# 403 Forbidden after fresh install with Softaculous

**URL:** <https://forum.mautic.org/t/403-forbidden-after-fresh-install-with-softaculous/23891>\
**Category:** Product Support\
**Created:** [April 26, 2022, 1:42pm UTC](https://forum.mautic.org/t/403-forbidden-after-fresh-install-with-softaculous/23891 "2022-04-26T13:42:52Z")\
**Posts on this page:** 19\
**Page:** 1

<div class="post-metadata">

**Author:** ![gmiotke](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mautic.org/gmiotke/32/7443_2.png) [@gmiotke](https://forum.mautic.org/u/gmiotke)\
**Post date:** [April 26, 2022, 1:42pm UTC](https://forum.mautic.org/t/403-forbidden-after-fresh-install-with-softaculous/23891/1 "2022-04-26T13:42:52Z")

</div>

**Your software**  
My Mautic version is: 4.2.1  
My PHP version is: 7.4  
My Database type and version is:

**Your problem**  
I am trying to install for the first time using softaculous. It indicates that the installis a success however when I try to log in I get a 403 access forbidden

These errors are showing in the log:

Steps I have tried to fix the problem: uninstalled and then reinstalled

---

<div class="post-metadata">

**Author:** ![joeyk](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mautic.org/joeyk/32/11164_2.png) [@joeyk](https://forum.mautic.org/u/joeyk)\
**Post date:** [April 26, 2022, 3:35pm UTC](https://forum.mautic.org/t/403-forbidden-after-fresh-install-with-softaculous/23891/2 "2022-04-26T15:35:35Z")

</div>

Hi,

1. can you please confirm, that the login page works and the issue is only after login?
2. Do you have SSL installed?

---

<div class="post-metadata">

**Author:** ![gmiotke](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mautic.org/gmiotke/32/7443_2.png) [@gmiotke](https://forum.mautic.org/u/gmiotke)\
**Post date:** [April 26, 2022, 3:57pm UTC](https://forum.mautic.org/t/403-forbidden-after-fresh-install-with-softaculous/23891/3 "2022-04-26T15:57:58Z")

</div>

The log in does not work. When I navigate to the login url I immediately get a 403

---

<div class="post-metadata">

**Author:** ![silavapi](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mautic.org/silavapi/32/7424_2.png) [@silavapi](https://forum.mautic.org/u/silavapi)\
**Post date:** [April 26, 2022, 4:02pm UTC](https://forum.mautic.org/t/403-forbidden-after-fresh-install-with-softaculous/23891/4 "2022-04-26T16:02:48Z")

</div>

Also worth checking if you’re using Mautic in a sub-folder. If you are, I expect you’ll need to update your htaccess file to reflect that.

---

<div class="post-metadata">

**Author:** ![joeyk](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mautic.org/joeyk/32/11164_2.png) [@joeyk](https://forum.mautic.org/u/joeyk)\
**Post date:** [April 26, 2022, 4:03pm UTC](https://forum.mautic.org/t/403-forbidden-after-fresh-install-with-softaculous/23891/5 "2022-04-26T16:03:48Z")

</div>

Do you have SSL installed?

---

<div class="post-metadata">

**Author:** ![gmiotke](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mautic.org/gmiotke/32/7443_2.png) [@gmiotke](https://forum.mautic.org/u/gmiotke)\
**Post date:** [April 26, 2022, 5:01pm UTC](https://forum.mautic.org/t/403-forbidden-after-fresh-install-with-softaculous/23891/6 "2022-04-26T17:01:20Z")

</div>

Yes. It is just the free SSL with namehero hosting

---

<div class="post-metadata">

**Author:** ![gmiotke](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mautic.org/gmiotke/32/7443_2.png) [@gmiotke](https://forum.mautic.org/u/gmiotke)\
**Post date:** [April 26, 2022, 5:02pm UTC](https://forum.mautic.org/t/403-forbidden-after-fresh-install-with-softaculous/23891/7 "2022-04-26T17:02:01Z")

</div>

i also tried to install in a subdomain as opposed to a folder buthad same results

---

<div class="post-metadata">

**Author:** ![joeyk](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mautic.org/joeyk/32/11164_2.png) [@joeyk](https://forum.mautic.org/u/joeyk)\
**Post date:** [April 26, 2022, 7:01pm UTC](https://forum.mautic.org/t/403-forbidden-after-fresh-install-with-softaculous/23891/8 "2022-04-26T19:01:56Z")

</div>

Seems like a htaccess error.  
Can you see a “hidden” .htaccess file in the main dir?

---

<div class="post-metadata">

**Author:** ![gmiotke](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mautic.org/gmiotke/32/7443_2.png) [@gmiotke](https://forum.mautic.org/u/gmiotke)\
**Post date:** [April 26, 2022, 9:13pm UTC](https://forum.mautic.org/t/403-forbidden-after-fresh-install-with-softaculous/23891/9 "2022-04-26T21:13:51Z")

</div>

Yes there is a hidden .htaccess file in th emain

---

<div class="post-metadata">

**Author:** ![gmiotke](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mautic.org/gmiotke/32/7443_2.png) [@gmiotke](https://forum.mautic.org/u/gmiotke)\
**Post date:** [April 26, 2022, 9:15pm UTC](https://forum.mautic.org/t/403-forbidden-after-fresh-install-with-softaculous/23891/10 "2022-04-26T21:15:44Z")

</div>

I renamed it to \_old but the 403 is still being shown

---

<div class="post-metadata">

**Author:** ![joeyk](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mautic.org/joeyk/32/11164_2.png) [@joeyk](https://forum.mautic.org/u/joeyk)\
**Post date:** [April 26, 2022, 9:31pm UTC](https://forum.mautic.org/t/403-forbidden-after-fresh-install-with-softaculous/23891/11 "2022-04-26T21:31:22Z")

</div>

Can you plz read this? Does the workarounds mentioned here help?

> <https://github.com/mautic/mautic/issues/10913>
>
> \### Mautic Version
> 
> 4.2.x series
> 
> \### PHP version
> 
> 7.4.27
> 
> \### What brow…sers are you seeing the problem on?
> 
> Firefox, Chrome
> 
> \### What happened?
> 
> After performing an upgrade, the site reports an error 403, forbidden.
> 
> We upgrade via command line and clear cache and clean permissions as part of the process.
> 
> This maybe server specific, but this line in the HTACCESS
> 
> https://github.com/mautic/mautic/blob/4.2.0/.htaccess
> 
> \`\`\`
> \# Apache 2.4+
> \<IfModule authz\_core\_module\>
> # Deny access via HTTP requests to all PHP files.
> \<FilesMatch "\\.php$"\>
> Require all denied
> \</FilesMatch\>
> \`\`\`
> 
> Causes the issue, by commenting out
> 
> \`\`\`
> \<FilesMatch "\\.php$"\>
> Require all denied
> \</FilesMatch\>
> \`\`\`
> 
> The site loads again.
> 
> Prior to this verison 4.1.2 Worked with this in the htaccess file.
> 
> \### How can we reproduce this issue?
> 
> Server
> Ubunto 18.04.4 LTS
> Server API | FPM/FastCGI
> MariaDB
> 1:10.2.43+maria~bionic
> Apache
> 2.4.52-1+ubuntu18.04+1
> NGiNX
> 1.19.9-1+ubuntu18.04+1
> 
> Not sure if this is important, but we have mautic in a subfolder off the domain
> eg: domain.com/mautic/
> 
> \### Relevant log output
> 
> \`\`\`shell
> n/a
> \`\`\`
> 
> 
> \### Code of Conduct
> 
> \- \[X\] I confirm that I have read and agree to follow this project's Code of Conduct

---

<div class="post-metadata">

**Author:** ![gmiotke](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mautic.org/gmiotke/32/7443_2.png) [@gmiotke](https://forum.mautic.org/u/gmiotke)\
**Post date:** [April 26, 2022, 10:07pm UTC](https://forum.mautic.org/t/403-forbidden-after-fresh-install-with-softaculous/23891/12 "2022-04-26T22:07:31Z")

</div>

There is no line that matches this in my htaccess file. Additionally I renamed the entire htaccess file so that it was not being called at all and the problem persisted. This leads me to believe that it is not an htaccess issue right?

---

<div class="post-metadata">

**Author:** ![nikita](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mautic.org/nikita/32/6488_2.png) [@nikita](https://forum.mautic.org/u/nikita)\
**Post date:** [April 27, 2022, 7:30am UTC](https://forum.mautic.org/t/403-forbidden-after-fresh-install-with-softaculous/23891/13 "2022-04-27T07:30:49Z")

</div>

Hi @gmiotke

I am from Softaculous team.

Apologies for the inconvenience caused to you.

You can open a support ticket with us and we shall look into it.  
[https://softaculous.deskuss.com/](https://softaculous.deskuss.com/)

PS: If you can provide your server details in the ticket (it is completely secure and the details shall be wiped off once the ticket is closed). As it would be faster to check and resolve the issue on your server.

---

<div class="post-metadata">

**Author:** ![Shaz3e](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mautic.org/shaz3e/32/236_2.png) [@Shaz3e](https://forum.mautic.org/u/Shaz3e)\
**Post date:** [September 13, 2022, 3:52pm UTC](https://forum.mautic.org/t/403-forbidden-after-fresh-install-with-softaculous/23891/14 "2022-09-13T15:52:32Z")

</div>

I have just removed comment the following lines in .htaccess and everything is working

```auto
# Apache 2.4+
<IfModule authz_core_module>
    # Deny access via HTTP requests to all PHP files.
    <FilesMatch "\.php$">
        # Comment the following line to avoid 403 error
        #Require all denied
    </FilesMatch>

    # Deny access via HTTP requests to composer files.
    <FilesMatch "^(composer\.json|composer\.lock)$">
        Require all denied
    </FilesMatch>

    # Except those allowed below.
    <If "%{REQUEST_URI} =~ m#^/emails/(index|index_dev|upgrade/upgrade)\.php#">
        Require all granted
    </If>
</IfModule>

```

---

<div class="post-metadata">

**Author:** ![karlisc](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mautic.org/karlisc/32/13150_2.png) [@karlisc](https://forum.mautic.org/u/karlisc)\
**Post date:** [April 15, 2023, 5:16pm UTC](https://forum.mautic.org/t/403-forbidden-after-fresh-install-with-softaculous/23891/15 "2023-04-15T17:16:27Z")

</div>

Thanks, this worked fine also for me in a similar situation with Mautic 4.4.7. However, wouldn’t this create a security concern, if http access is allowed also to php files to which it should not have been?  
Best, …

---

<div class="post-metadata">

**Author:** ![gandolfslayer](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mautic.org/gandolfslayer/32/12434_2.png) [@gandolfslayer](https://forum.mautic.org/u/gandolfslayer)\
**Post date:** [August 4, 2024, 3:14am UTC](https://forum.mautic.org/t/403-forbidden-after-fresh-install-with-softaculous/23891/16 "2024-08-04T03:14:31Z")

</div>

I too have a fresh install using softaculous. I saw on one of the forums to comment out

# Comment the following line to avoid 403 error

```
    #Require all denied

```

so i did that now i am receiving the error code  
The “app/bundles/CoreBundle/Resources/views/Offline” directory does not exist (“/opt/cpanel/ea-php81/root/usr/bin/app/bundles/CoreBundle/Resources/views/Offline”).

---

<div class="post-metadata">

**Author:** ![rcarabelli](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mautic.org/rcarabelli/32/6807_2.png) [@rcarabelli](https://forum.mautic.org/u/rcarabelli)\
**Post date:** [August 4, 2024, 3:51am UTC](https://forum.mautic.org/t/403-forbidden-after-fresh-install-with-softaculous/23891/17 "2024-08-04T03:51:44Z")

</div>

Try increasing your PHP memory to 512 or even 1024  
Also this is the htaccess that I use in difficult installations:

> ```auto
> <IfModule mod_rewrite.c>
> RewriteEngine On
> 
> # Redirigir a HTTPS
> RewriteCond %{HTTPS} !=on
> RewriteRule ^ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]
> 
> # Establecer encabezado de autorización para OAuth2 cuando PHP se ejecuta bajo fcgi
> RewriteCond %{HTTP:Authorization} .+
> RewriteRule .* - [E=HTTP_AUTHORIZATION:%{HTTP:Authorization}]
> 
> # Redirigir a URI sin front controller para prevenir contenido duplicado
> RewriteCond %{ENV:REDIRECT_STATUS} ^$
> RewriteRule ^index\.php(/(.*)|$) /$2 [R=301,L]
> 
> # Si el archivo solicitado existe, simplemente servirlo
> RewriteCond %{REQUEST_FILENAME} -f
> RewriteRule .? - [L]
> 
> # Reescribir todas las demás consultas al front controller
> RewriteRule .? /index.php [L]
> 
> # Proteger el directorio de logs
> RewriteRule ^app/logs/ - [F,L]
> 
> # Proteger el directorio de configuraciones
> RewriteRule ^app/config/ - [F,L]
> 
> # Proteger el directorio de media
> RewriteRule ^media/ - [F,L]
> </IfModule>
> 
> <IfModule mod_php5.c>
> # Ajuste para php_value siempre_populate_raw_post_data
> php_value always_populate_raw_post_data -1
> </IfModule>
> 
> <IfModule mod_deflate.c>
> AddOutputFilterByType DEFLATE application/javascript application/rss+xml application/x-font-ttf font/ttf text/css text/javascript
> </IfModule>
> 
> # Bloquear acceso a archivos sensibles
> <FilesMatch "^(composer\.json|composer\.lock|\.env|\.htaccess|\.htpasswd|web\.config|app/config/parameters\.yml)$">
> Order deny,allow
> Deny from all
> </FilesMatch>
> 
> # Denegar acceso directo a archivos PHP (excepto index.php y upgrade.php)
> <FilesMatch "\.php$">
> <If "%{REQUEST_URI} =~ m#^/index\.php#">
> Require all granted
> </If>
> <If "%{REQUEST_URI} =~ m#^/upgrade/upgrade\.php#">
> Require all granted
> </If>
> Require all denied
> </FilesMatch>
> 
> # Impedir la navegación de directorios
> Options -Indexes
> 
> # Headers de seguridad
> <IfModule mod_headers.c>
> Header set X-Content-Type-Options "nosniff"
> Header set X-XSS-Protection "1; mode=block"
> Header set X-Frame-Options "DENY"
> Header always set Referrer-Policy "no-referrer-when-downgrade"
> Header always set Content-Security-Policy "default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval'; style-src 'self' 'unsafe-inline'; img-src 'self' data:; font-src 'self'; frame-ancestors 'none';"
> # Protección adicional contra clickjacking
> Header always append X-Frame-Options SAMEORIGIN
> </IfModule>
> 
> # Protección adicional para el archivo de actualización
> <Files "upgrade.php">
> Order deny,allow
> Deny from all
> Allow from 192.168.1.100
> </Files>
> 
> # Bloquear User Agents maliciosos
> SetEnvIfNoCase User-Agent "^Mozilla/4\.0$" bad_user
> SetEnvIfNoCase User-Agent "^Java.*" bad_user
> SetEnvIfNoCase User-Agent "^Microsoft URL Control" bad_user
> SetEnvIfNoCase User-Agent "^User-Agent.*" bad_user
> <Limit GET POST>
> Order Allow,Deny
> Allow from all
> Deny from env=bad_user
> </Limit>
> 
> # Limitar métodos HTTP
> <LimitExcept GET POST>
> Order deny,allow
> Deny from all
> </LimitExcept>
> 
> # Protección contra hotlinking
> RewriteEngine On
> RewriteCond %{HTTP_REFERER} !^$
> RewriteCond %{HTTP_REFERER} !^https://(www\.)?yourdomain\.com/ [NC]
> RewriteRule \.(jpg|jpeg|png|gif)$ - [F,NC]
> 
> <IfModule mod_headers.c>
> Header set Access-Control-Allow-Origin "*"
> Header set Access-Control-Allow-Methods "GET, POST, OPTIONS, DELETE, PUT"
> Header set Access-Control-Allow-Headers "Content-Type, Authorization, X-Requested-With"
> Header set Access-Control-Allow-Credentials "true"
> </IfModule>
> 
> ```

---

<div class="post-metadata">

**Author:** ![gandolfslayer](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mautic.org/gandolfslayer/32/12434_2.png) [@gandolfslayer](https://forum.mautic.org/u/gandolfslayer)\
**Post date:** [August 4, 2024, 4:09am UTC](https://forum.mautic.org/t/403-forbidden-after-fresh-install-with-softaculous/23891/18 "2024-08-04T04:09:55Z")

</div>

> [@rcarabelli](#):
>
> `192.168.1.100`

That just turned it back to a 403 forbidden page

---

<div class="post-metadata">

**Author:** ![rcarabelli](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mautic.org/rcarabelli/32/6807_2.png) [@rcarabelli](https://forum.mautic.org/u/rcarabelli)\
**Post date:** [August 4, 2024, 4:24am UTC](https://forum.mautic.org/t/403-forbidden-after-fresh-install-with-softaculous/23891/19 "2024-08-04T04:24:09Z")

</div>

Also increased PHP memory?

Try this htaccess

```auto
> <IfModule mod_rewrite.c>
> RewriteEngine On
> RewriteBase /
> 
> # Redirect all requests to index.php
> RewriteCond %{REQUEST_FILENAME} !-f
> RewriteCond %{REQUEST_FILENAME} !-d
> RewriteRule ^ index.php [L]
> 
> # Allow access to all files
> <FilesMatch ".*">
> Order allow,deny
> Allow from all
> </FilesMatch>
> </IfModule>
> 
> # Disable directory browsing
> Options -Indexes
> 
> # Disable server signature
> ServerSignature Off
> 
> # Add default charset
> AddDefaultCharset UTF-8
> 
> # Enable CORS for Mautic tracking
> <IfModule mod_headers.c>
> Header set Access-Control-Allow-Origin "*"
> Header set Access-Control-Allow-Methods "GET, POST, OPTIONS"
> Header set Access-Control-Allow-Headers "Content-Type, Authorization"
> </IfModule>
> 
> # Allow access to Mautic tracking files
> <Files "mtc.js">
> Order allow,deny
> Allow from all
> </Files>
> <Files "index.php">
> Order allow,deny
> Allow from all
> </Files>

```

Is just a non production version, to see if there is another issue
