Anubis locks me out with "oh noes!" regularly, referring to disabled cookies (while cookies are enabled) #13427
Labels
No labels
announcement
anubis
authentication
aws
backlog
blocked
bodhi
ci
cloud
communishift
copr
database
day-to-day
dc-move
deprecated
dev
discourse
dns
downloads
easyfix
epel
firmitas
forgejo_migration
Gain
High
Gain
Low
Gain
Medium
gitlab
greenwave
hardware
help wanted
high-trouble
koji
koschei
lists
low-trouble
medium-trouble
mirrorlists
monitoring
Needs investigation
odcs
OpenShift
ops
outage
packager_workflow_blocker
pagure
permissions
Priority
Needs Review
Priority
Next Meeting
Priority
🔥 URGENT 🔥
Priority
Waiting on Assignee
Priority
Waiting on External
Priority
Waiting on Reporter
rabbitmq
release-monitoring
releng
request-for-resources
s390x
security
SMTP
sprint-0
sprint-1
src.fp.o
staging
unfreeze
waiverdb
websites-general
wiki
Backlog Status
Needs Review
Backlog Status
Ready
chore
documentation
points
01
points
02
points
03
points
05
points
08
points
13
Priority
High
Priority
Low
Priority
Medium
Sprint Status
Blocked
Sprint Status
Done
Sprint Status
In Progress
Sprint Status
Review
Sprint Status
To Do
Technical Debt
Work Item
Bug
Work Item
Epic
Work Item
Spike
Work Item
Task
Work Item
User Story
No milestone
No project
No assignees
3 participants
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
infra/tickets#13427
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Description of request
I get more and more often locked out of Fedora services from Anubis ("Oh noes!"). My feeling is that the issues occur mostly when I'm at home with 5G Internet (not sure if the latency makes a difference or so?), but sometimes I need to refresh many times and then it works at some time, but sometimes it seems to not work at all. I have comparable issues with some kernel.org pages. I use our default Firefox build. Strict mode (with the recommended "fix major issues" enabled), ublock, noscript (having a page and its linked domains as "always trusted" in noscript does either not always mitigate the issue or has no impact at all). My cookies of fedoraproject.org are permanent.
The difference to the other ticket about the "oh noes!": I have no "internal server error". In my case, Anubis refers to me having cookies disabled, which obviously is not true as it works at some time when I keep refreshing (mostly at least ^^).
Additionally, I just identified that I likely experience two different issues, but both with the same error: on one hand, there are situations in which I just need to refresh several times, and at some point it works (although I sometimes gave up before that point is reached ^^).
Now, I experienced that I can so far 100% reproduce the issue when I go to https://github.com/py0xc3/mirror_self-moderation-guidelines-and-rules and then click the link https://forge.fedoraproject.org/discussion/self-moderation-guidelines-and-rules to be forwarded to the upstream repo -> this always causes an "oh noes!" and so far I could refresh as much as I wanted, it never changed. However, if I open this link by copy/paste without forwarding, it works immediately properly.
The latter issue is definitely caused by noScript, and I can reproduce it with 100% (noscript enabled) and 0% (noscript disabled).
But the first issue, that only occasionally occurs and needs many refreshes, remains. I try over time to find out if that has also a noScript relation but its harder to reproduce, and that many refreshes solve it at some point make me also question the relation.
Feel free to let me know if I shall collect something specific or so. I think the second issue can be neglected anyway.
The screenshot is always the same, in both issues, see attached. This is NOT urgent (neither of the issues).
When attempting to manually download (with firefox) rpms from https://koji.fedoraproject.org/koji/buildinfo?buildID=3027449 I get this file instead of the RPM. This web app will not allow me to paste or upload it. It is an HTML page with javascript. The relevant text is:
"You are seeing this because the administrator of this website has set up Anubis to protect the server against the scourge of AI companies aggressively scraping websites. This can and does cause downtime for the websites, which makes their resources inaccessible for everyone."
Do you disable javascript or have any extensions that would affect javascript?
Also, we were having a proxy issue... perhaps just try again now?
I tried with IPv4 instead of IPv6 - no change.
Suddenly started working ...
Concerning the first phenomenon (the one not always reproducible), I haven't experienced it myself quite some time now. Maybe some update or so solved it.
Concerning the second phenomenon (the one 100%/0% reproducible with/without noscript), you don't need to keep this open for me as I can mitigate it, but it might be worth to consider to keep the ticket open and work on that: several privacy-focused OS have noscript enabled by default and users might not even know they use it. For them this might cause a DoS as some might not know if/how to mitigate (I understand compromises must be made though, so maybe that is not solvable given the need to protect the infra)
Feel free to let me know if I can help with any testing or so.
I think this may have been all due to a misbehaving proxy. It had OOM killed it's varnish cache, so anything going through there resulted in problems. ;(
So, lets close this I guess and if you all see it again, please reopen or file a new issue.
Thanks and sorry for the trouble.
@kevin I can no longer reproduce the first issue (the unpredictable one), but still the second issue [1] (the one reproducible 100% with /0% without noscript): not sure if I should open this again?
On one hand, it might exclude some users who want to open our pages through a link but don't know that they use noscript. On the other hand, I am not sure if a useful compromise is realistic without disabling what Anubis was introduced to do. I leave it to you if we shall re-open. I am happy to help / test as far as I can on my side.
[1] Still using https://github.com/py0xc3/mirror_self-moderation-guidelines-and-rules and then clicking on the forge link at the top right (below the "About")
So, to clarify, you have noscript set to disallow javascript? or what is its settings there?
Actually, for everything under *.fedoraproject.org, javascript is enabled at all, without restrictions, see:
So I expect my noscript is less restrictive than defaults.
Given that the issue occurs only in situations linked from other domains to here, I expect it is some XSS measure of noscript.
I installed noscript and its defaults not through Firefox but through dnf, so through the package
mozilla-noscript.noarchthat is auto-added to Firefox once installed.I just modified the domains (see 1st screenshot). Beyond, it is default I think (though not 100% sure), but I cannot say "what" default (so of what time) given that I installed it years ago.
Supplement: it seems to be not the two tick in the "advanced" settings.
Pics of my noscript config below:
Another supplement: if I change the "Cross-tab identity leak protection" within the "advanced" settings from "enabled everywhere" to "disabled", then it works. 100% reproducible if I enable and disable this.
I doubt I changed that, so I assume that is the default many users have, some knowing, some not. The question will be if anything can be done to mitigate that without breaking the goal of Anubis.
Well, I am not sure how many people use noscript these days. And those that do probibly expect some javascript issues like this?
In this case I guess it is trying to make sure none of your info on the github page gets sent when you follow the link, but I'm not sure what is removed that anubis wants in order to load the page or challenge you like normal. ;(
Don't know. Some privacy-focused systems use it by default. But I would assume it is a seldom case that someone uses, e.g., Tails to enter Fedora pages through external link.
So I agree its a minor case not worth much work (and that work might break the goals of anubis anyway). Let's keep it closed. Thanks for the efforts and the quick feedback and support though :)