FAQFAQ   SearchSearch   MemberlistMemberlist   UsergroupsUsergroups   RegisterRegister 
 ProfileProfile   Log in to check your private messagesLog in to check your private messages   Log inLog in 
Can't Preview or Post with Parentheses in Message Body

 
Post new topic   Reply to topic    ScoreHero Forum Index -> Bug Reports
View previous topic :: View next topic  
Author Message
ricecake  





Joined: 17 May 2007
Posts: 1890
Location: Linthicum Heights, MD

PostPosted: Thu Feb 14, 2019 4:43 am    Post subject: Can't Preview or Post with Parentheses in Message Body Reply with quote

I tried to edit a post and when I hit Preview, I got the 403 error. I also tried posting without previewing and that did not work either.

Previewing this post when posting new works.

EDIT: It seems it has to do with parentheses:
Code:
<b>one</b> (<b>two</b>)
I had to use the HTML entity codes (ampersand-hash-40-semicolon and ampersand-hash-41-semicolon) to get the above code to post. When I try to use actual parentheses, I get the 403 error. It seems to work if I only replace either one with an actual parenthesis; it is only when I replace both of them that I get the error. Also, I used real parentheses in this paragraph; it may be related to having the parentheses on the same line as embedded HTML.

EDIT2: Found another case:
Code:
[list][*](.
[/list]
Interestingly, for this case, if I use the HTML entity, then I get the 403; if I use a real parenthesis, then it works. Also, the newline between the period and the end-of-list BBcode is significant.

Maybe an issue with escaping special characters?
_________________
Back to top
View user's profile Wiki User Page Send private message Visit poster's website PSN Name: ricecake138
ricecake  





Joined: 17 May 2007
Posts: 1890
Location: Linthicum Heights, MD

PostPosted: Thu Feb 14, 2019 6:40 am    Post subject: Reply with quote

EDIT: Sorry, meant to post this in a different thread... Tried to delete the post but it just gave me a blank page. Might be the IPv6 issue.
_________________
Back to top
View user's profile Wiki User Page Send private message Visit poster's website PSN Name: ricecake138
bushidox  





Joined: 09 Jun 2008
Posts: 2539
Location: STL

PostPosted: Thu Feb 14, 2019 1:43 pm    Post subject: Reply with quote

In addition, if you put a "." after an image you get the same error.

Also, you cannot post with an equal sign without the same error getting thrown up. 443 error.
_________________
The Unofficial Score Hero GH Guitar leaderboard for X/H/M/E: http://www.scorehero.com/forum/viewtopic.php?p=1638203#1638203
The Unofficial Score Hero RB Guitar leaderboard for X/H/M/E: http://rockband.scorehero.com/forum/viewtopic.php?p=703852#703852
The Unofficial Score Hero Bass GH leaderboard for X/H/M/E: http://www.scorehero.com/forum/viewtopic.php?t=107740
The Unofficial Score Hero Bass RB leaderboard for X/H/M/E: http://rockband.scorehero.com/forum/viewtopic.php?p=703842#703842
The Unofficial Cross Platform FGFC leaderboard for X/H/M/E: http://www.scorehero.com/forum/viewtopic.php?t=108548
Back to top
View user's profile Send private message PSN Name: bushidox
JCirri  





Joined: 04 Feb 2006
Posts: 4576

PostPosted: Fri Feb 15, 2019 6:09 am    Post subject: Reply with quote

These 403 issues are unfortunately all false positive pattern matches against some security checks that are being ran. I've been tweaking the ruleset to help cut these down, but it might be hard to entirely eliminate them.

Thanks for the notice on these specific cases - I'll look through the server logs tomorrow and see if I can target fixes on those.
_________________
Back to top
View user's profile Wiki User Page Send private message Visit poster's website XBL Gamertag: JCirri821 Wii Friend Code: 1455611809021899
JCirri  





Joined: 04 Feb 2006
Posts: 4576

PostPosted: Sat Feb 16, 2019 7:14 am    Post subject: Reply with quote

I think for the most part we'll unfortunately need to live with some inconvenience on these false positives, as I'm not seeing much else that I can easily / safely target without disabling larger chunks of useful security.

If you encounter a 403, which hopefully isn't very common, it's most certainly due to something in the post and I'd suggest trying again with portions removed or altered until it works.

Periods ending lines seems to be one situation, use of open and close parenthesis/brackets/etc. is another, so I'd try reducing the use of them as a first step when/if you hit the error.

In most browsers, hitting the "back" button after a 403 should restore post contents, so hopefully that would help to avoid losing the written post entirely.
_________________
Back to top
View user's profile Wiki User Page Send private message Visit poster's website XBL Gamertag: JCirri821 Wii Friend Code: 1455611809021899
Display posts from previous:   
Post new topic   Reply to topic    ScoreHero Forum Index -> Bug Reports All times are GMT
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum





Copyright © 2006-2024 ScoreHero, LLC
Terms of Use | Privacy Policy


Powered by phpBB