Thanks for working so hard to fix this, and I’m sorry it’s happening!
Also came by here to mention that I’m getting stuck in an infinite verification loop on Kindle Fire. I think it might be an issue with Silk, Amazon’s built-in browser app. I’m able to verify fine on my phone with Chrome (albeit with the same need to refresh and re-verify others have reported), but I’m hard stuck on Kindle. And Kindle is where I normally read from
I’ll see if I can figure out what’s going on. The dev contacted me today and I need to get him some info, so I’ll send this along, too. I’ve been testing on and off and am having trouble with Firefox on my phone (but not on PC), so I think Cloudflare is causing some weird issues still.
Getting uncaught reference error stats is not defined and an uncaught type error cannot read properties of undefined (reading ‘setStartingStatsClone’) whenever I click on any demo regardless of the game. Guessing this is a bug that’s going around in the aftermath of these bot attacks.
I’m using phone to read cog demo and one thing I hate is everytime I refresh the page it always take me to verify page. I mean I don’t mind it but if it takes me there everytime I refresh the page it’s really annoys me
What browser are you using? And is it mobile (phone/tablet) or PC? The only way I’m getting the weird errors is on Firefox on my iPhone.
I just turned down the throttling on /play. If everything stays calm tomorrow, I’ll just leave the throttle on the main site (and re-enable favorites). I found another list of bots to add to my Apache block list, and that should help, too.
I’m going to shut that off tomorrow, provided things stay calm on the site. I just don’t want to shut it down, go to bed, and wake up to everyone pissed off because the site’s not responding again.
Yep… what I don’t get is that I have it set to check every hour (before, it was 30 minutes, because I was sick of getting hammered by the crap that slipped past Cloudflare), but it seems to be more often.
I suggest spamming quick save until everything is settled. I also think Cloudflare is doing something funky with the cookies, but haven’t quite nailed down what it is yet. That is likely a dev question.
the culprit is cloudflare. That script is on timer so if you stay on a website too long it has to verrify you again. i think its called ‘‘time-out’’ (not sure about that section but its clearly cloudflare).
lol, i took a specific look on how the rules works. The " clouflare owasp ruleset " of boy ! cogdemos can’t work with cloudflare scripts its impossible.
In my many sessions i open a tab and don’t refresh it for days…days !!! the cloudflare time-out will take those tab connections as an hostile bot or something, sigh !
Is bots problems on cogdemos this serious ? Do connections need to be refresh often ?
Like I said, if it stays calm with traffic, I’ll take the throttle of of the play path, which should ease this some.
But yeah, the bots were that bad the other night–5k hits over ten minutes from one IP, with another 10-15 IPs doing the same thing. Blocking the IP was like whack-a-mole, because they were changing their IP often. By the time I woke up yesterday morning, there were over a million hits over night and it killed the site. It wasn’t fun.
I know it’s annoying right now, but I’d rather have the site working (mostly) than to have it lose function for everyone. I’m hoping cloudflare will help this enough where I can ease the restrictions on re-verifying often (and am going to tinker more with the blocks I have set up on the server itself).
Cogdemos has one of the best low ressource loading time. Meaning that a low ressource internet connection can enjoy the website, one of the best perk of the site.
I was in the believe that the website load the texts to the client and close the connection. So bots are the only one that refresh more than 5 times in the row. And its easy to see those bots and to manage them. In my opinion cloudflare mess thing up and isn’t practical (without going on the more serious topic on how the censure work with cloudflare).
i found documentation in the waf (web application firewall) section.
take a look it may help :
This is new, I think. Gets fixed by a refresh, usually, but still. (Randomly on page load when returning to a tab that has a game open but decides to refresh, if that helps.)
If you got that right before you posted it, it was likely because I restarted php-fpm. I was making a change to up the workers because they were hitting the ceiling again earlier today. Not like before (thankfully), but after some more digging, I see this has been going on for a while, just very intermittently. Maybe once or twice a week. It only came to a head when the bots decided to go into Terminator mode.
I sent the dev a bunch of info on this, along with proof that the issue is with the load being too heavy on PHP.
No, that particular one was 19:53 UTC+2 DST (so… four hours prior? Something like that). I’ve had two or three of them last twelve hours and I think one or two the day before, but I’m not sure.