Thanks so much for your efforts here. Here is what I have discovered and hope this may help you as well.
1. It is indeed 6G WAF blocking bad request. The data center tech could not find an easy way to let this specific page request through the firewall. But if I disable -bad-request monitoring for the entire site, the verification link works!
2. Now, before I discovered this, I went and removed the verification link from the first email as I have “Subscribe” checked automatically. My next question is, if users who not verify, although they seem to be getting notification emails as others comment on the post, do they stay being subscribed until they remove themselves. I think I read somewhere that users who do not verify will be automatically unsubscribed after a certain length of time. If this is the case, I am forced to put the verification link back in and just disable all -bag-request within 6G WAF.
I can’t send over a real domain but here is the actual 6G error: [DATE-TIME] [“:bad_request_7:”] IPADDRESS https://www.domain.com “GET /comment-subscriptions/?LONGSTRINGUSEDTOVERIFYLINK HTTP/2.0” 403 “-” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.106 Safari/537.36”
Hope that makes sense.
By the way, for the “Double Check Message”. What is the second line that includes the verification link that comes after this? I forgot to save that portion.
You have requested to be notified every time a new comment is added to:
[post_permalink]
-
This reply was modified 4 years, 9 months ago by
mealto.