my login page URL
    - the XML-RPC file listed above

    None of them work, unless I deactivate the AIO WP Security plugin. I've had significant issues with hacking and spam, and I'd love to stick with this plugin if I can.

  13. mbrsolution
    Member
    Plugin Contributor

    Posted 6 months ago #

    Hi @kylaroma do you have Enable Pingback Protection active? As mentioned by @wpsolutions above in reply 3?

    If not can you disable all firewall features. And carry out a test.

  14. kylaroma
    Member
    Posted 6 months ago #

    I don't have "Enable Pingback Protection Active" activated, and the only firewall setting that I had activated was "Block Fake Googlebots" - but as soon as I did that, it worked!!

    Thank you for being so responsive! My site is how I make my living and this makes life a lot easier for me.

  15. mbrsolution
    Member
    Plugin Contributor

    Posted 6 months ago #

    I am happy to hear @kylaroma that it is now working for you.

    Kind regards

Reply

You must log in to post.

About this Plugin

About this Topic