PLEASE NOTE: This article may be out-of-date. Please visit the Support site for the latest information.

Updates for 03/27/2011 (Lock to Account Enforced)

111 posts / 0 new
Dernière contribution
wmjob (non vérifié)

hi. my name is mykola. I am from Ukraine and my english is to bed.
may be my accounts are banned? because tumbnail do not work, but it was fine some weeks later.
can we some doing?

Thank
my sites -
*** Potential spam removed ***

Portrait de aussiebattery
aussiebattery
offline
Inscription: 08/16/2011
Visiter  aussiebattery's Site web

Helpful and details note, thank u

cgehringer
offline
Inscription: 12/14/2009
Visiter  cgehringer's Site web

1. Why isn't https://s-external.ak.fbcdn.net/safe_image.php?d=AQAGrjbNzNnZMKwP&url=http%3A%2F%2Fimages.shrinktheweb.com%2Fxino.php%3Fembed%3D1%26STWAccessKeyId%3Dxxxxxxxxxxx%26stwsize%3Dlg%26stwUrl%3DCherokeeAlumni.org working?

I added s-external.ak.fbcdn.net to my referrers.

2. Should I also add fbcdn.net to be safe?

Thanks.

Portrait de puravida
puravida
Jedi Warrior
offline
Inscription: 09/01/2007
Visiter  puravida's Site web

We cannot be sure without seeing an end-user implementation. If the referrer is the full subdomain you mentioned, then it should be working. It would not be necessary to add the top level domain. In this case, if it works, then we really need to add that to the master whitelist, since others may need it too.

Since it is not working for you, my first guess is that the actual referrer being sent to us is the actual domain/IP where the image is showing or is something else from Amazon other than what we expect.

cgehringer
offline
Inscription: 12/14/2009
Visiter  cgehringer's Site web

You may be able to see the result if you go to Facebook. In your profile, pretend you are going to update your status. Type http://wwpnorthalumni.org and then a space. Facebook will go out and fetch the image which I had programmed into the page (since changed) but still cached. You should see the banned image rather than the one I intended.

Portrait de puravida
puravida
Jedi Warrior
offline
Inscription: 09/01/2007
Visiter  puravida's Site web

I had to dust off my facebook credentials, since I don't use it much. lol.

Anyway, I see the banned placeholder and suspect that Facebook is making the request using a different referrer. As a courtesy, I ran some investigative tests but could not rule anything out for certain, mostly since I do not have your code (and do not have time to review it right now either)...

Troubleshooting Notes:

  1. I noted in your logs that there are some lock-to-account failed requests
  2. In order to rule out lock-to-account, I upgraded your account to BASIC, disabled lock-to-account, turned on full logging, forced facebook to refresh my page [CTRL+F5], and then pasted the URL again
  3. I still saw the same banned placeholder
  4. In the logs, I saw no traces of the request at all
  5. I did, however, see several requests coming in from IPs (meaning from servers directly, most likely scripts)
  6. Just to be sure that logging is working correctly, I made a request using your credentials for test.com and did see it in the logs

Since I saw no trace of the request when I refreshed and retried on facebook, I would say that:

  1. They either cache the image and did not retry it OR
  2. Your code is missing your stwaccesskeyid (possible reason not showing in logs)

On a side note, even if you get this working, you would need to upgrade to at least "BASIC Account" level, because you are using an advanced method that is no longer supported for free accounts. It will be disabled in the upcoming months.

The other reason is that at least "BASIC Account" level is also required to remove the lock-to-account requirement, which is going to be necessary in this implementation. We cannot add facebook.com to the master whitelist or else it would open up a security loophole to abuse user accounts. However, your implementation through Facebook guards your credentials very well. I saw no possible way to get to them, so it is a secure implementation, even though you would be "unlocking" your account.

I have set your account back to the way it was before. I hope my observations are helpful.

zuggi_zuggi
offline
Inscription: 11/22/2010
Visiter  zuggi_zuggi's Site web

"On a side note, even if you get this working, you would need to upgrade to at least "BASIC Account" level, because you are using an advanced method that is no longer supported for free accounts. It will be disabled in the upcoming months."

What could this advanced method be, and when will it be disabled ?

Portrait de puravida
puravida
Jedi Warrior
offline
Inscription: 09/01/2007
Visiter  puravida's Site web

I just stumbled across another possibility.

I discovered that facebook.com and www.facebook.com were both specifically on the DOMAIN BLACKLIST. That may have been blocking it OR you may have fixed your code. If you made no changes, then removing facebook from the blacklist may be what fixed it, as I can see the screenshot now when I paste it into my status update.

I also saw the "hit" in the logs and it came from that same IP block that I mentioned earlier, so that must be Facebook's servers and they use a script to pull those images in.

All of this was done with upgraded to BASIC and with lock-to-account disabled.

gdmnw
offline
Inscription: 06/10/2010
Visiter  gdmnw's Site web

Hi,

I'm getting the Locked thumbnail here: http://gdmnw.com/empyrean/blogdex_entry/gdmnw-com/

I've added the following to my allowed list:

174.120.1.24
gdmnw.com
bunker5.com

I have a basic account and use the 'official' WP Plugin.

Ironically the thumbnails appear to be working fine at http://gdmnw.com/blogdex/40k-blogs/

Warning, there's a lot of them on that page, I'm rebuilding the site to change that and that's when I've encountered problems.

Any help?

Portrait de puravida
puravida
Jedi Warrior
offline
Inscription: 09/01/2007
Visiter  puravida's Site web

Generally speaking, the forum is not as monitored as the support tickets. You may be better off opening a ticket, as I will rarely post on issues here.

That said, you have added the IP and domain correctly, from what I can tell.

That means that you should turn on "Full Logging" to see what error messages you receive (or don't receive, which is also a clue).

Topic locked

ShrinkTheWeb® (About STW) est une autre innovation de Neosys Consulting

Nous contacter | PagePix Benefits | Learn More | Nos partenaires | Politique de confidentialité | Conditions d'utilisation

©2014 ShrinkTheWeb. All rights reserved. ShrinkTheWeb is a registered trademark of ShrinkTheWeb.