Anubis locks me out with "oh noes!" regularly, referring to disabled cookies (while cookies are enabled) #13427

Closed
opened 2026-06-22 13:17:06 +00:00 by py0xc3 · 12 comments

Description of request

I get more and more often locked out of Fedora services from Anubis ("Oh noes!"). My feeling is that the issues occur mostly when I'm at home with 5G Internet (not sure if the latency makes a difference or so?), but sometimes I need to refresh many times and then it works at some time, but sometimes it seems to not work at all. I have comparable issues with some kernel.org pages. I use our default Firefox build. Strict mode (with the recommended "fix major issues" enabled), ublock, noscript (having a page and its linked domains as "always trusted" in noscript does either not always mitigate the issue or has no impact at all). My cookies of fedoraproject.org are permanent.

The difference to the other ticket about the "oh noes!": I have no "internal server error". In my case, Anubis refers to me having cookies disabled, which obviously is not true as it works at some time when I keep refreshing (mostly at least ^^).

Additionally, I just identified that I likely experience two different issues, but both with the same error: on one hand, there are situations in which I just need to refresh several times, and at some point it works (although I sometimes gave up before that point is reached ^^).

Now, I experienced that I can so far 100% reproduce the issue when I go to https://github.com/py0xc3/mirror_self-moderation-guidelines-and-rules and then click the link https://forge.fedoraproject.org/discussion/self-moderation-guidelines-and-rules to be forwarded to the upstream repo -> this always causes an "oh noes!" and so far I could refresh as much as I wanted, it never changed. However, if I open this link by copy/paste without forwarding, it works immediately properly.

The latter issue is definitely caused by noScript, and I can reproduce it with 100% (noscript enabled) and 0% (noscript disabled).

But the first issue, that only occasionally occurs and needs many refreshes, remains. I try over time to find out if that has also a noScript relation but its harder to reproduce, and that many refreshes solve it at some point make me also question the relation.

Feel free to let me know if I shall collect something specific or so. I think the second issue can be neglected anyway.

The screenshot is always the same, in both issues, see attached. This is NOT urgent (neither of the issues).

### Description of request I get more and more often locked out of Fedora services from Anubis ("Oh noes!"). My feeling is that the issues occur mostly when I'm at home with 5G Internet (not sure if the latency makes a difference or so?), but sometimes I need to refresh many times and then it works at some time, but sometimes it seems to not work at all. I have comparable issues with some kernel.org pages. I use our default Firefox build. Strict mode (with the recommended "fix major issues" enabled), ublock, noscript (having a page and its linked domains as "always trusted" in noscript does either not always mitigate the issue or has no impact at all). My cookies of fedoraproject.org are permanent. The difference to the [other ticket about the "oh noes!"](https://forge.fedoraproject.org/infra/tickets/issues/13192): I have no "internal server error". In my case, Anubis refers to me having cookies disabled, which obviously is not true as it works at some time when I keep refreshing (mostly at least ^^). Additionally, I just identified that I likely experience two different issues, but both with the same error: on one hand, there are situations in which I just need to refresh several times, and at some point it works (although I sometimes gave up before that point is reached ^^). Now, I experienced that I can so far 100% reproduce the issue when I go to https://github.com/py0xc3/mirror_self-moderation-guidelines-and-rules and then click the link https://forge.fedoraproject.org/discussion/self-moderation-guidelines-and-rules to be forwarded to the upstream repo -> this **always** causes an "oh noes!" and so far I could refresh as much as I wanted, it never changed. However, if I open this link by copy/paste without forwarding, it works immediately properly. The latter issue is definitely caused by noScript, and I can reproduce it with 100% (noscript enabled) and 0% (noscript disabled). But the first issue, that only occasionally occurs and needs many refreshes, remains. I try over time to find out if that has also a noScript relation but its harder to reproduce, and that many refreshes solve it at some point make me also question the relation. Feel free to let me know if I shall collect something specific or so. I think the second issue can be neglected anyway. The screenshot is always the same, in both issues, see attached. This is **NOT** urgent (neither of the issues).

When attempting to manually download (with firefox) rpms from https://koji.fedoraproject.org/koji/buildinfo?buildID=3027449 I get this file instead of the RPM. This web app will not allow me to paste or upload it. It is an HTML page with javascript. The relevant text is:

"You are seeing this because the administrator of this website has set up Anubis to protect the server against the scourge of AI companies aggressively scraping websites. This can and does cause downtime for the websites, which makes their resources inaccessible for everyone."

When attempting to manually download (with firefox) rpms from https://koji.fedoraproject.org/koji/buildinfo?buildID=3027449 I get this file instead of the RPM. This web app will not allow me to paste or upload it. It is an HTML page with javascript. The relevant text is: "You are seeing this because the administrator of this website has set up Anubis to protect the server against the scourge of AI companies aggressively scraping websites. This can and does cause downtime for the websites, which makes their resources inaccessible for everyone."
Owner

Do you disable javascript or have any extensions that would affect javascript?

Also, we were having a proxy issue... perhaps just try again now?

Do you disable javascript or have any extensions that would affect javascript? Also, we were having a proxy issue... perhaps just try again now?

I tried with IPv4 instead of IPv6 - no change.

I tried with IPv4 instead of IPv6 - no change.

Suddenly started working ...

Suddenly started working ...
Author

Concerning the first phenomenon (the one not always reproducible), I haven't experienced it myself quite some time now. Maybe some update or so solved it.

Concerning the second phenomenon (the one 100%/0% reproducible with/without noscript), you don't need to keep this open for me as I can mitigate it, but it might be worth to consider to keep the ticket open and work on that: several privacy-focused OS have noscript enabled by default and users might not even know they use it. For them this might cause a DoS as some might not know if/how to mitigate (I understand compromises must be made though, so maybe that is not solvable given the need to protect the infra)

Feel free to let me know if I can help with any testing or so.

Concerning the first phenomenon (the one not always reproducible), I haven't experienced it myself quite some time now. Maybe some update or so solved it. Concerning the second phenomenon (the one 100%/0% reproducible with/without noscript), you don't need to keep this open for me as I can mitigate it, but it might be worth to consider to keep the ticket open and work on that: several privacy-focused OS have noscript enabled by default and users might not even know they use it. For them this might cause a DoS as some might not know if/how to mitigate (I understand compromises must be made though, so maybe that is not solvable given the need to protect the infra) Feel free to let me know if I can help with any testing or so.
Owner

I think this may have been all due to a misbehaving proxy. It had OOM killed it's varnish cache, so anything going through there resulted in problems. ;(

So, lets close this I guess and if you all see it again, please reopen or file a new issue.

Thanks and sorry for the trouble.

I think this may have been all due to a misbehaving proxy. It had OOM killed it's varnish cache, so anything going through there resulted in problems. ;( So, lets close this I guess and if you all see it again, please reopen or file a new issue. Thanks and sorry for the trouble.
kevin closed this issue 2026-07-04 17:17:36 +00:00
Author

@kevin I can no longer reproduce the first issue (the unpredictable one), but still the second issue [1] (the one reproducible 100% with /0% without noscript): not sure if I should open this again?

On one hand, it might exclude some users who want to open our pages through a link but don't know that they use noscript. On the other hand, I am not sure if a useful compromise is realistic without disabling what Anubis was introduced to do. I leave it to you if we shall re-open. I am happy to help / test as far as I can on my side.

[1] Still using https://github.com/py0xc3/mirror_self-moderation-guidelines-and-rules and then clicking on the forge link at the top right (below the "About")

@kevin I can no longer reproduce the first issue (the unpredictable one), but still the second issue [1] (the one reproducible 100% with /0% without noscript): not sure if I should open this again? On one hand, it might exclude some users who want to open our pages through a link but don't know that they use noscript. On the other hand, I am not sure if a useful compromise is realistic without disabling what Anubis was introduced to do. I leave it to you if we shall re-open. I am happy to help / test as far as I can on my side. [1] Still using https://github.com/py0xc3/mirror_self-moderation-guidelines-and-rules and then clicking on the forge link at the top right (below the "About")
Owner

So, to clarify, you have noscript set to disallow javascript? or what is its settings there?

So, to clarify, you have noscript set to disallow javascript? or what is its settings there?
Author

Actually, for everything under *.fedoraproject.org, javascript is enabled at all, without restrictions, see: image

So I expect my noscript is less restrictive than defaults.

Given that the issue occurs only in situations linked from other domains to here, I expect it is some XSS measure of noscript.

I installed noscript and its defaults not through Firefox but through dnf, so through the package mozilla-noscript.noarch that is auto-added to Firefox once installed.

I just modified the domains (see 1st screenshot). Beyond, it is default I think (though not 100% sure), but I cannot say "what" default (so of what time) given that I installed it years ago.

Supplement: it seems to be not the two tick in the "advanced" settings.

Pics of my noscript config below:

image
image
image

Actually, for everything under *.fedoraproject.org, javascript is enabled at all, without restrictions, see: ![image](/attachments/f92d8b33-9f74-4eb3-a7d2-45167693976c) So I expect my noscript is less restrictive than defaults. Given that the issue occurs only in situations linked from other domains to here, I expect it is some XSS measure of noscript. I installed noscript and its defaults not through Firefox but through dnf, so through the package `mozilla-noscript.noarch` that is auto-added to Firefox once installed. I just modified the domains (see 1st screenshot). Beyond, it is default I think (though not 100% sure), but I cannot say "what" default (so of what time) given that I installed it years ago. **Supplement:** it seems to be not the two tick in the "advanced" settings. Pics of my noscript config below: ![image](/attachments/08fcbf02-734a-468c-9dea-63f6a1d33603) ![image](/attachments/31e8fb48-b680-4512-a6fa-894d9745b3d6) ![image](/attachments/d5d00827-8f13-4b1d-96ab-a66b255e3e68)
Author

Another supplement: if I change the "Cross-tab identity leak protection" within the "advanced" settings from "enabled everywhere" to "disabled", then it works. 100% reproducible if I enable and disable this.

I doubt I changed that, so I assume that is the default many users have, some knowing, some not. The question will be if anything can be done to mitigate that without breaking the goal of Anubis.

Another supplement: if I change the "Cross-tab identity leak protection" within the "advanced" settings from "enabled everywhere" to "disabled", then it works. 100% reproducible if I enable and disable this. I doubt I changed that, so I assume that is the default many users have, some knowing, some not. The question will be if anything can be done to mitigate that without breaking the goal of Anubis.
Owner

Well, I am not sure how many people use noscript these days. And those that do probibly expect some javascript issues like this?

In this case I guess it is trying to make sure none of your info on the github page gets sent when you follow the link, but I'm not sure what is removed that anubis wants in order to load the page or challenge you like normal. ;(

Well, I am not sure how many people use noscript these days. And those that do probibly expect some javascript issues like this? In this case I guess it is trying to make sure none of your info on the github page gets sent when you follow the link, but I'm not sure what is removed that anubis wants in order to load the page or challenge you like normal. ;(
Author

Well, I am not sure how many people use noscript these days. And those that do probibly expect some javascript issues like this?

Don't know. Some privacy-focused systems use it by default. But I would assume it is a seldom case that someone uses, e.g., Tails to enter Fedora pages through external link.

So I agree its a minor case not worth much work (and that work might break the goals of anubis anyway). Let's keep it closed. Thanks for the efforts and the quick feedback and support though :)

> Well, I am not sure how many people use noscript these days. And those that do probibly expect some javascript issues like this? Don't know. Some privacy-focused systems use it by default. But I would assume it is a seldom case that someone uses, e.g., Tails to enter Fedora pages through external link. So I agree its a minor case not worth much work (and that work might break the goals of anubis anyway). Let's keep it closed. Thanks for the efforts and the quick feedback and support though :)
Sign in to join this conversation.
No milestone
No project
No assignees
3 participants
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
infra/tickets#13427
No description provided.