When I login in to the backoffice there is not content tree nodes, content, settings, media etc across the top menu and I get the following error
Authorization error: Unauthorized access to URL:
LocalizedText
Contact your administrator for information.
Authorization error: Unauthorized access to URL:
/umbraco/backoffice/umbracoapi/authentication/GetRemainingTimeoutSeconds
Contact your administrator for information.
If I click in the U icon top left the version is undefined.
If I click in the user button on top right i get:
Authorization error: Unauthorized access to URL:
views/common/overlays/user/user.html
Contact your administrator for information.
If I press on the help ? I get:
Authorization error: Unauthorized access to URL:
views/common/drawers/help/help.html
Contact your administrator for information.
Site behaves correctly on local system.
Was published to live server using VS2022 "publish" using FTP.
Website appears to work as expected.
when I refresh the page I get a 403 - Forbidden: Access is denied.
Failed to load resource: the server responded with a status of 403 ()
umbraco-backoffice-js.js.vbff92525987e3f7cfb9c113a93c5c023af38d7bc:147 Possibly unhandled rejection: {"errorMsg":"Failed to get tours","data":"<!DOCTYPE html PUBLIC \"-//W3C//DTD XHTML 1.0 Strict//EN\" \"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd\">\r\n<html xmlns=\"http://www.w3.org/1999/xhtml\">\r\n<head>\r\n<meta http-equiv=\"Content-Type\" content=\"text/html; charset=iso-8859-1\"/>\r\n<title>403 - Forbidden: Access is denied.</title>\r\n<style type=\"text/css\">\r\n<!--\r\nbody{margin:0;font-size:.7em;font-family:Verdana, Arial, Helvetica, sans-serif;background:#EEEEEE;}\r\nfieldset{padding:0 15px 10px 15px;} \r\nh1{font-size:2.4em;margin:0;color:#FFF;}\r\nh2{font-size:1.7em;margin:0;color:#CC0000;} \r\nh3{font-size:1.2em;margin:10px 0 0 0;color:#000000;} \r\n#header{width:96%;margin:0 0 0 0;padding:6px 2% 6px 2%;font-family:\"trebuchet MS\", Verdana, sans-serif;color:#FFF;\r\nbackground-color:#555555;}\r\n#content{margin:0 0 0 2%;position:relative;}\r\n.content-container{background:#FFF;width:96%;margin-top:8px;padding:10px;position:relative;}\r\n-->\r\n</style>\r\n</head>\r\n<body>\r\n<div id=\"header\"><h1>Server Error</h1></div>\r\n<div id=\"content\">\r\n <div class=\"content-container\"><fieldset>\r\n <h2>403 - Forbidden: Access is denied.</h2>\r\n <h3>You do not have permission to view this directory or page using the credentials that you supplied.</h3>\r\n </fieldset></div>\r\n</div>\r\n</body>\r\n</html>\r\n","status":403}
(anonymous) @ umbraco-backoffice-js.js.vbff92525987e3f7cfb9c113a93c5c023af38d7bc:147
umbraco/backoffice/umbracoapi/language/GetAllLanguages:1 Failed to load resource: the server responded with a status of 403 ()
umbraco-backoffice-js.js.vbff92525987e3f7cfb9c113a93c5c023af38d7bc:147 Possibly unhandled rejection: {"errorMsg":"Failed to get languages","data":"<!DOCTYPE html PUBLIC \"-//W3C//DTD XHTML 1.0 Strict//EN\" \"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd\">\r\n<html xmlns=\"http://www.w3.org/1999/xhtml\">\r\n<head>\r\n<meta http-equiv=\"Content-Type\" content=\"text/html; charset=iso-8859-1\"/>\r\n<title>403 - Forbidden: Access is denied.</title>\r\n<style type=\"text/css\">\r\n<!--\r\nbody{margin:0;font-size:.7em;font-family:Verdana, Arial, Helvetica, sans-serif;background:#EEEEEE;}\r\nfieldset{padding:0 15px 10px 15px;} \r\nh1{font-size:2.4em;margin:0;color:#FFF;}\r\nh2{font-size:1.7em;margin:0;color:#CC0000;} \r\nh3{font-size:1.2em;margin:10px 0 0 0;color:#000000;} \r\n#header{width:96%;margin:0 0 0 0;padding:6px 2% 6px 2%;font-family:\"trebuchet MS\", Verdana, sans-serif;color:#FFF;\r\nbackground-color:#555555;}\r\n#content{margin:0 0 0 2%;position:relative;}\r\n.content-container{background:#FFF;width:96%;margin-top:8px;padding:10px;position:relative;}\r\n-->\r\n</style>\r\n</head>\r\n<body>\r\n<div id=\"header\"><h1>Server Error</h1></div>\r\n<div id=\"content\">\r\n <div class=\"content-container\"><fieldset>\r\n <h2>403 - Forbidden: Access is denied.</h2>\r\n <h3>You do not have permission to view this directory or page using the credentials that you supplied.</h3>\r\n </fieldset></div>\r\n</div>\r\n</body>\r\n</html>\r\n","status":403}
(anonymous) @ umbraco-backoffice-js.js.vbff92525987e3f7cfb9c113a93c5c023af38d7bc:147
umbraco/backoffice/umbracoapi/dashboard/GetDashboard?section=content:1 Failed to load resource: the server responded with a status of 403 ()
umbraco-backoffice-js.js.vbff92525987e3f7cfb9c113a93c5c023af38d7bc:147 Possibly unhandled rejection: {"errorMsg":"Failed to get dashboard content","data":"<!DOCTYPE html PUBLIC \"-//W3C//DTD XHTML 1.0 Strict//EN\" \"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd\">\r\n<html xmlns=\"http://www.w3.org/1999/xhtml\">\r\n<head>\r\n<meta http-equiv=\"Content-Type\" content=\"text/html; charset=iso-8859-1\"/>\r\n<title>403 - Forbidden: Access is denied.</title>\r\n<style type=\"text/css\">\r\n<!--\r\nbody{margin:0;font-size:.7em;font-family:Verdana, Arial, Helvetica, sans-serif;background:#EEEEEE;}\r\nfieldset{padding:0 15px 10px 15px;} \r\nh1{font-size:2.4em;margin:0;color:#FFF;}\r\nh2{font-size:1.7em;margin:0;color:#CC0000;} \r\nh3{font-size:1.2em;margin:10px 0 0 0;color:#000000;} \r\n#header{width:96%;margin:0 0 0 0;padding:6px 2% 6px 2%;font-family:\"trebuchet MS\", Verdana, sans-serif;color:#FFF;\r\nbackground-color:#555555;}\r\n#content{margin:0 0 0 2%;position:relative;}\r\n.content-container{background:#FFF;width:96%;margin-top:8px;padding:10px;position:relative;}\r\n-->\r\n</style>\r\n</head>\r\n<body>\r\n<div id=\"header\"><h1>Server Error</h1></div>\r\n<div id=\"content\">\r\n <div class=\"content-container\"><fieldset>\r\n <h2>403 - Forbidden: Access is denied.</h2>\r\n <h3>You do not have permission to view this directory or page using the credentials that you supplied.</h3>\r\n </fieldset></div>\r\n</div>\r\n</body>\r\n</html>\r\n","status":403}
(anonymous) @ umbraco-backoffice-js.js.vbff92525987e3f7cfb9c113a93c5c023af38d7bc:147
umbraco/backoffice/umbracoapi/dashboard/GetDashboard?section=media:1 Failed to load resource: the server responded with a status of 403 ()
umbraco-backoffice-js.js.vbff92525987e3f7cfb9c113a93c5c023af38d7bc:147 Possibly unhandled rejection: {"errorMsg":"Failed to get dashboard media","data":"<!DOCTYPE html PUBLIC \"-//W3C//DTD XHTML 1.0 Strict//EN\" \"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd\">\r\n<html xmlns=\"http://www.w3.org/1999/xhtml\">\r\n<head>\r\n<meta http-equiv=\"Content-Type\" content=\"text/html; charset=iso-8859-1\"/>\r\n<title>403 - Forbidden: Access is denied.</title>\r\n<style type=\"text/css\">\r\n<!--\r\nbody{margin:0;font-size:.7em;font-family:Verdana, Arial, Helvetica, sans-serif;background:#EEEEEE;}\r\nfieldset{padding:0 15px 10px 15px;} \r\nh1{font-size:2.4em;margin:0;color:#FFF;}\r\nh2{font-size:1.7em;margin:0;color:#CC0000;} \r\nh3{font-size:1.2em;margin:10px 0 0 0;color:#000000;} \r\n#header{width:96%;margin:0 0 0 0;padding:6px 2% 6px 2%;font-family:\"trebuchet MS\", Verdana, sans-serif;color:#FFF;\r\nbackground-color:#555555;}\r\n#content{margin:0 0 0 2%;position:relative;}\r\n.content-container{background:#FFF;width:96%;margin-top:8px;padding:10px;position:relative;}\r\n-->\r\n</style>\r\n</head>\r\n<body>\r\n<div id=\"header\"><h1>Server Error</h1></div>\r\n<div id=\"content\">\r\n <div class=\"content-container\"><fieldset>\r\n <h2>403 - Forbidden: Access is denied.</h2>\r\n <h3>You do not have permission to view this directory or page using the credentials that you supplied.</h3>\r\n </fieldset></div>\r\n</div>\r\n</body>\r\n</html>\r\n","status":403}
(anonymous) @ umbraco-backoffice-js.js.vbff92525987e3f7cfb9c113a93c5c023af38d7bc:147
umbraco/backoffice/umbracoapi/dashboard/GetDashboard?section=content:1 Failed to load resource: the server responded with a status of 403 ()
umbraco-backoffice-js.js.vbff92525987e3f7cfb9c113a93c5c023af38d7bc:147 Possibly unhandled rejection: {"errorMsg":"Failed to get dashboard content","data":"<!DOCTYPE html PUBLIC \"-//W3C//DTD XHTML 1.0 Strict//EN\" \"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd\">\r\n<html xmlns=\"http://www.w3.org/1999/xhtml\">\r\n<head>\r\n<meta http-equiv=\"Content-Type\" content=\"text/html; charset=iso-8859-1\"/>\r\n<title>403 - Forbidden: Access is denied.</title>\r\n<style type=\"text/css\">\r\n<!--\r\nbody{margin:0;font-size:.7em;font-family:Verdana, Arial, Helvetica, sans-serif;background:#EEEEEE;}\r\nfieldset{padding:0 15px 10px 15px;} \r\nh1{font-size:2.4em;margin:0;color:#FFF;}\r\nh2{font-size:1.7em;margin:0;color:#CC0000;} \r\nh3{font-size:1.2em;margin:10px 0 0 0;color:#000000;} \r\n#header{width:96%;margin:0 0 0 0;padding:6px 2% 6px 2%;font-family:\"trebuchet MS\", Verdana, sans-serif;color:#FFF;\r\nbackground-color:#555555;}\r\n#content{margin:0 0 0 2%;position:relative;}\r\n.content-container{background:#FFF;width:96%;margin-top:8px;padding:10px;position:relative;}\r\n-->\r\n</style>\r\n</head>\r\n<body>\r\n<div id=\"header\"><h1>Server Error</h1></div>\r\n<div id=\"content\">\r\n <div class=\"content-container\"><fieldset>\r\n <h2>403 - Forbidden: Access is denied.</h2>\r\n <h3>You do not have permission to view this directory or page using the credentials that you supplied.</h3>\r\n </fieldset></div>\r\n</div>\r\n</body>\r\n</html>\r\n","status":403}
(anonymous) @ umbraco-backoffice-js.js.vbff92525987e3f7cfb9c113a93c5c023af38d7bc:147
umbraco/views/common/drawers/help/help.html?umb__rnd=55cf41cb7a843f406e64be738e39702729f99e46:1 Failed to load resource: the server responded with a status of 403 ()
umbraco/backoffice/umbracoapi/authentication/GetRemainingTimeoutSeconds:1 Failed to load resource: the server responded with a status of 403 ()
umbraco-backoffice-js.js.vbff92525987e3f7cfb9c113a93c5c023af38d7bc:147 Possibly unhandled rejection: {"errorMsg":"Server call failed for checking remaining seconds","data":"<!DOCTYPE html PUBLIC \"-//W3C//DTD XHTML 1.0 Strict//EN\" \"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd\">\r\n<html xmlns=\"http://www.w3.org/1999/xhtml\">\r\n<head>\r\n<meta http-equiv=\"Content-Type\" content=\"text/html; charset=iso-8859-1\"/>\r\n<title>403 - Forbidden: Access is denied.</title>\r\n<style type=\"text/css\">\r\n<!--\r\nbody{margin:0;font-size:.7em;font-family:Verdana, Arial, Helvetica, sans-serif;background:#EEEEEE;}\r\nfieldset{padding:0 15px 10px 15px;} \r\nh1{font-size:2.4em;margin:0;color:#FFF;}\r\nh2{font-size:1.7em;margin:0;color:#CC0000;} \r\nh3{font-size:1.2em;margin:10px 0 0 0;color:#000000;} \r\n#header{width:96%;margin:0 0 0 0;padding:6px 2% 6px 2%;font-family:\"trebuchet MS\", Verdana, sans-serif;color:#FFF;\r\nbackground-color:#555555;}\r\n#content{margin:0 0 0 2%;position:relative;}\r\n.content-container{background:#FFF;width:96%;margin-top:8px;padding:10px;position:relative;}\r\n-->\r\n</style>\r\n</head>\r\n<body>\r\n<div id=\"header\"><h1>Server Error</h1></div>\r\n<div id=\"content\">\r\n <div class=\"content-container\"><fieldset>\r\n <h2>403 - Forbidden: Access is denied.</h2>\r\n <h3>You do not have permission to view this directory or page using the credentials that you supplied.</h3>\r\n </fieldset></div>\r\n</div>\r\n</body>\r\n</html>\r\n","status":403}
(anonymous) @ umbraco-backoffice-js.js.vbff92525987e3f7cfb9c113a93c5c023af38d7bc:147
umbraco/backoffice/umbracoapi/dashboard/GetDashboard?section=media:1 Failed to load resource: the server responded with a status of 403 ()
umbraco-backoffice-js.js.vbff92525987e3f7cfb9c113a93c5c023af38d7bc:147 Possibly unhandled rejection: {"errorMsg":"Failed to get dashboard media","data":"<!DOCTYPE html PUBLIC \"-//W3C//DTD XHTML 1.0 Strict//EN\" \"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd\">\r\n<html xmlns=\"http://www.w3.org/1999/xhtml\">\r\n<head>\r\n<meta http-equiv=\"Content-Type\" content=\"text/html; charset=iso-8859-1\"/>\r\n<title>403 - Forbidden: Access is denied.</title>\r\n<style type=\"text/css\">\r\n<!--\r\nbody{margin:0;font-size:.7em;font-family:Verdana, Arial, Helvetica, sans-serif;background:#EEEEEE;}\r\nfieldset{padding:0 15px 10px 15px;} \r\nh1{font-size:2.4em;margin:0;color:#FFF;}\r\nh2{font-size:1.7em;margin:0;color:#CC0000;} \r\nh3{font-size:1.2em;margin:10px 0 0 0;color:#000000;} \r\n#header{width:96%;margin:0 0 0 0;padding:6px 2% 6px 2%;font-family:\"trebuchet MS\", Verdana, sans-serif;color:#FFF;\r\nbackground-color:#555555;}\r\n#content{margin:0 0 0 2%;position:relative;}\r\n.content-container{background:#FFF;width:96%;margin-top:8px;padding:10px;position:relative;}\r\n-->\r\n</style>\r\n</head>\r\n<body>\r\n<div id=\"header\"><h1>Server Error</h1></div>\r\n<div id=\"content\">\r\n <div class=\"content-container\"><fieldset>\r\n <h2>403 - Forbidden: Access is denied.</h2>\r\n <h3>You do not have permission to view this directory or page using the credentials that you supplied.</h3>\r\n </fieldset></div>\r\n</div>\r\n</body>\r\n</html>\r\n","status":403}
(anonymous) @ umbraco-backoffice-js.js.vbff92525987e3f7cfb9c113a93c5c023af38d7bc:147
umbraco/backoffice/umbracoapi/dashboard/GetDashboard?section=content:1 Failed to load resource: the server responded with a status of 403 ()
umbraco-backoffice-js.js.vbff92525987e3f7cfb9c113a93c5c023af38d7bc:147 Possibly unhandled rejection: {"errorMsg":"Failed to get dashboard content","data":"<!DOCTYPE html PUBLIC \"-//W3C//DTD XHTML 1.0 Strict//EN\" \"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd\">\r\n<html xmlns=\"http://www.w3.org/1999/xhtml\">\r\n<head>\r\n<meta http-equiv=\"Content-Type\" content=\"text/html; charset=iso-8859-1\"/>\r\n<title>403 - Forbidden: Access is denied.</title>\r\n<style type=\"text/css\">\r\n<!--\r\nbody{margin:0;font-size:.7em;font-family:Verdana, Arial, Helvetica, sans-serif;background:#EEEEEE;}\r\nfieldset{padding:0 15px 10px 15px;} \r\nh1{font-size:2.4em;margin:0;color:#FFF;}\r\nh2{font-size:1.7em;margin:0;color:#CC0000;} \r\nh3{font-size:1.2em;margin:10px 0 0 0;color:#000000;} \r\n#header{width:96%;margin:0 0 0 0;padding:6px 2% 6px 2%;font-family:\"trebuchet MS\", Verdana, sans-serif;color:#FFF;\r\nbackground-color:#555555;}\r\n#content{margin:0 0 0 2%;position:relative;}\r\n.content-container{background:#FFF;width:96%;margin-top:8px;padding:10px;position:relative;}\r\n-->\r\n</style>\r\n</head>\r\n<body>\r\n<div id=\"header\"><h1>Server Error</h1></div>\r\n<div id=\"content\">\r\n <div class=\"content-container\"><fieldset>\r\n <h2>403 - Forbidden: Access is denied.</h2>\r\n <h3>You do not have permission to view this directory or page using the credentials that you supplied.</h3>\r\n </fieldset></div>\r\n</div>\r\n</body>\r\n</html>\r\n","status":403}
Authorization error: Unauthorized access to URL:
/umbraco/backoffice/umbracoapi/backofficeassets/GetSupportedLocales
Contact your administrator for information.
×
Authorization error: Unauthorized access to URL:
/umbraco/backoffice/umbracoapi/updatecheck/GetCheck
Contact your administrator for information.
×
Authorization error: Unauthorized access to URL:
LocalizedText
Contact your administrator for information.
×
Authorization error: Unauthorized access to URL:
/umbraco/backoffice/umbracoapi/tour/GetTours
Contact your administrator for information.
×
Authorization error: Unauthorized access to URL:
/umbraco/backoffice/umbracoapi/contenttype/AllowsCultureVariation
Contact your administrator for information.
×
Authorization error: Unauthorized access to URL:
/umbraco/backoffice/umbracoapi/section/GetSections
Contact your administrator for information.
×
Authorization error: Unauthorized access to URL:
/umbraco/backoffice/umbracoapi/section/GetSections
Contact your administrator for information.
Have you found a solution for this issue? I'm seeing something very similar.
I've tried adjusting the folder permissions for the account used by the Application Pool. That didn't seem to help at all. They were already setup correctly.
"Each incoming HTTP request and the related response are checked against a set of rules. If the check succeeds, the HTTP request is passed to website content. If the check fails, the event is logged, a notification is sent, and the HTTP response is provided with an error code."
The backoffice errors occour.
If I change it to Detection only
"Each incoming HTTP request and the related response are checked against a set of rules. If the check succeeds, the HTTP request is passed to website content. If the check fails, the event is logged and ModSecurity performs no other actions. Other services (for example, Fail2ban) can still perform their own actions on HTTP requests that failed the check."
The backoffice works and the error catchments are
there is a list of activities that are allowed and disallowed.
looking in the error log spotted [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sq
Umbraco9 live backoffice not showing any content
Have just setup my first live umbraco9 site.
When I login in to the backoffice there is not content tree nodes, content, settings, media etc across the top menu and I get the following error
Authorization error: Unauthorized access to URL: LocalizedText Contact your administrator for information.
Authorization error: Unauthorized access to URL: /umbraco/backoffice/umbracoapi/authentication/GetRemainingTimeoutSeconds Contact your administrator for information.
If I click in the U icon top left the version is undefined.
If I click in the user button on top right i get:
Authorization error: Unauthorized access to URL: views/common/overlays/user/user.html Contact your administrator for information.
If I press on the help ? I get:
Authorization error: Unauthorized access to URL: views/common/drawers/help/help.html Contact your administrator for information.
Site behaves correctly on local system.
Was published to live server using VS2022 "publish" using FTP.
Website appears to work as expected.
when I refresh the page I get a 403 - Forbidden: Access is denied.
Has anyone got any advice. Have tried upgrading to version 10 and have the same problem still.
This is getting really frustrating.
See a list of console errors.
Dan,
Have you found a solution for this issue? I'm seeing something very similar.
I've tried adjusting the folder permissions for the account used by the Application Pool. That didn't seem to help at all. They were already setup correctly.
Thanks,
-Mike
Hi Mike I still haven't found a solution. Although there are plenty of posts that could relate.
Have you found a solution yet.
Hi Mike unfortunately I haven't found a solution. I have done the same.
I Have made progress. But not there yet.
The issue is to do with the firewall.
If i have Web application firewall set to on
"Each incoming HTTP request and the related response are checked against a set of rules. If the check succeeds, the HTTP request is passed to website content. If the check fails, the event is logged, a notification is sent, and the HTTP response is provided with an error code."
The backoffice errors occour.
If I change it to Detection only
"Each incoming HTTP request and the related response are checked against a set of rules. If the check succeeds, the HTTP request is passed to website content. If the check fails, the event is logged and ModSecurity performs no other actions. Other services (for example, Fail2ban) can still perform their own actions on HTTP requests that failed the check."
The backoffice works and the error catchments are
there is a list of activities that are allowed and disallowed.
looking in the error log spotted [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sq
So deactivating platform-multi solved the issue.
I'm having the same exact issue.... But don't seem to have a firewall configuration in my hosting provider (with Plesk)
is working on a reply...