Wordfence blocks wp-graphql API calls when using JWT auth
-
We are currently facing issues using WordPress in an headless installation using wp-graphql and wp-graphql-jwt-authentication (see versions below).
Calls to the API including a JWT auth header return a correct response body but with a status code of 403 (which seems like an odd combination).
What we tried:- Omitting the JWT header: does work ??
- Disabling the only fw rule we found that is related to the wp-graphql plugin: does not work ??
- Disabling the firewall in the plugin settings: does not work ??
- Disabling the Wordfence plugin: does work ??
Since omiting the token or diabling Wordfence fixes the issue it might be a false flag from WF?
Do you have any hint on how to fix this?
Plugins:
- Wordfence 7.8.2 free
- WPGraphQL 1.13.7
- WPGraphQL JWT Authentication 0.6.0
Viewing 6 replies - 1 through 6 (of 6 total)
Viewing 6 replies - 1 through 6 (of 6 total)
- The topic ‘Wordfence blocks wp-graphql API calls when using JWT auth’ is closed to new replies.