Support

Admin Tools

#28843 Template Creator 403 cannot preview

Posted in ‘Admin Tools for Joomla! 4 & 5’
This is a public ticket

Everybody will be able to see its contents. Do not include usernames, passwords or any other sensitive information.

Environment Information

Joomla! version
n/a
PHP version
n/a
Admin Tools version
n/a

Latest post by on Wednesday, 10 January 2018 17:17 CST

joomleb
Hi guys,

using Template Creator CK building my "material" template, when I preview the template Ihave back a 403 error page.

Following this Admin Tools support ticket

In the Security Exceptions Logs I have back the URL https://mysite.com/index.php?option=com_content&templatename=material&template=templatecreatorck&tmpl=preview

In "Web Application Firewall > Configure WAF > Visual Fingerprinting Protection > List of allowed tmpl= keywords: I set "material"

But I still have back the same error.
Please, Can you help me ?

nicholas
Akeeba Staff
Manager
You were very close but not close enough :) On the Configure WAF pages you need to do two things.

First, in the List of allowed tmpl= keywords add preview Why? Look at the URL. The parameter there reads tmpl=preview hence the name of the Joomla! rendering template you need to use.

Second, set "Block template=foo site template switch" to No. Why? Look at the URL again. The template used is template=templatecreatorck which is a virtual template: it doesn't really exist as a template on your site. Therefore we cannot use the simpler and safer "Allow site templates" option.

Nicholas K. Dionysopoulos

Lead Developer and Director

πŸ‡¬πŸ‡·Greek: native πŸ‡¬πŸ‡§English: excellent πŸ‡«πŸ‡·French: basic β€’ πŸ• My time zone is Europe / Athens
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

joomleb
Hi Nicholas,
many thanks for the too appreciate explications. It's running.

Now, always in Template Creator CK, exporting the Gabarit file I have back a blank page when I download it.

I set joomla "Debug System" / "Error Reporting" andI have no back errors.

I suppose it is something related with the .htaccess maker, but I'm not able to have it back running

Please, Can you help me on it ?

nicholas
Akeeba Staff
Manager
Good God! I thought that Cedric would have known better

I would urge you to ask Cedric to fix this issue. There are several ways for him to fix this:

  • The downloads of the tck3z files must go through a Joomla! controller, not directly through the browser. Preferred for security reasons.
  • The files must be placed in a subfolder of the the media/com_templateck folder.


I STRONGLY recommend the first option. The way the extension is written right now means that anyone can download the file from your site as long as they know the name. Considering that the name of the file is also the name of the template, visible in the source code of your site, it's not that hard to guess.

In the meantime you could, of course, do as he says. In the .htaccess Maker add
components/com_templateck/projects
(note that you must use forward slashes) to the list of directories where all files, except .php, are allowed. Remember to regenerate the .htaccess file. I just don't recommend it because of the obvious security / privacy implications.

Maybe ask Cedric to email me? I can't find his email :/

Nicholas K. Dionysopoulos

Lead Developer and Director

πŸ‡¬πŸ‡·Greek: native πŸ‡¬πŸ‡§English: excellent πŸ‡«πŸ‡·French: basic β€’ πŸ• My time zone is Europe / Athens
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

joomleb
Hi Nicholas,

I post to him in the forum and sent to you his email

Thanks for help,
Emiliano

nicholas
Akeeba Staff
Manager
Thank you!

Nicholas K. Dionysopoulos

Lead Developer and Director

πŸ‡¬πŸ‡·Greek: native πŸ‡¬πŸ‡§English: excellent πŸ‡«πŸ‡·French: basic β€’ πŸ• My time zone is Europe / Athens
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

System Task
system
This ticket has been automatically closed. All tickets which have been inactive for a long time are automatically closed. If you believe that this ticket was closed in error, please contact us.

Support Information

Working hours: We are open Monday to Friday, 9am to 7pm Cyprus timezone (EET / EEST). Support is provided by the same developers writing the software, all of which live in Europe. You can still file tickets outside of our working hours, but we cannot respond to them until we're back at the office.

Support policy: We would like to kindly inform you that when using our support you have already agreed to the Support Policy which is part of our Terms of Service. Thank you for your understanding and for helping us help you!