# /forest/sessions returns 404 unable to log in/unlock data

**URL:** <https://community.forestadmin.com/t/forest-sessions-returns-404-unable-to-log-in-unlock-data/5352>\
**Category:** Help me!\
**Tags:** rails\
**Created:** [October 6, 2022, 10:24pm UTC](https://community.forestadmin.com/t/forest-sessions-returns-404-unable-to-log-in-unlock-data/5352 "2022-10-06T22:24:43Z")\
**Posts on this page:** 13\
**Page:** 1

<div class="post-metadata">

**Author:** ![webdev.kiwi](https://dub1.discourse-cdn.com/flex013/user_avatar/community.forestadmin.com/webdev.kiwi/32/5192_2.png) [@webdev.kiwi](https://community.forestadmin.com/u/webdev.kiwi)\
**Post date:** [October 6, 2022, 10:24pm UTC](https://community.forestadmin.com/t/forest-sessions-returns-404-unable-to-log-in-unlock-data/5352/1 "2022-10-06T22:24:43Z")

</div>

## Feature(s) impacted

- Access to forest admin app, user login, can not unlock data.
- forest\_liana rails gem

## Observed behavior

Can not unlock data, error is returned from rails app. 404 to route `myappurl/forest/sessions`

 ![image](https://europe1.discourse-cdn.com/flex013/uploads/forest/original/2X/e/ed2789908ac48e0b2bb8158f9dae2c2691d205c4.png)

## Expected behavior

Able to unlock data.

## Failure Logs

 ![image](https://europe1.discourse-cdn.com/flex013/uploads/forest/original/2X/1/13686655cb3467d55f227e0d4c6bd890ba5ad36f.png)

 ![image](https://europe1.discourse-cdn.com/flex013/uploads/forest/original/2X/8/8d0abda34881f3d7f2c2ab967d844c2a41abbb38.png)

## Context

I have a Rails app that I am trying to update from the `forest_liana` v5 gem.

My Rails version is v5, my Ruby version is 2.6.8 - all is in progress of rewrite to update, not relevant to issue. `forest_liana` v5 working fine.

Have attempted both `forest_liana` versions 6.6.3 and 7.7 - both have same issue.

Have followed upgrade documentation from v5 to v6.

/forest/ is mounting, as I was able to call the route `/forest/authentication/callback` via curl to generate the JWT needed for client\_id that is requested in the upgrade documentation [Upgrade to v6 | Developer Guide](https://docs.forestadmin.com/documentation/how-tos/maintain/upgrade-notes-rails/upgrade-to-v6)

CORS is setup and working as expected.

This is a Heroku staging environment, paths redacted, all env vars appear correct.

My routes are mounted as they were in v5 and earlier `mount ForestLiana::Engine => '/forest'`

This app has been using Forest for over 5 years now, and updated progressively through that time. Could newer versions have introduced something different that is absent from the upgrade docs?

Help please, I’m stuck!

---

<div class="post-metadata">

**Author:** ![Florian\_Gonzales](https://dub1.discourse-cdn.com/flex013/user_avatar/community.forestadmin.com/florian_gonzales/32/5541_2.png) [@Florian\_Gonzales](https://community.forestadmin.com/u/Florian_Gonzales)\
**Post date:** [October 7, 2022, 7:14am UTC](https://community.forestadmin.com/t/forest-sessions-returns-404-unable-to-log-in-unlock-data/5352/2 "2022-10-07T07:14:30Z")

</div>

Hello @webdev.kiwi,

Thanks for your feedback ! We will try to understand and solve your problem as soon as possible. Can you tell me what is your project name please? 🙏

Kind regards,

Florian

---

<div class="post-metadata">

**Author:** ![webdev.kiwi](https://dub1.discourse-cdn.com/flex013/user_avatar/community.forestadmin.com/webdev.kiwi/32/5192_2.png) [@webdev.kiwi](https://community.forestadmin.com/u/webdev.kiwi)\
**Post date:** [October 7, 2022, 8:25am UTC](https://community.forestadmin.com/t/forest-sessions-returns-404-unable-to-log-in-unlock-data/5352/3 "2022-10-07T08:25:24Z")

</div>

Hello @Florian_Gonzales,

Thanks for your reply, the project name is ihub-api

---

<div class="post-metadata">

**Author:** ![matthv](https://dub1.discourse-cdn.com/flex013/user_avatar/community.forestadmin.com/matthv/32/3269_2.png) [@matthv](https://community.forestadmin.com/u/matthv)\
**Post date:** [October 7, 2022, 2:19pm UTC](https://community.forestadmin.com/t/forest-sessions-returns-404-unable-to-log-in-unlock-data/5352/7 "2022-10-07T14:19:07Z")

</div>

Hello @webdev.kiwi

The `/forest/session` route no longer exists on versions \>=6 .  
It seems that the frontend does not recognize the gem update.  
Did you push the .forestadmin-schema.json file into production?

The file contains the version number. Here an example :  
 ![Screenshot 2022-10-07 at 16.18.01](https://europe1.discourse-cdn.com/flex013/uploads/forest/original/2X/4/4fd45a428ccf5c267a2bc814a7b86bc5b51902d0.png)

---

<div class="post-metadata">

**Author:** ![webdev.kiwi](https://dub1.discourse-cdn.com/flex013/user_avatar/community.forestadmin.com/webdev.kiwi/32/5192_2.png) [@webdev.kiwi](https://community.forestadmin.com/u/webdev.kiwi)\
**Post date:** [October 7, 2022, 5:04pm UTC](https://community.forestadmin.com/t/forest-sessions-returns-404-unable-to-log-in-unlock-data/5352/8 "2022-10-07T17:04:21Z")

</div>

Hello @matthv

This schema file is out of date. I believe that we only introduced this file when upgrading to v5.

![image](https://europe1.discourse-cdn.com/flex013/uploads/forest/original/2X/4/4ac87e0ab91f5a824092c6ea87ef1cb0bc967cfc.png)

Would you know the expected workflow for how this file is generated and updated as models change?

Using the regular `bundle` type commands to update the gems did not update this file, and I did not see reference to this in the documentation [Upgrade to v6 - Developer guide](https://docs.forestadmin.com/documentation/how-tos/maintain/upgrade-notes-rails/upgrade-to-v6)

Please excuse my misunderstanding of workflow, we only recently upgraded to v5, we had used a much earlier version for many years prior.

I have manually updated the `liana_version` version to `7.7.0` in the `.forestadmin-scema.json`, this matches the gem version installed. While my issue has not resolved, the symptoms have changed.

![image](https://europe1.discourse-cdn.com/flex013/uploads/forest/original/2X/5/5b7c07dd53f28c53ec18469b63e7466bc0ba36c9.png)

The CORS rules are set inline with that described in the [Upgrade to v6 - Developer guide](https://docs.forestadmin.com/documentation/how-tos/maintain/upgrade-notes-rails/upgrade-to-v6) documentation.

![image](https://europe1.discourse-cdn.com/flex013/uploads/forest/original/2X/b/bf1f3f3e2908881de355cb9410a18f7713f6c874.png)

Thank you for your assistance

---

<div class="post-metadata">

**Author:** ![matthv](https://dub1.discourse-cdn.com/flex013/user_avatar/community.forestadmin.com/matthv/32/3269_2.png) [@matthv](https://community.forestadmin.com/u/matthv)\
**Post date:** [October 10, 2022, 8:26am UTC](https://community.forestadmin.com/t/forest-sessions-returns-404-unable-to-log-in-unlock-data/5352/9 "2022-10-10T08:26:59Z")

</div>

On the development environment the file is automatically generated when you start your rails server application (`rails server`).  
(You must also check that the cache is active on this environment ‘rails dev:cache’)

Otherwise you can also force the generation of this file via the command `rails forest:send_apimap`

Regarding the CORS configuration I don’t recommend to leave `*` for the origins parameter.

---

<div class="post-metadata">

**Author:** ![webdev.kiwi](https://dub1.discourse-cdn.com/flex013/user_avatar/community.forestadmin.com/webdev.kiwi/32/5192_2.png) [@webdev.kiwi](https://community.forestadmin.com/u/webdev.kiwi)\
**Post date:** [October 10, 2022, 6:08pm UTC](https://community.forestadmin.com/t/forest-sessions-returns-404-unable-to-log-in-unlock-data/5352/10 "2022-10-10T18:08:41Z")

</div>

Thanks for your response @matthv

I think I may be misunderstanding the outcome of `rails dev:cache`, to enable caching in a development environment. I have run this command with no affect. We do not wish to enable caching in production, and the production API has multiple instances and is behind a load balancer, serving mobile applications and SPAs from unknown origins.

This is being pushed onto a staging server, which is only a single instance and not load balanced, however I followed the instruction to generate the client\_id for that domain, and those calls are successful.

 ![forest caching](https://europe1.discourse-cdn.com/flex013/uploads/forest/original/2X/c/c53fae5a8620867b17a4ed013ff3a7d2aec878f4.png)

If I look into the console for forest, there are 500s being returned.

 ![image](https://europe1.discourse-cdn.com/flex013/uploads/forest/original/2X/d/de2e60d3c0020930c0714effbdb4e191eb1edc1e.png)

---

<div class="post-metadata">

**Author:** ![matthv](https://dub1.discourse-cdn.com/flex013/user_avatar/community.forestadmin.com/matthv/32/3269_2.png) [@matthv](https://community.forestadmin.com/u/matthv)\
**Post date:** [October 11, 2022, 7:39am UTC](https://community.forestadmin.com/t/forest-sessions-returns-404-unable-to-log-in-unlock-data/5352/11 "2022-10-11T07:39:59Z")

</div>

Could you also share the browser console tab. It might help to understand the issue 🙏

---

<div class="post-metadata">

**Author:** ![webdev.kiwi](https://dub1.discourse-cdn.com/flex013/user_avatar/community.forestadmin.com/webdev.kiwi/32/5192_2.png) [@webdev.kiwi](https://community.forestadmin.com/u/webdev.kiwi)\
**Post date:** [October 11, 2022, 5:19pm UTC](https://community.forestadmin.com/t/forest-sessions-returns-404-unable-to-log-in-unlock-data/5352/12 "2022-10-11T17:19:17Z")

</div>

Thanks matthv, sorry I am not sure I understand to share the browser console tab, is that in my last post?

I have also tried setting up a new forest project, and following the guide in a new rails project to see if there was difference. I am also unable to connect in that instance. The screen is stuck on “waiting for your backend to run…”, which it is. I then refresh the page and simply get stuck at this point.

 ![image](https://europe1.discourse-cdn.com/flex013/uploads/forest/original/2X/b/b8ec453239ab7fe751deb4a57b4a935acfeb954d.png)

This is a “development” environment following the new project setup guide exactly. I have also noted that the setup does not step through various steps that the upgrade to v6 docs mentioned, such as requiring an application\_url set in secrets.yml or a client\_id, or making any changes to CORS configuration.

---

<div class="post-metadata">

**Author:** ![webdev.kiwi](https://dub1.discourse-cdn.com/flex013/user_avatar/community.forestadmin.com/webdev.kiwi/32/5192_2.png) [@webdev.kiwi](https://community.forestadmin.com/u/webdev.kiwi)\
**Post date:** [October 11, 2022, 5:44pm UTC](https://community.forestadmin.com/t/forest-sessions-returns-404-unable-to-log-in-unlock-data/5352/13 "2022-10-11T17:44:25Z")

</div>

I can see by tailing the production logs that the forest\_liana 7.7.0 gem throws error,

 ![image](https://europe1.discourse-cdn.com/flex013/uploads/forest/original/2X/f/f125c01a0689292e8716f5b114b0c2ad89b216f3.png)

---

<div class="post-metadata">

**Author:** ![webdev.kiwi](https://dub1.discourse-cdn.com/flex013/user_avatar/community.forestadmin.com/webdev.kiwi/32/5192_2.png) [@webdev.kiwi](https://community.forestadmin.com/u/webdev.kiwi)\
**Post date:** [October 12, 2022, 6:04am UTC](https://community.forestadmin.com/t/forest-sessions-returns-404-unable-to-log-in-unlock-data/5352/14 "2022-10-12T06:04:39Z")

</div>

As reference for anyone encountering similar issues, I have a progress update.

While I was not able to get a ‘development’ environment working through the setup tutorial for creating a new rails forest project with my specific codebase, I have a staging environment connecting to a new ‘project’ I have created in forest admin that was created for testing. We will need to make some architectural changes for production which we are in process of discussing.

There was an issue with an earlier version of `rack-cors` we were running (`0.4.1`), updating this to `1.1.1`, with some other changes to our cors config has lead to successfully connecting using the forest\_liana 7.70 gem.

There is a caveat to this setup. Forest admin requires that `credentials: true` is set in the `rack-cors` config, while `rack-cors: 1.1.1` does not allow wildcard `origins '*'` and `credentials: true` to be set at the same time, the app will not start and will crash with an error informing so. Understandable security concerns with `credentials: true`, your app will run with `credentials: false` and `origins '*'` but you will not be able to unlock your data in forest.

This will be a limitation for some where their API is public. There are ways around this, such as running a separate instance of the app for forest admin with a differing cors config, or standing up another app for the public API that acts as a proxy, and other ideas you may have. This is not advice on what you should do to address this, that will be up to your own business requirements.

If you are running an ionic Mobile app, see [CORS Errors: Cross-Origin Resource Sharing - Ionic Documentation](https://ionicframework.com/docs/troubleshooting/cors) for details on the ports used for your version to set cors config to allow mobile apps to connect (not yet tested for our setup).

We also have a React Native app in development which will require some different config to set cors too, these are expected to be similar, if not the same, to ionic.

If you’re running a native app on iOS or Android, you may need to consider setting up different app instances for forest with a different cors config if your native app framework enforces cors. Same will go for desktop and Electron type apps, you will need to investigate further if you experience any issues there .

known working versions:  
Ruby: 2.6.x  
Rails: 5.2.x  
Rack-cors: 1.1.1  
forest\_liana: 7.7.0

Your `rack-cors` config will need to match the following exactly, with only changes to append additional known origins you may have, and/or pass those in with the environment variable `CORS_ORIGINS`.

 ![image](https://europe1.discourse-cdn.com/flex013/uploads/forest/original/2X/c/c60f914f1f21a767b46a8268da09e1afa345421f.png)

---

<div class="post-metadata">

**Author:** ![matthv](https://dub1.discourse-cdn.com/flex013/user_avatar/community.forestadmin.com/matthv/32/3269_2.png) [@matthv](https://community.forestadmin.com/u/matthv)\
**Post date:** [October 12, 2022, 8:17am UTC](https://community.forestadmin.com/t/forest-sessions-returns-404-unable-to-log-in-unlock-data/5352/15 "2022-10-12T08:17:17Z")

</div>

Did you manage to solve the problem also on your project? 🙂

About CORS as you indicate you can’t leave origins ‘\*’ with credentials at ‘true’.  
More information here: [Reason: Credential is not supported if the CORS header 'Access-Control-Allow-Origin' is '\*' - HTTP | MDN](https://developer.mozilla.org/en-US/docs/Web/HTTP/CORS/Errors/CORSNotSupportingCredentials)

---

<div class="post-metadata">

**Author:** ![webdev.kiwi](https://dub1.discourse-cdn.com/flex013/user_avatar/community.forestadmin.com/webdev.kiwi/32/5192_2.png) [@webdev.kiwi](https://community.forestadmin.com/u/webdev.kiwi)\
**Post date:** [October 12, 2022, 5:17pm UTC](https://community.forestadmin.com/t/forest-sessions-returns-404-unable-to-log-in-unlock-data/5352/16 "2022-10-12T17:17:06Z")

</div>

Thanks for all your assistance @matthv,

from this we have solved our issue with a branch of our rails api hosted on a staging server connecting to a ‘test’ project in forest. I am fairly confident this will be the solution, we’re currently discussing our options of running separate app instances (and CORS config) for forest and public api.
