Downloading a mobile add-on gives a 403

VERIFIED FIXED in 5.12.12

Status

defect
--
major
VERIFIED FIXED
8 years ago
3 years ago

People

(Reporter: krupa.mozbugs, Assigned: oremj)

Tracking

5.12.12

Details

(URL)

(Reporter)

Description

8 years ago
Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10.6; en-US; rv:1.9.2.13) Gecko/20101203 Firefox/3.6.13

steps to reproduce:
1. Load https://addons.allizom.org/en-US/mobile/
2. Click 'Download Now' for one of the featured mobile add-ons


observed behavior:
403 on  https://addons-cdn.allizom.org/_files/_attachments/162014/phony-2.0-fn.xpi

NOTE: happens only on preview. Next is fine

headers:

https://addons.allizom.org/mobile/downloads/file/110496/type:attachment/url_fixer-2.0.1-fx+fn.xpi?src=homepagebrowse



GET /mobile/downloads/file/110496/type:attachment/url_fixer-2.0.1-fx+fn.xpi?src=homepagebrowse HTTP/1.1

Host: addons.allizom.org

User-Agent: Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10.6; en-US; rv:1.9.2.13) Gecko/20101203 Firefox/3.6.13

Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8

Accept-Language: en,kn;q=0.7,en-us;q=0.3

Accept-Encoding: gzip,deflate

Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7

Keep-Alive: 115

Connection: keep-alive

Referer: https://addons.allizom.org/en-US/mobile/

Cookie: csrftoken=3ade3122a33771bc3ad18e3968d41b0c; amo_home_promo_seen=5; AMOappName=firefox; yes-I-read-the-dev-agreement=; AMOv3=gr27rttotbce7ev6mrgiq6drs5; sessionid=ad1edd19af3f244ff86981d62bc3da67



HTTP/1.1 302 FOUND

Server: Apache

Vary: X-Mobile

X-Backend-Server: pm-app-amo24

Cache-Control: no-cache

Content-Type: text/html; charset=utf-8

X-Target-Digest: sha256:40ac0fea9eaacedc22d40cee6c068f6f122a069b48efc38d72d233c55dbcd068

Date: Wed, 02 Mar 2011 01:52:48 GMT

Location: https://addons-cdn.allizom.org/_files/_attachments/2871/url_fixer-2.0.1-fx+fn.xpi

Keep-Alive: timeout=5, max=998

X-Content-Security-Policy-Report-Only: policy-uri /services/csp/policy

Via: Moz-Cache-pm-zlb-amo01

Connection: Keep-Alive

X-Frame-Options: DENY

Content-Length: 0

----------------------------------------------------------

https://addons-cdn.allizom.org/_files/_attachments/2871/url_fixer-2.0.1-fx+fn.xpi



GET /_files/_attachments/2871/url_fixer-2.0.1-fx+fn.xpi HTTP/1.1

Host: addons-cdn.allizom.org

User-Agent: Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10.6; en-US; rv:1.9.2.13) Gecko/20101203 Firefox/3.6.13

Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8

Accept-Language: en,kn;q=0.7,en-us;q=0.3

Accept-Encoding: gzip,deflate

Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7

Keep-Alive: 115

Connection: keep-alive

Referer: https://addons.allizom.org/en-US/mobile/



HTTP/1.1 403 Forbidden

Server: Apache

X-Backend-Server: pm-app-amo24

Content-Type: text/html; charset=iso-8859-1

Date: Wed, 02 Mar 2011 01:52:48 GMT

Keep-Alive: timeout=5, max=1000

Via: Moz-Cache-pm-zlb-amo01

Connection: Keep-Alive

X-Cache-Info: caching

Content-Length: 252
oremj: It appears that _files was broken by some of this weeks exciting rewrite wrangling. Do you know what's going on, or have diffs so we can figure it out?
Assignee: nobody → jeremy.orem+bugs
Target Milestone: 5.12.12 → 6.0.0
(Assignee)

Comment 2

8 years ago
Fixed on allizom. Let me know when I should push this to production.
Status: NEW → RESOLVED
Last Resolved: 8 years ago
Resolution: --- → FIXED
I didn't know it was broken in production.  If it is, why isn't next broken?
Target Milestone: 6.0.0 → 5.12.12
(Reporter)

Comment 4

8 years ago
(In reply to comment #3)
> I didn't know it was broken in production. 

It is not.
(Reporter)

Comment 5

8 years ago
verified @ https://addons.allizom.org/en-US/mobile/extensions/?sort=created
Status: RESOLVED → VERIFIED
(In reply to comment #4)
> (In reply to comment #3)
> > I didn't know it was broken in production. 
> 
> It is not.

oremj thinks it is, but perhaps it's on a case by case basis.  Can you cause the problem with the same add-on on each?
Product: addons.mozilla.org → addons.mozilla.org Graveyard
You need to log in before you can comment on or make changes to this bug.