I'm the administrator for a Joomla running Admin Tools. I'm trying to diagnose a WAF block that I can't trace through any of the normal tools, and I'm hoping you can point me to where else this might be logged or configured.
Symptoms:
- A specific user (not me) is blocked from accessing the backend (/administrator) and shown our custom WAF message (set under Configure WAF -> Customisation -> Custom message).
- She can access the site frontend without any issue - only the backend triggers the block.
- The block is reproducible: with the Admin Tools system plugin enabled, she is blocked every time (confirmed with a hard refresh and cleared browser cache). With the plugin disabled (renamed provider.php in plugins/system/admintools/services/ to disable it), she can log into the backend without issue.
- Her IP address is entered in the IP Allow list (Site IP Allow List) and is NOT present in the IP Disallow List, WAF Deny List, ipblock table, or ipautoban table.
- I checked the XXX_admintools_log table directly in the database (with "Log blocked requests" set to Yes) and there is no entry at all for her IP, before or after her most recent blocked attempt.
- I enabled "Keep a debug log file" under Logging & Reporting, had her retry, and no new debug log file was created anywhere under /administrator/logs or /tmp, and no file anywhere on the site was modified in the 2 hours around her attempt.
- I also checked admintools_wafblacklists, admintools_ipallow, admintools_adminiplist, and admintools_filescache without finding anything relevant.
Given that the block clearly originates from the Admin Tools plugin (disabling it resolves the issue immediately) but produces no log, debug file, or database record anywhere I can find, could you help me identify the problem.
Happy to provide screenshots, config exports, or further details as needed.
Thank you for your help.
David Hillock
Website Chair, Toronto Camera Club
torontocameraclub.com