Support

Admin Tools

#43342 403 remains even after re naming .htaccess and .htaccessadmintools

Posted in ‘Admin Tools for Joomla!’
This is a public ticket

Everybody will be able to see its contents. Do not include usernames, passwords or any other sensitive information.

Environment Information

Joomla! version
n/a
PHP version
n/a
Admin Tools version
n/a

Latest post by nicholas on Tuesday, 29 September 2026 00:09 CDT

Wouter Turkenburg

Please look at the bottom of this page (under Support Policy Summary) for our support policy summary, containing important information regarding our working hours and our support policy. Thank you!

Hello, I am getting a 403 generic Joomla warning as I log in as administrator. My host tells me that the .htaccess in my file manager, is misconfigured and has many mistakes. If I rename it to .htaccess_bak the 403 remains. If i rename the .htacccess.admintools also to _bak and put in a clean Joomla .htaccess, the 403 remains. What is blocking the superadministrator log in? No, there is no .htaccess under administrator in the publ_html. Best regards, Walter

System Task
system
The ticket information has been edited by Wouter Turkenburg (Wouter Turkenburg).

nicholas
Akeeba Staff
Manager

The .htaccess file in your site's root is generated by Admin Tools. It is not "misconfigured", and does not have "many mistakes". Moreover, the fact that nothing changed after removing it proves beyond any reasonable doubt that it had never anything to do with your issue.

I don't have enough information to tell you what's wrong right now, but I suspect that a third party plugin may be the root cause. Edit your configuration.php file in your site's root and find the $debug and $error reporting lines. Change them so they read:

public $debug = true;
public $error_reporting = 'maximum';

Reproduce your issue. You will get a longer message with a backtrace. Copy the exact message you get, including the backtrace, and do tell me if it happens before or after you try to log in. I can help you further having those two pieces of information.

Nicholas K. Dionysopoulos

Lead Developer and Director

🇬🇷Greek: native 🇬🇧English: excellent 🇫🇷French: basic • 🕐 My time zone is Europe / Athens
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

Wouter Turkenburg
An error has occurred. 403 You don't have permission to access this. Please contact a website administrator if this is incorrect. Call Stack # Function Location 1 () JROOT/administrator/components/com_users/src/Controller/MethodsController.php:133 2 Joomla\Component\Users\Administrator\Controller\MethodsController->display() JROOT/libraries/src/MVC/Controller/BaseController.php:730 3 Joomla\CMS\MVC\Controller\BaseController->execute() JROOT/administrator/components/com_users/src/Controller/DisplayController.php:135 4 Joomla\Component\Users\Administrator\Controller\DisplayController->display() JROOT/libraries/src/MVC/Controller/BaseController.php:730 5 Joomla\CMS\MVC\Controller\BaseController->execute() JROOT/libraries/src/Dispatcher/ComponentDispatcher.php:143 6 Joomla\CMS\Dispatcher\ComponentDispatcher->dispatch() JROOT/libraries/src/Component/ComponentHelper.php:361 7 Joomla\CMS\Component\ComponentHelper::renderComponent() JROOT/libraries/src/Application/AdministratorApplication.php:150 8 Joomla\CMS\Application\AdministratorApplication->dispatch() JROOT/libraries/src/Application/AdministratorApplication.php:206 9 Joomla\CMS\Application\AdministratorApplication->doExecute() JROOT/libraries/src/Application/CMSApplication.php:320 10 Joomla\CMS\Application\CMSApplication->execute() JROOT/administrator/includes/app.php:58 11 require_once() JROOT/administrator/index.php:32 This i s what I get now. After I try to log in. Stil the 403 warning on top.

nicholas
Akeeba Staff
Manager

This tells you that the current user does not have permission to access Joomla's Users component. I have a few questions, though.

Are you trying to log into your site as a Super User, or a lesser-privileged user. In the latter case tell me which user group you belong to.

Have you enabled any features which force the user to edit their own account upon login e.g. forced MFA, or Joomla's com_privacy? If so, have you tried logging into the frontend of the site using the same user to see if you can apply the necessary changes to your user profile there?

Is your site behind a CDN, a TLS terminator, a load balancer, or an opaque caching proxy (e.g. Varnish) which may be caching the response from a different user trying to log into the site?

Nicholas K. Dionysopoulos

Lead Developer and Director

🇬🇷Greek: native 🇬🇧English: excellent 🇫🇷French: basic • 🕐 My time zone is Europe / Athens
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

Wouter Turkenburg
I try to log in as Super User. I see the backend but the 403 blocks me form goin further. There is no other user. Frontend login is not possible. The features you mention I do not know and are not enabled. My site is not behind the things you mention. Is there something in the database that I could edit that will end the blocking? Best, Walter

nicholas
Akeeba Staff
Manager

Before going down a rabbit hole, do you perhaps have a recent backup of your site from a date you know it was working fine?

Nicholas K. Dionysopoulos

Lead Developer and Director

🇬🇷Greek: native 🇬🇧English: excellent 🇫🇷French: basic • 🕐 My time zone is Europe / Athens
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

Wouter Turkenburg
I have tried to restore backups from the server of the host. No success. Even after cleaning the public_html and selecting dates of backups at moments that I knew all was working fine. Next, I cleaned everything: user, database, public_html. I started from scratch, uploaded via FileZilla an old .jpa backup and kickstart, and the website was up and running again. This strongly suggests that the problem was on the server of the host. They have been very friendly and helpful but could not solve the problem. One of the suggestions I found on the internet was that perhaps an update of the (shared) main server of the host, could have created the problems. What do you think? For sure, it was not akeeba backup or admin tools. Thans for the help, Walter

nicholas
Akeeba Staff
Manager

I am diving deeper into that, even though it's definitely out of scope of our support – mainly because I am very curious as to what is actually going on, and whether I can troubleshoot a weird issue without having hands on the site (if I didn't like a good puzzle I wouldn't be a software developer).

It looks like you are using Joomla 5.4 and the problem comes from Joomla's Multi-factor Authentication (MFA). The line number referenced in your message says that you were authenticated (username and password), then you are taken to the MFA, which rejected your request as it considered itself impossible to display.

My problem with what I am seeing in the stack trace and your description of what you did – especially the part about restoring a backup of a known-good site – is that they do not fit. The only reason the specific code line referenced in your stack trace would return the 403 is if you have disabled all multifactorauth plugins, or if your user is simultaneously in a forced MFA and a never MFA group. However, either of these issues would've made logging into the original site as that user impossible.

What I would do is restore the site, then use phpMyAdmin to remove all entries from the #__user_mfa table, thus disabling MFA for all users everywhere. If this doesn't help, also find all #__extension table entries where folder = 'multifactorauth' and enable them.

Nicholas K. Dionysopoulos

Lead Developer and Director

🇬🇷Greek: native 🇬🇧English: excellent 🇫🇷French: basic • 🕐 My time zone is Europe / Athens
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

Wouter Turkenburg
I sincerely appreciate and admire your perseverance. Here are some more pieces of the puzzle. I really like the J51 Layla template. But you cannot install that template directly on a Joomla 6 site. The work-around that I did, was installing it on a Joomla 5 site, and upgrade to Joomla 6. There were many overrides to check, which I did. I immediately installed Akeeba Backup Pro and Admintools Pro and configured the WAF. The J51 site was working well for a few days, but suddenly there was this 403 error. In directadmin I set the error reporting on maximum and got all these call-stack messages, which I do not really understand. I gave all the reporting to Google AI and one of the suggestions was, as you described, go into the database and set all multifactor stuff on zero. But that did not help either. So I removed the user, the database, cleaned the public_html folder and started from scratch. New user, new database, recent .jpa backup, kickstart.php and got the site up running. New problem this time:I updated the php version and installed an SSL layer but Firefox keeps telling the site is unsafe. Safari does not but I want the Firefox shield without the warning. Here is the site: 2025klagenfurt.iasj.com Are the 403 problem and this warning related? What do you think? Beste regards, Walter

nicholas
Akeeba Staff
Manager

Since you never tried any of my suggestions all I can do is ask you to follow my suggestions.

Nicholas K. Dionysopoulos

Lead Developer and Director

🇬🇷Greek: native 🇬🇧English: excellent 🇫🇷French: basic • 🕐 My time zone is Europe / Athens
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

Wouter Turkenburg
Sorry for the misunderstanding. I did follow all of your directions. I could never have sent you the error report if I had not followed your directions to make this change: public $debug = true; public $error_reporting = 'maximum' I changed the settings of the MFA as you suggested in phpMy Admin. But without results. I have not mentioned that in the former message; I should have. Sorry again. All is fine now. Thanks to your suggestions and ideas, and the workaround described above, the site is working again. The host cleaned up the SSL misdirections (without telling me how they did it). Without your help this would not have happened. So thanks again. Walter. Ticket can be closed.

nicholas
Akeeba Staff
Manager

Ooooh! The way I read your previous reply I understood that after the site was working you had restored it again with the same problem. OK, no worries, your site's working now, all good.

Nicholas K. Dionysopoulos

Lead Developer and Director

🇬🇷Greek: native 🇬🇧English: excellent 🇫🇷French: basic • 🕐 My time zone is Europe / Athens
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

Support Information

Working hours: We are open Monday to Friday, 9am to 7pm Cyprus timezone (EET / EEST). Support is provided by the same developers writing the software, all of which live in Europe. You can still file tickets outside of our working hours, but we cannot respond to them until we're back at the office.

Support policy: We would like to kindly inform you that when using our support you have already agreed to the Support Policy which is part of our Terms of Service. Thank you for your understanding and for helping us help you!