Admin unauthorized to view staging environment from different computers

Feature(s) impacted

admin users cant view part of the envs

Observed behavior

admin users cant view part of the envs from their computers, from others they can.

Expected behavior

Failure Logs

Context

  • Project name: RebarAdmin
  • Team name: Operations
  • Environment name: Staging
  • Agent technology: (nodejs, php, rails, python): nodejs
  • Agent (forest package) name & version: 9.3.10
  • Database type: sql
  • Recent changes made on your end if any: none,

Hello @zigit_zigit,

Can you check the network for any errors when you are failing to reach your agent ?

WhatsApp Image 2025-02-09 at 09.27.36_1b7c020a


Can you share the content of the CORS error on your authentication call ?

You could try as well to access it with private navigation and all extensions disabled to ensure it is not coming from the browser.

still dont work, https://europe1.discourse-cdn.com/flex013/uploads/forest/original/2X/7/78b543b3e59eb98585fce0e2ab53c98925848ddc.jpeg

Hello @zigit_zigit,

As we can see that you have a 403 error in your network, I was able to trace it back on our monitoring, I would suspect that your users cannot reach your environments as they do not have 2FA enabled on their account while using email/password as authentication. And your staging environment requires 2FA to be accessible.

However you should have been prompted with a more explicit error modal. Do you confirm that this is the issue, in which case I would start investigating as to why the proper modal has not been displayed.

Best regards,

In production, we have two-factor authentication (2FA) implemented, in the issue happen only in staging env so that not the problem

Could you share with me the kind of 403 error that is being sent then ? Can you check for logs in your agent when your users receive this error.

From my side the only traces I can see are errors related to 2FA not being enabled and I observe 2 users using email/password without 2FA enabled on their account.

which users you find?

I see 2 accounts without 2FA enabled and using email/password:

  • stav.d@
  • amit@