Welcome to the LimeSurvey Community Forum

Ask the community, share ideas, and connect with other LimeSurvey users!

allowed_hosts.php never created behind F5 and warning shown at every login

More
2 weeks 6 days ago - 2 weeks 6 days ago #275126 by Winterwolf
Please help us help you and fill where relevant:
LimeSurvey version: 6.17.13+260728
Own server or LimeSurvey Cloud: Own server
Survey theme/template:
==================
Hello,

We upgraded our LimeSurvey installation from 6.10.5 to 6.17.13+260728.

The database upgrade completed successfully and the current database version is:

DBVersion = 651

Since the upgrade, all users receive the following popup message every time they log in:

"The allowed hosts file (application/config/allowed_hosts.php) could not be created because the application/config directory is not writable."

Environment:
- LimeSurvey version: 6.17.13+260728
- Database version: 651
- Database: MySQL 8.0.29 Enterprise
- PHP: 8.3.31
- Operating System: RHEL Red Hat Enterprise Linux release 9.8 (Plow)
- Two application servers behind an F5 load balancer

Verification performed:
- application/config is writable by the web server user.
- We successfully created a test file in application/config as the Apache user.
- SELinux contexts appear correct.
- The application is otherwise fully functional.
- application/config/allowed_hosts.php does not exist.
- The popup is displayed on every login.

Question:
Is allowed_hosts.php expected to be created automatically in LimeSurvey 6.17.13?

If so, under what conditions is the file generated?

Could this warning be a false positive even when application/config is writable?

We reviewed issue #20560 regarding automatic creation of allowed_hosts.php and would like to understand whether the current behavior is expected in 6.17.13.

Thank you.
Young
Last edit: 2 weeks 6 days ago by Winterwolf.

Please Log in to join the conversation.

More
2 weeks 6 days ago #275127 by jelo
Looks like the popup is triggered without any reason.
Would be interesting to see what would happen with SELinux off.

I recommend to add a note to the bugticket with your case.
If you're sure that SELinux is not stopping any filecheck the php code has a bug.

You could comment out the part with the popup from application/controllers/admin/Authentication.php
github.com/LimeSurvey/LimeSurvey/commit/...363bce6841803874a801

The allowed_hosts.php is created by LimeSurvey when an admin is logged in for a the first time.. It's not shipped with the installation.
The file hostnames are used to check for HTTP host header injection. The file should contain all the hosts via which LimeSurvey is delivered.
Public URL is always trusted.
 

The meaning of the word "stable" for users
www.limesurvey.org/forum/development/117...ord-stable-for-users
The following user(s) said Thank You: Winterwolf

Please Log in to join the conversation.

More
2 weeks 5 days ago #275140 by Winterwolf

Looks like the popup is triggered without any reason.
Would be interesting to see what would happen with SELinux off.

I recommend to add a note to the bugticket with your case.
If you're sure that SELinux is not stopping any filecheck the php code has a bug.

You could comment out the part with the popup from application/controllers/admin/Authentication.php
github.com/LimeSurvey/LimeSurvey/commit/...363bce6841803874a801

The allowed_hosts.php is created by LimeSurvey when an admin is logged in for a the first time.. It's not shipped with the installation.
The file hostnames are used to check for HTTP host header injection. The file should contain all the hosts via which LimeSurvey is delivered.
Public URL is always trusted.

 

Thank you for your suggestions.

I did some additional testing.

I was able to reproduce the behavior in PREPROD. After clearing the caches, restarting the services, and isolating one application server at a time, LimeSurvey automatically recreated allowed_hosts.php after the first administrator login with the expected hostname on each server.

In PROD, manually creating the same file with the correct production hostname immediately stopped the warning popup.

This suggests that the issue is related to the missing allowed_hosts.php file rather than actual filesystem permissions.

Thanks again for pointing me in the right direction.

Regards,
Young

Please Log in to join the conversation.

Moderators: holch, tpartner

Lime-years ahead

Online-surveys for every purse and purpose