# Security enhancement gives 403

**URL:** <https://forum.mautic.org/t/security-enhancement-gives-403/24460>\
**Category:** Product Support\
**Created:** [June 14, 2022, 4:34pm UTC](https://forum.mautic.org/t/security-enhancement-gives-403/24460 "2022-06-14T16:34:09Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![xmontero](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mautic.org/xmontero/32/7499_2.png) [@xmontero](https://forum.mautic.org/u/xmontero)\
**Post date:** [June 14, 2022, 4:34pm UTC](https://forum.mautic.org/t/security-enhancement-gives-403/24460/1 "2022-06-14T16:34:09Z")

</div>

My Mautic version is: 4.3.1

In this issue in github [The new .htaccess now gives 403 after upgrading · Issue #11249 · mautic/mautic · GitHub](https://github.com/mautic/mautic/issues/11249) I was answered that the file causing the 403 error was a security enhancement.

It seems that more people feel like suffering it and the solution is to remove it.

I’ve seen if I revert to the previous version of the file, it works. But if someone committed this is for some reason to improve, I guess.

Question:

Why the “good file” gives a 403 and what should I do if instead of “removing those lines from the .htaccess” I want to stick to the file committed to the project? (I guess if it’s committed it means it’s better than the previous one).

---

<div class="post-metadata">

**Author:** ![silavapi](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mautic.org/silavapi/32/7424_2.png) [@silavapi](https://forum.mautic.org/u/silavapi)\
**Post date:** [June 14, 2022, 4:50pm UTC](https://forum.mautic.org/t/security-enhancement-gives-403/24460/2 "2022-06-14T16:50:30Z")

</div>

Hey there!

In the [release notes](https://github.com/mautic/mautic/releases/tag/4.2.0) we have linked to an issue which explains [what to do if you are using Mautic in a subfolder](https://github.com/mautic/mautic/issues/10913#issuecomment-1055681986), which I guess is the case for you.

Please follow those instructions, and please do review the release notes any time you are planning to update 🙂

---

<div class="post-metadata">

**Author:** ![xmontero](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mautic.org/xmontero/32/7499_2.png) [@xmontero](https://forum.mautic.org/u/xmontero)\
**Post date:** [June 14, 2022, 6:39pm UTC](https://forum.mautic.org/t/security-enhancement-gives-403/24460/3 "2022-06-14T18:39:47Z")

</div>

I’m not in a subfolder.

I’m directly in the root of a subdomain, say similar to [https://feedback.example.com](https://feedback.example.com)

The “If” directive that is giving problems to everyone works in the “URL path” side? or the “filesystem side”?

---

<div class="post-metadata">

**Author:** ![joeyk](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mautic.org/joeyk/32/11164_2.png) [@joeyk](https://forum.mautic.org/u/joeyk)\
**Post date:** [June 15, 2022, 5:57am UTC](https://forum.mautic.org/t/security-enhancement-gives-403/24460/4 "2022-06-15T05:57:24Z")

</div>

Are you using a proxy before Mautic? For example SSL is added to a container by an nginx or haproxy server?

---

<div class="post-metadata">

**Author:** ![xmontero](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mautic.org/xmontero/32/7499_2.png) [@xmontero](https://forum.mautic.org/u/xmontero)\
**Post date:** [June 15, 2022, 10:17am UTC](https://forum.mautic.org/t/security-enhancement-gives-403/24460/5 "2022-06-15T10:17:22Z")

</div>

Indeed. It is using https. I’ve not manually configured the web server, I’m using a hosting that does that. Most probably they have a reverse proxy to handle letsencrypt and let mautic alone.

---

<div class="post-metadata">

**Author:** ![joeyk](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mautic.org/joeyk/32/11164_2.png) [@joeyk](https://forum.mautic.org/u/joeyk)\
**Post date:** [June 16, 2022, 2:48am UTC](https://forum.mautic.org/t/security-enhancement-gives-403/24460/6 "2022-06-16T02:48:34Z")

</div>

You can try to break the endless ssl redirect by adding  
`$_SERVER['HTTPS'] = 'on';`  
To the first line of your index.php right after the opening tag.

---

<div class="post-metadata">

**Author:** ![jason\_nyc](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mautic.org/jason_nyc/32/12895_2.png) [@jason\_nyc](https://forum.mautic.org/u/jason_nyc)\
**Post date:** [October 3, 2024, 4:01am UTC](https://forum.mautic.org/t/security-enhancement-gives-403/24460/7 "2024-10-03T04:01:17Z")

</div>

![image](https://us1.discourse-cdn.com/flex020/uploads/mautic/original/2X/3/31c45a5fef11ffbae8fe6d6bed149f565bc21038.png)  
This worked for me. [[upgrade] 4.1.2 to 4.2.0 issue with .htaccess · Issue #10913 · mautic/mautic · GitHub](https://github.com/mautic/mautic/issues/10913#issuecomment-1084513105)
