WordPress.org

Making WordPress.org

Opened 6 weeks ago

Closed 6 weeks ago

#4776 closed defect (fixed)

'sconfig' profile URLs return a 'raw' 403

Reported by: jonoaldersonwp Owned by: dd32
Milestone: Priority: lowest
Component: Profiles Keywords: seo analytics
Cc:

Description

See https://wordpress.org/support/users/sconfig/, https://profiles.wordpress.org/sconfig/ and similar.

This looks like a legit user - see https://wordpress.org/support/topic/too-many-cookies/

Can this be fixed, or, set to a clean(er) 404?

Change History (2)

#1 @dd32
6 weeks ago

  • Keywords pending-systems added
  • Owner set to dd32
  • Status changed from new to accepted

We've got some config urls blocked with 403's (that should *never* be linked to - 403's are staying), looks like one of them is a bit too greedy here though.

Filed a systems request. https://make.wordpress.org/systems/2019/10/24/tighten-the-config-block-rules/

Last edited 6 weeks ago by dd32 (previous) (diff)

#2 @dd32
6 weeks ago

  • Keywords pending-systems removed
  • Resolution set to fixed
  • Status changed from accepted to closed
Note: See TracTickets for help on using tickets.