# 403 Error after Mautic 3.3.5 update

**URL:** https://forum.mautic.org/t/403-error-after-mautic-3-3-5-update/22859
**Category:** Product Support
**Created:** [March 1, 2022, 11:48am UTC](https://forum.mautic.org/t/403-error-after-mautic-3-3-5-update/22859 "2022-03-01T11:48:28Z")
**Posts on this page:** 12
**Page:** 1

<div class="post-metadata">

### Author: ![abracadabra.photogra](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mautic.org/abracadabra.photogra/32/505_2.png) [@abracadabra.photogra](https://forum.mautic.org/u/abracadabra.photogra)
#### Post date: [March 1, 2022, 11:48am UTC](https://forum.mautic.org/t/403-error-after-mautic-3-3-5-update/22859/1 "2022-03-01T11:48:28Z")

</div>

Hello,  
I have this 403 error after updating Mautic to the minor version 3.3.5

How can I fix it? I cannot access Mautic anymore

---

<div class="post-metadata">

### Author: ![silavapi](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mautic.org/silavapi/32/7424_2.png) [@silavapi](https://forum.mautic.org/u/silavapi)
#### Post date: [March 1, 2022, 11:51am UTC](https://forum.mautic.org/t/403-error-after-mautic-3-3-5-update/22859/2 "2022-03-01T11:51:08Z")

</div>

Hi there,

Please check your htaccess file did not have any changes which you require for your hosting. The update made a change to this file, so if your hosting environment has some settings customised in the file, you may need to review and update accordingly.

---

<div class="post-metadata">

### Author: ![abracadabra.photogra](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mautic.org/abracadabra.photogra/32/505_2.png) [@abracadabra.photogra](https://forum.mautic.org/u/abracadabra.photogra)
#### Post date: [March 1, 2022, 3:06pm UTC](https://forum.mautic.org/t/403-error-after-mautic-3-3-5-update/22859/3 "2022-03-01T15:06:35Z")

</div>

Hi,  
thanks for your reply.

this is my htaccess, I don’t think there is any code of my hosting:

```auto
# Use the front controller as index file. It serves as a fallback solution when
# every other rewrite/redirect fails (e.g. in an aliased environment without
# mod_rewrite). Additionally, this reduces the matching process for the
# start page (path "/") because otherwise Apache will apply the rewriting rules
# to each configured DirectoryIndex file (e.g. index.php, index.html, index.pl).
#DirectoryIndex index.php

<IfModule mod_rewrite.c>
    RewriteEngine On

    # Set Authorization header for OAuth1a for when php is running under fcgi
    RewriteCond %{HTTP:Authorization} .+
    RewriteRule .* - [E=HTTP_AUTHORIZATION:%{HTTP:Authorization}]

    # Determine the RewriteBase automatically and set it as environment variable.
    # If you are using Apache aliases to do mass virtual hosting or installed the
    # project in a subdirectory, the base path will be prepended to allow proper
    # resolution of the app.php file and to redirect to the correct URI. It will
    # work in environments without path prefix as well, providing a safe, one-size
    # fits all solution. But as you do not need it in this case, you can comment
    # the following 2 lines to eliminate the overhead.
    RewriteCond %{REQUEST_URI}::$1 ^(/.+)/(.*)::\2$
    RewriteRule ^(.*) - [E=BASE:%1]

    # Redirect to URI without front controller to prevent duplicate content
    # (with and without `/app.php`). Only do this redirect on the initial
    # rewrite by Apache and not on subsequent cycles. Otherwise we would get an
    # endless redirect loop (request -> rewrite to front controller ->
    # redirect -> request -> ...).
    # So in case you get a "too many redirects" error or you always get redirected
    # to the start page because your Apache does not expose the REDIRECT_STATUS
    # environment variable, you have 2 choices:
    # - disable this feature by commenting the following 2 lines or
    # - use Apache >= 2.3.9 and replace all L flags by END flags and remove the
    # following RewriteCond (best solution)
    RewriteCond %{ENV:REDIRECT_STATUS} ^$
    RewriteRule ^index\.php(/(.*)|$) %{ENV:BASE}/$2 [R=301,L]

    # If the requested filename exists, simply serve it.
    # We only want to let Apache serve files and not directories.
    RewriteCond %{REQUEST_FILENAME} -f
    RewriteRule .? - [L]

    # Rewrite all other queries to the front controller.
    RewriteRule .? %{ENV:BASE}/index.php [L]
</IfModule>

<IfModule !mod_rewrite.c>
    <IfModule mod_alias.c>
        # When mod_rewrite is not available, we instruct a temporary redirect of
        # the start page to the front controller explicitly so that the website
        # and the generated links can still be used.
        RedirectMatch 302 ^(?!/(index\.php|index_dev\.php|app|addons|plugins|media|upgrade))(/(.*))$ /index.php$2
        # RedirectTemp cannot be used instead
    </IfModule>
</IfModule>

<IfModule mod_php5.c>
    # @link https://github.com/mautic/mautic/issues/1504
    php_value always_populate_raw_post_data -1
</IfModule>

<IfModule mod_deflate.c>
    <IfModule mod_filter.c>
        AddOutputFilterByType DEFLATE application/javascript
        AddOutputFilterByType DEFLATE application/rss+xml
        AddOutputFilterByType DEFLATE application/vnd.ms-fontobject
        AddOutputFilterByType DEFLATE application/x-font
        AddOutputFilterByType DEFLATE application/x-font-opentype
        AddOutputFilterByType DEFLATE application/x-font-otf
        AddOutputFilterByType DEFLATE application/x-font-truetype
        AddOutputFilterByType DEFLATE application/x-font-ttf
        AddOutputFilterByType DEFLATE application/x-javascript
        AddOutputFilterByType DEFLATE font/opentype
        AddOutputFilterByType DEFLATE font/otf
        AddOutputFilterByType DEFLATE font/ttf
        AddOutputFilterByType DEFLATE image/svg+xml
        AddOutputFilterByType DEFLATE image/x-icon
        AddOutputFilterByType DEFLATE text/css
        AddOutputFilterByType DEFLATE text/javascript
        # Do not enable compression for file types that could contain secrets
        #AddOutputFilterByType DEFLATE text/html
        #AddOutputFilterByType DEFLATE text/plain
        #AddOutputFilterByType DEFLATE text/xml
        #AddOutputFilterByType DEFLATE application/xhtml+xml
        #AddOutputFilterByType DEFLATE application/xml
        #AddOutputFilterByType DEFLATE application/json
        <IfModule mod_setenvif.c>
            <IfModule mod_header.c>
                # Remove browser bugs (only needed for really old browsers)
                BrowserMatch ^Mozilla/4 gzip-only-text/html
                BrowserMatch ^Mozilla/4\.0[678] no-gzip
                BrowserMatch \bMSIE !no-gzip !gzip-only-text/html
                Header append Vary User-Agent
            </IfModule>
        </IfModule>
    </IfModule>
</IfModule>

# Apache 2.4+
<IfModule authz_core_module>
    # Deny access via HTTP requests to all PHP files.
    <FilesMatch "\.php$">
        Require all denied
    </FilesMatch>

    # Deny access via HTTP requests to composer files.
    <FilesMatch "^(composer\.json|composer\.lock)$">
        Require all denied
    </FilesMatch>

    # Except those allowed below.
    <If "%{REQUEST_URI} =~ m#^/(index|index_dev|upgrade/upgrade)\.php#">
        Require all granted
    </If>
</IfModule>

# Fallback for Apache < 2.4
<IfModule !authz_core_module>
    # Deny access via HTTP requests to all PHP files.
    <FilesMatch "\.php$">
        Order deny,allow
        Deny from all
    </FilesMatch>

    # Deny access via HTTP requests to composer files
    <FilesMatch "^(composer\.json|composer\.lock)$">
        Order deny,allow
        Deny from all
    </FilesMatch>

    # Except those allowed below.
    <If "%{REQUEST_URI} =~ m#^/(index|index_dev|upgrade/upgrade)\.php#">
        Order allow,deny
        Allow from all
    </If>
</IfModule>

```

---

<div class="post-metadata">

### Author: ![raramuridesign](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mautic.org/raramuridesign/32/13226_2.png) [@raramuridesign](https://forum.mautic.org/u/raramuridesign)
#### Post date: [March 1, 2022, 4:30pm UTC](https://forum.mautic.org/t/403-error-after-mautic-3-3-5-update/22859/4 "2022-03-01T16:30:26Z")

</div>

@abracadabra.photogra  
In the htaccess try and disable these lines

```auto
    <FilesMatch "\.php$">
        Require all denied
    </FilesMatch>

```

Let us know if this helps.  
M.

---

<div class="post-metadata">

### Author: ![silavapi](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mautic.org/silavapi/32/7424_2.png) [@silavapi](https://forum.mautic.org/u/silavapi)
#### Post date: [March 1, 2022, 4:32pm UTC](https://forum.mautic.org/t/403-error-after-mautic-3-3-5-update/22859/5 "2022-03-01T16:32:01Z")

</div>

Linking to GitHub issue:

> <https://github.com/mautic/mautic/issues/10913>
>
> \### Mautic Version
> 
> 4.2.x series
> 
> \### PHP version
> 
> 7.4.27
> 
> \### What brow…sers are you seeing the problem on?
> 
> Firefox, Chrome
> 
> \### What happened?
> 
> After performing an upgrade, the site reports an error 403, forbidden.
> 
> We upgrade via command line and clear cache and clean permissions as part of the process.
> 
> This maybe server specific, but this line in the HTACCESS
> 
> https://github.com/mautic/mautic/blob/4.2.0/.htaccess
> 
> \`\`\`
> \# Apache 2.4+
> \<IfModule authz\_core\_module\>
> # Deny access via HTTP requests to all PHP files.
> \<FilesMatch "\\.php$"\>
> Require all denied
> \</FilesMatch\>
> \`\`\`
> 
> Causes the issue, by commenting out
> 
> \`\`\`
> \<FilesMatch "\\.php$"\>
> Require all denied
> \</FilesMatch\>
> \`\`\`
> 
> The site loads again.
> 
> Prior to this verison 4.1.2 Worked with this in the htaccess file.
> 
> \### How can we reproduce this issue?
> 
> Server
> Ubunto 18.04.4 LTS
> Server API | FPM/FastCGI
> MariaDB
> 1:10.2.43+maria~bionic
> Apache
> 2.4.52-1+ubuntu18.04+1
> NGiNX
> 1.19.9-1+ubuntu18.04+1
> 
> Not sure if this is important, but we have mautic in a subfolder off the domain
> eg: domain.com/mautic/
> 
> \### Relevant log output
> 
> \`\`\`shell
> n/a
> \`\`\`
> 
> 
> \### Code of Conduct
> 
> \- \[X\] I confirm that I have read and agree to follow this project's Code of Conduct

---

<div class="post-metadata">

### Author: ![abracadabra.photogra](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mautic.org/abracadabra.photogra/32/505_2.png) [@abracadabra.photogra](https://forum.mautic.org/u/abracadabra.photogra)
#### Post date: [March 3, 2022, 8:00am UTC](https://forum.mautic.org/t/403-error-after-mautic-3-3-5-update/22859/6 "2022-03-03T08:00:39Z")

</div>

yes, it seems it is working now, thanks!

---

<div class="post-metadata">

### Author: ![mauticisright](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mautic.org/mauticisright/32/7094_2.png) [@mauticisright](https://forum.mautic.org/u/mauticisright)
#### Post date: [March 27, 2022, 3:20pm UTC](https://forum.mautic.org/t/403-error-after-mautic-3-3-5-update/22859/7 "2022-03-27T15:20:59Z")

</div>

@raramuridesign - it helped, it worked. Thank you very much. 🤗

---

<div class="post-metadata">

### Author: ![crozilla](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mautic.org/crozilla/32/2054_2.png) [@crozilla](https://forum.mautic.org/u/crozilla)
#### Post date: [May 19, 2022, 2:00pm UTC](https://forum.mautic.org/t/403-error-after-mautic-3-3-5-update/22859/8 "2022-05-19T14:00:17Z")

</div>

That fixed it.

---

<div class="post-metadata">

### Author: ![tke852](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mautic.org/tke852/32/2404_2.png) [@tke852](https://forum.mautic.org/u/tke852)
#### Post date: [June 20, 2022, 2:21pm UTC](https://forum.mautic.org/t/403-error-after-mautic-3-3-5-update/22859/9 "2022-06-20T14:21:07Z")

</div>

@raramuridesign, Thank you so much. I thought I had read every single idea on the internet to fix this and you finally gave me the right advice. Thank you so much for sharing!

---

<div class="post-metadata">

### Author: ![mauticuser1245](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mautic.org/mauticuser1245/32/433_2.png) [@mauticuser1245](https://forum.mautic.org/u/mauticuser1245)
#### Post date: [November 15, 2022, 1:27pm UTC](https://forum.mautic.org/t/403-error-after-mautic-3-3-5-update/22859/10 "2022-11-15T13:27:03Z")

</div>

Hello,

I installed the mautic with **Softaculous Apps Installer** (clean subfolder install)

I had 403 error when i tried to activate the API. I tried everything written here + forum without success.

I fixed it by simply disabling “ **ModSecurity** ” on Cpanel which solve the issue directly.

I put back the original htaccess, even i was in “subfolder” configuration.

Here is my actual HTACCESS :

> **[\# Use the front controller as index file. It serves as a fallback solution...](https://pastebin.com/mrRxr1wA)**
>
> Pastebin.com is the number one paste tool since 2002. Pastebin is a website where you can store text online for a set period of time.

I hope this post will help people.

---

<div class="post-metadata">

### Author: ![patrick1](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mautic.org/patrick1/32/9280_2.png) [@patrick1](https://forum.mautic.org/u/patrick1)
#### Post date: [February 11, 2023, 11:37am UTC](https://forum.mautic.org/t/403-error-after-mautic-3-3-5-update/22859/11 "2023-02-11T11:37:49Z")

</div>

I tried the same and it’s still not working, anyone has other idea please ?

---

<div class="post-metadata">

### Author: ![dirk\_s](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mautic.org/dirk_s/32/748_2.png) [@dirk\_s](https://forum.mautic.org/u/dirk_s)
#### Post date: [April 15, 2023, 9:25pm UTC](https://forum.mautic.org/t/403-error-after-mautic-3-3-5-update/22859/12 "2023-04-15T21:25:44Z")

</div>

… is your Mautic installed in a sub directory? Then you need to edit your .htaccess.
