Isn’t that a REST API issue? Can you go to :
- NinjaFirewall > Firewall Policies > Protect against username enumeration: Did you enable that policy?
- NinjaFirewall > Firewall Policies > WordPress REST API: Did you enabled the ” Block any access to the API” policy?
Thread Starter
Trevor
(@twevva)
Thanks for the reply. I have tried with both of these options checked and unchecked. The problem is there whatever combination I use, but not in WordPress WAF mode. As I say, in WordPress WAF mode there is not an issue, but in Full WAF mode there is.
Did you check the firewall log (NinjaFirewall > Logs) to see if the incident was written to the log ? It would include the reason why it was blocked.
Thread Starter
Trevor
(@twevva)
Thanks. I did check. Nothing was written to the log. Strange.
Did you enable one or more options from the “Firewall Policies > Advanced Policies > HTTP response headers” section ?
Thread Starter
Trevor
(@twevva)
No, Intermediate and Advanced Policies are set to default values.
Thread Starter
Trevor
(@twevva)
I should add that this behaviour began only a few weeks ago – I can’t remember exactly when. Before that, WooCommerce and NinjaFirewall in Full WAF mode behaved fine. I suspect the problem is due to a WooCommerce update.
Can you explain to me how to reproduce the issue, i.e., what steps should I follow until I get that error? Or is it a random issue?
Thread Starter
Trevor
(@twevva)
Sure. Select Full WAF mode. Then simply click on WooCommerce (Home) and you will see the Inbox error. If you are unable to reproduce it, I will try to make a more precise diagnosis by disabling plugins and themes. Thanks for looking into this.
Thread Starter
Trevor
(@twevva)
Hi again. Update: the problem seems to disappear if I install and activate the LiteSpeed Cache plugin. Is this plugin required for correct implementation of NinjaFirewall Full WAF mode? I don’t use LiteSpeed Cache.
The LiteSpeed Cache is not needed at all.
I still can’t reproduce the issue. Did you activate some specific options/policies in NinjaFirewall?
Thread Starter
Trevor
(@twevva)
No specific options. I’ve been testing on a fresh WordPress install with only NinjaFirewall and WooCommerce installed. No other plugins. I used the default settings and then activated Full WAF mode.
When activating Full WAF mode, I am asked to ‘Select your HTTP server and your PHP server API (SAPI)’. In the dropdown box I see ‘Litespeed (recommended)’. That is why I wondered whether the LiteSpeed Cache plugin was necessary.
When I installed the LiteSpeed Cache plugin for testing, the WooCommerce problem went away. If you are unable to reproduce the problem, it is possible that the problem is with my server configuration (Hostinger).
I seem to be well protected in WordPress WAF mode, so I’ll just accept that Full WAF mode will not work on my WooCommerce sites. Thank you for investigating. Please let me know if you find a solution.
- Can you check your Woocommerce log (WooCommerce > Status > Logs)?
- Can you check your PHP error log?
If there was anything in those logs, that could help to find out where is the problem.
Thread Starter
Trevor
(@twevva)
Thanks. I’ve done that. There are no logs with a timestamp corresponding to the WooCommerce error. I wish I could be of more help.
I’m still unable to reproduce the problem. If one day you can find anything that could help debugging it, re-open a thread here and we’ll look at it.