Skip to content

[Bug]: nextcloud-whitelist parser doesn't cover POST /apps/mail/api/mailboxes/<id>/sync returning 403 #1871

Description

@jiriks74

Describe the bug
When using Nextcloud Mail, legitimate mailbox synchronization requests trigger a ban within roughly a minute.

CrowdSec sees requests such as:

http_path: /apps/mail/api/mailboxes/<id>/sync
http_status: 403
http_verb: POST
log_type: http_access-log
service: http

To Reproduce

  1. Open browser developer tools on the Network tab.
  2. Open Nextcloud Mail.
  3. Observe POST /apps/mail/api/mailboxes/<id>/sync requests returning 403.
  4. Get banned by CrowdSec.

Expected behavior
Legitimate mailbox sync requests should not trigger a ban.

Screenshots

Note

/auth/token in the screenshot is not from Nextcloud but another service.

Image

Additional context
<id> in /apps/mail/api/mailboxes/<id>/sync is a numeric mailbox ID.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions