Thantis
  •  Thantis
  • 81.8% (Honored)
  • YAF Commander Topic Starter
2012-01-27T01:04:44Z
Hello,

I am currently running a forum on v1.9.5.5 RTW, hosted on a server 2008 IIS 7 server. The forum has worked great for a long while, up until recently. Users are now experiencing an issue when logging in now. Any user that tries to log in, if they correctly supply their username/password, instead of being directed to the forum is immediately redirected straight back to the login page. I can't provide a log error (unless YAF saves it somewhere in the directory and I just haven't discovered it) since even I can no longer log into the forum. Any ideas?
Sponsor
daveburke
2012-01-27T01:57:59Z
When users are sent to the login page it means they don't have permissions to...something.

Sorry for not being able to give you a more detailed response, but think about any changes to the site. Even an image could trigger this type of behavior. Perhaps viewing the chain-of-events in Fiddler may help you.

Good luck!
-Dave
Thantis
  •  Thantis
  • 81.8% (Honored)
  • YAF Commander Topic Starter
2012-01-29T03:55:29Z
Hey Dave,

Thanks for the quick response. I gave fiddler a look and all I am getting back is this:

# Result Protocol Host URL Body Caching Content-Type Process Comments Custom
2 200 HTTP /ThantisForum/Default.aspx?g=login& 32 no-cache Expires: -1 text/plain; charset=utf-8 iexplore:3912
3 302 HTTP /ThantisForum/ 198 private text/html; charset=utf-8 iexplore:3912
4 200 HTTP /ThantisForum/yaf_login.aspx?returnurl=%2fThantisForum%2fdefault.aspx 16,532 private text/html; charset=utf-8 iexplore:3912

Maybe I'm missing something, or don't have fiddler setup correctly, but it seems like as soon as I log in it redirects to
the login page without trying anything else... Any ideas?
daveburke
2012-01-29T14:29:06Z
Thantis,

The HTTP 302 tells the tale, a temporary redirect for performing a redirection. What's happening on /ThantisForum/default.aspx? Can you access it when not logged in to the forum? What are its IIS permissions and authentication (NT Authentication vrs Anonymous), etc.

Also, have you made any changes to forum access?

Good luck,
Dave
Thantis
  •  Thantis
  • 81.8% (Honored)
  • YAF Commander Topic Starter
2012-01-29T20:31:20Z
Hmm. Well, there haven't been any changes in access to the forum itself, nor the directory structure.
I'm using Anon authentication, via pass-through from the app-pool account (Network Service). I've double
checked that IUSR/IIS_USERS and Network Service have access for read/write and they both do for the
whole forum directory. I'm beginning to think their may be something wrong with IIS or WAS (Windows Process Activation Service) I'm kind of stumped.. I suppose as a last resort I can uninstall IIS and WAS and start over, if you don't have any other ideas.
squirrel
2012-01-29T21:39:11Z
Originally Posted by: Thantis 

Hmm. Well, there haven't been any changes in access to the forum itself, nor the directory structure.
I'm using Anon authentication, via pass-through from the app-pool account (Network Service). I've double
checked that IUSR/IIS_USERS and Network Service have access for read/write and they both do for the
whole forum directory. I'm beginning to think their may be something wrong with IIS or WAS (Windows Process Activation Service) I'm kind of stumped.. I suppose as a last resort I can uninstall IIS and WAS and start over, if you don't have any other ideas.



Your redirects are coming from YAF I'm almost willing to bet.

If you have access to the webserver logs, I would attempt to load the site, do your login, and once you're redirected, immediately open a copy of the webserver log for that timeframe -- you will be given the full URL of the path of the file that is being served/redirected. From there, we might be able to figure out what's happening. I wouldn't go blaming IIS/WAS just yet, as you are currently serving pages -- you are just suffering from some form of YAF redirect it seems.
If you can't find it using the forum search, try my signature link -- searches this site using Google: Google is my Friend 
Thantis
  •  Thantis
  • 81.8% (Honored)
  • YAF Commander Topic Starter
2012-01-30T02:38:52Z
Hey Squirrel,

Here is the log of what I get from attempting to log in from start to finish.

GET /thantisforum/default.aspx - 80 - Mozilla/5.0 Windows+NT+6.1;+WOW64;+rv:9.0.1)+Gecko/20100101+Firefox/9.0.1 302 0 0 2910

GET /ThantisForum/Default.aspx g=login& 80 - Mozilla/5.0+Windows+NT+6.1;+WOW64;+rv:9.0.1)+Gecko/20100101+Firefox/9.0.1 200 0 0 102

GET /ThantisForum/resources/css/forum.css - 80 - Mozilla/5.0+ Windows+NT+6.1;+WOW64;+rv:9.0.1)+Gecko/20100101+Firefox/9.0.1 304 0 0 209

GET /ThantisForum/Themes/soclean/theme.css - 80 - Mozilla/5.0+(Windows+NT+6.1;+WOW64;+rv:9.0.1)+Gecko/20100101+Firefox/9.0.1 304 0 0 215

GET /ThantisForum/ScriptResource.axd d=FVny5IzdDDO6VVdzAppcn8XbUQ98ADwMrFAuMCe1RAkGe9R06W6X5lJYKHF32waa8cfJskp-DMOYL8SDuwxPJj5rLXK54EpNZQtUtWgr5KjWVgG04wTgoxurepRUcBfXu1hEw5aR9CqJda0DqiZRylkXMmKRfOunddfbqsE_9qZ_ZDiK0&t=fffffffffd055acd 80 - Mozilla/5.0+(Windows+NT+6.1;+WOW64;+rv:9.0.1)+Gecko/20100101+Firefox/9.0.1 200 0 0 212

GET /ThantisForum/WebResource.axd d=ezBMHs4qLKr6Pb5Mx-gd5ccjbVTMJnEkeeZS4yq2Lb8JVXD4rGAKZQyeGMaG1SjhMipYT96YMMXnii16h6klhIjLJ3Q1&t=634605330834856163 80 - Mozilla/5.0+(Windows+NT+6.1;+WOW64;+rv:9.0.1)+Gecko/20100101+Firefox/9.0.1 200 0 0 229

GET /ThantisForum/WebResource.axd d=jyd4V2LTQqtWknrNYwNY0nnoPfXkweSAnrGw1WsYk5uRjQdVrMpq3tzDqNIDylaDFcf8bbSbCVIbPEb_ZbtEowR2zvk1&t=634605330834856163 80 - Mozilla/5.0+(Windows+NT+6.1;+WOW64;+rv:9.0.1)+Gecko/20100101+Firefox/9.0.1 200 0 0 231

POST /ThantisForum/Default.aspx g=login& 80 - Mozilla/5.0+(Windows+NT+6.1;+WOW64;+rv:9.0.1)+Gecko/20100101+Firefox/9.0.1 200 0 0 45

GET /ThantisForum/ - 80 - Mozilla/5.0+(Windows+NT+6.1;+WOW64;+rv:9.0.1)+Gecko/20100101+Firefox/9.0.1 302 0 0 20

GET /ThantisForum/Default.aspx g=login& 80 - Mozilla/5.0+(Windows+NT+6.1;+WOW64;+rv:9.0.1)+Gecko/20100101+Firefox/9.0.1 200 0 0 15
squirrel
2012-01-30T03:53:45Z
Originally Posted by: Thantis 

Hey Squirrel,

Here is the log of what I get from attempting to log in from start to finish.

GET /thantisforum/default.aspx - 80 - Mozilla/5.0 Windows+NT+6.1;+WOW64;+rv:9.0.1)+Gecko/20100101+Firefox/9.0.1 302 0 0 2910

GET /ThantisForum/Default.aspx g=login& 80 - Mozilla/5.0+Windows+NT+6.1;+WOW64;+rv:9.0.1)+Gecko/20100101+Firefox/9.0.1 200 0 0 102

GET /ThantisForum/resources/css/forum.css - 80 - Mozilla/5.0+ Windows+NT+6.1;+WOW64;+rv:9.0.1)+Gecko/20100101+Firefox/9.0.1 304 0 0 209

GET /ThantisForum/Themes/soclean/theme.css - 80 - Mozilla/5.0+(Windows+NT+6.1;+WOW64;+rv:9.0.1)+Gecko/20100101+Firefox/9.0.1 304 0 0 215

GET /ThantisForum/ScriptResource.axd d=FVny5IzdDDO6VVdzAppcn8XbUQ98ADwMrFAuMCe1RAkGe9R06W6X5lJYKHF32waa8cfJskp-DMOYL8SDuwxPJj5rLXK54EpNZQtUtWgr5KjWVgG04wTgoxurepRUcBfXu1hEw5aR9CqJda0DqiZRylkXMmKRfOunddfbqsE_9qZ_ZDiK0&t=fffffffffd055acd 80 - Mozilla/5.0+(Windows+NT+6.1;+WOW64;+rv:9.0.1)+Gecko/20100101+Firefox/9.0.1 200 0 0 212

GET /ThantisForum/WebResource.axd d=ezBMHs4qLKr6Pb5Mx-gd5ccjbVTMJnEkeeZS4yq2Lb8JVXD4rGAKZQyeGMaG1SjhMipYT96YMMXnii16h6klhIjLJ3Q1&t=634605330834856163 80 - Mozilla/5.0+(Windows+NT+6.1;+WOW64;+rv:9.0.1)+Gecko/20100101+Firefox/9.0.1 200 0 0 229

GET /ThantisForum/WebResource.axd d=jyd4V2LTQqtWknrNYwNY0nnoPfXkweSAnrGw1WsYk5uRjQdVrMpq3tzDqNIDylaDFcf8bbSbCVIbPEb_ZbtEowR2zvk1&t=634605330834856163 80 - Mozilla/5.0+(Windows+NT+6.1;+WOW64;+rv:9.0.1)+Gecko/20100101+Firefox/9.0.1 200 0 0 231

POST /ThantisForum/Default.aspx g=login& 80 - Mozilla/5.0+(Windows+NT+6.1;+WOW64;+rv:9.0.1)+Gecko/20100101+Firefox/9.0.1 200 0 0 45

GET /ThantisForum/ - 80 - Mozilla/5.0+(Windows+NT+6.1;+WOW64;+rv:9.0.1)+Gecko/20100101+Firefox/9.0.1 302 0 0 20

GET /ThantisForum/Default.aspx g=login& 80 - Mozilla/5.0+(Windows+NT+6.1;+WOW64;+rv:9.0.1)+Gecko/20100101+Firefox/9.0.1 200 0 0 15



I'm seeing many successful GET statements and a couple 'redirect' statements there. I am wondering two things. One: When was the last time the 'forum' application was restarted? YAF uses cookies to track login information. I would take just a moment and make very sure you don't have a corrupted cookie on your browser that is causing issues with the login cookie for YAF. I just ran a test against my own YAF and if I block cookies for the domain, I get almost exactly the same responses in my log files that you are getting, and even after a successful login, I am re-directed as if I never logged in.

I would like to start with this to rule out that it is not a cookie issue -- then we will go from here --
If you can't find it using the forum search, try my signature link -- searches this site using Google: Google is my Friend 
Thantis
  •  Thantis
  • 81.8% (Honored)
  • YAF Commander Topic Starter
2012-01-30T04:42:37Z
The the whole deal has been restarted before-hand, just to make sure, in addition to clearing my browser
cookies. No one is currently able to login, all users suffer the same fate. Even using a new user (kinda weird that it lets me get through creating a new user) still gets the redirect to the login page.
squirrel
2012-01-30T04:49:25Z
Originally Posted by: Thantis 

The the whole deal has been restarted before-hand, just to make sure, in addition to clearing my browser
cookies. No one is currently able to login, all users suffer the same fate. Even using a new user (kinda weird that it lets me get through creating a new user) still gets the redirect to the login page.



I noticed the same scenario. I sent you a PM with more information -- I'm going to research a little inside my own database and see if I can see something that sticks out that we can try --

If you can't find it using the forum search, try my signature link -- searches this site using Google: Google is my Friend 
Thantis
  •  Thantis
  • 81.8% (Honored)
  • YAF Commander Topic Starter
2012-01-31T19:11:04Z
Well, after pulling my hair out, and much help from Dave and Squirrel, I figured out the problem. I went back over the basics and found that somehow or another, forms authentication was disabled for the application. Just goes to show you always need to check, and apparently double check, the easy basic stuff! Thanks everybody for the help!
daveburke
2012-02-01T03:09:49Z
Thantis,

Thanks for following up. We're so glad you figured out the problem!

Squirrel's idea of clearing out the cache/cookies was a good one, and I thought it would do the trick for you. However, disabled Forms Authentication in the app would certainly cause some problems. Good tip to remember.

-Dave
squirrel
2012-02-01T03:28:00Z
Originally Posted by: daveburke 

Thantis,

Thanks for following up. We're so glad you figured out the problem!

Squirrel's idea of clearing out the cache/cookies was a good one, and I thought it would do the trick for you. However, disabled Forms Authentication in the app would certainly cause some problems. Good tip to remember.

-Dave



I was really leaning to it being a cookie issue of some form -- inspecting the output from the forums only was tracking 'session' information, and nothing else, and the logs were not throwing any form of errors whatsoever. I even had a test server setup trying to break different things inside YAF to see if I could trigger the same form of error. Technically you and I were both on the forward track -- in all theory it was a permissions issue, just that the 'item' that remembers the user information so YAF could check permissions was never being created (IIS) - good show 🙂
If you can't find it using the forum search, try my signature link -- searches this site using Google: Google is my Friend 

About Us

The YAF.NET is an open source .NET forum project. YAF.NET is supported by an team of international developers who are build community by building community software.

Powered by Resharper Donate with PayPal button

Project Twitter Updates

Copyright © YetAnotherForum.NET & Ingo Herbote. All rights reserved