MaximilianKohler
Well-known member
I left this on and it prevented my Let's Encrypt SSL from renewing.Bot fight mode is fine.
I left this on and it prevented my Let's Encrypt SSL from renewing.Bot fight mode is fine.
How would that work? Cloudflare proxy (and everything that goes along with it like Bot Fight Mode) only affects inbound HTTP requests. So unless Let’s Encrypt is proactively contacting an API you have setup on your server to push an SSL cert to your server, it wouldn’t affect it. If your server is going out (making the connection), it’s not going through Cloudflare.I left this on and it prevented my Let's Encrypt SSL from renewing.
Yes, Windows. I'd prefer not to see the text but like the flags. Maybe an option would be to hide it on Windows so it's flags or nothing?The operating system you use. Microsoft doesn’t allow Windows to show the actual flag.
Let's Encrypt (with HTTP-01 verification) performs an inbound HTTP request to check if the challenge can be read fromCloudflare proxy (and everything that goes along with it like Bot Fight Mode) only affects inbound HTTP requests.
./well-known/acme-challenge/...
- this request can (and if smth. is misconfigured will) be blocked by Cloudflare WAF.Ah… clearly I don’t use Let’s Encrypt.Let's Encrypt (with HTTP-01 verification) performs an inbound HTTP request to check if the challenge can read read from./well-known/acme-challenge/...
- this request can (and if smth. is misconfigured will) be blocked by Cloudflare WAF.
Yep.Its's not just Let's Encrypt, the same would apply for any CA using the ACME protocol and HTTP-01![]()
If it’s a link you are posting in a post, ya… it will go through the proxy. If its not a link in a post, then no.I have link unfurling proxied. Would this by any chance interfere with Skimlinks? I have the Skimlinks code added in page container and inspection shows it's there and live but not working. Did all the things they suggest - turn off ad blocker, clear cookies, use their test link. So it occurred to me that proxying the link unfurling might conflict with it somehow? I can still add manually generated ones, but just wondering if this is causing it to not work.
Anything within the URL BBCode within a post will be downloaded via the proxy (that’s the whole point). If you don’t want links in posts to go through the proxy, you want to disable unfurl and image proxy.Yes it's a link in a post. So does this mean the proxy will stop the Skimlinks bit kicking in? Links are already in posts, so already proxied and the semlinks js tries to convert them.
Unless the bots are logging in as users, why not just enable guest page caching or just block the bots permanently that are causing the issue?@digitalpoint
Not sure if you’re open to feature requests, but before I get someone to build this as a separate add-on, I thought I’d ask if it might be a good fit for your mod, since you already have the API permissions and framework in place.
Automatic “Under Attack” mode:
When traffic exceeds a set threshold, “Under Attack” mode is triggered automatically, and stays on until traffic drops below the limit and a cooling-off period has passed.
My sites have been getting hit pretty hard a few times a week lately, with tens of thousands of bot guests at a time. I managed to get Claude AI to build this for my vBulletin sites and it’s worked really well — but I haven’t had any luck getting an AI version to work properly for XF. So if you don’t think it fits with your add-on, I’ll just get someone to custom-build it.
Thanks!
We use essential cookies to make this site work, and optional cookies to enhance your experience.