SeAT - forum: Bad Request - Request Too Long HTTP Error 400. The size of the request headers is too long - Page 1
Seion
18 Aug 2024 12:28
Some users doing additional character linking get the following error “Bad Request - Request Too Long HTTP Error 400. The size of the request headers is too long” I am still trying to figure out how it’s being triggered, but I am thinking it’s happening when the person has a lot of characters to link. I’ll provide more details as I get them, not seeing anything in logs unfortunately.
recursive_tree
18 Aug 2024 13:16
I think it can happen if you request too many scopes or something like that. It shouldn’t happen with seat though, even if you select all scopes
Claw
18 Aug 2024 13:31
If you go back to seat and select link again the account you tried to log in should be up with the characters, if you needed a workaround in the meantime
Seion
18 Aug 2024 13:32
In the dev page for the app on eve online I think I selected a lot of scopes and same in seat
I was unsure the specific scopes needed
I could probably clean that up a little
Is there a property somewhere that could expand the header size
Or is it on the eveonline side
I’m using my own proxy (nginx)
And cloudflare
recursive_tree
18 Aug 2024 13:39
The error is on ccps side
Seion
18 Aug 2024 13:43
:/
Any idea of its the amount of allowed scopes on the ccp dev app side or the amount of requested scopes from the eveseat single sign-on side of things?
recursive_tree
19 Aug 2024 13:12
It complains about the request being too long, so client side
Seion
19 Aug 2024 13:23
yea but which side is generating the header with scopes in it
I eventually am going to dig down into the oauth flow that CCP is using, but wanted to see which side I need to trim for now until I can get some time to research
recursive_tree
19 Aug 2024 16:43
the browser sends the request, so seat
Astral
21 Aug 2024 01:25
All scopes,
Seion
21 Aug 2024 01:25
I still have not gotten to debug yet, but is it cause because of the amount of scope along with the large amount of charcters attempting to be linked by one person?
Astral
21 Aug 2024 01:25
Just know cloudflare is useless if someone can connect right to your backend.. make sure to use mTLS or whitelist only cf ranges..
Seion
21 Aug 2024 01:26
its https
Astral
21 Aug 2024 01:26
Doesn't mean anything security wise if you aren't using cloudflare correctly..
Seion
21 Aug 2024 01:28
I have firewall and only port 443 open and strict full ssl turned on
and proxy on cloudflare
anything else I am missing?
Astral
21 Aug 2024 01:30
Yeah but is your firewall only allowing cloudflare ranges..?
Seion
21 Aug 2024 01:31
I have some other stuff I run through non cloudflare that I need
and they are not static IP's I can whitelist
I might be able to whitelist, ill look into it
anyways, any things I should look at when I get the user to screenshare and see the flow thats triggering this error
ill be tailing the log while they do it, but I didn't see anything out right when I tried to scan through it
Astral
21 Aug 2024 01:36
Eh just asking.. lots of people rely on Cloudflare but they don't actually secure it properly.. then it becomes, an attacker can cause havoc if they can just bypass Cloudflare directly, There is methods to figure out what the host is if you really want to actually find it..
Which stuff..?
Seion
22 Aug 2024 01:19
Here is the target URL when it fails. I have to split this into two chats.
%2Besi-corporations.readcontacts.v1%2Besi-corporations.readcontainerlogs.v1%2Besi-corporations.readcorporationmembership.v1%2Besi-corporations.readdivisions.v1%2Besi-corporations.readfacilities.v1%2Besi-corporations.readfwstats.v1%2Besi-corporations.readmedals.v1%2Besi-corporations.readstandings.v1%2Besi-corporations.readstarbases.v1%2Besi-corporations.readstructures.v1%2Besi-corporations.readtitles.v1%2Besi-corporations.trackmembers.v1%2Besi-fittings.readfittings.v1%2Besi-fleets.readfleet.v1%2Besi-industry.readcharacterjobs.v1%2Besi-industry.readcharactermining.v1%2Besi-industry.readcorporationjobs.v1%2Besi-industry.readcorporationmining.v1%2Besi-killmails.readcorporationkillmails.v1%2Besi-killmails.readkillmails.v1%2Besi-location.readlocation.v1%2Besi-location.readonline.v1%2Besi-location.readshiptype.v1%2Besi-mail.readmail.v1%2Besi-markets.readcharacterorders.v1%2Besi-markets.readcorporationorders.v1%2Besi-markets.structuremarkets.v1%2Besi-planets.manageplanets.v1%2Besi-planets.readcustomsoffices.v1%2Besi-search.searchstructures.v1%2Besi-skills.readskillqueue.v1%2Besi-skills.readskills.v1%2Besi-universe.readstructures.v1%2Besi-wallet.readcharacterwallet.v1%2Besi-wallet.readcorporationwallets.v1%26responsetype%3Dcode%26state%3DHIDDEN
Cindar of Gol
19 Sep 2024 12:54
Our Seat is having the same exact issue too!
Seems other tools similar to SeAT are also having similar issues. Ccp likely changed something in the SSO
Seion
30 Sep 2024 22:55
Let me know if you figure it out
Any one figure this out
Cindar of Gol
9 Oct 2024 16:58
The error cleared for us after ccp got their api fixed
Seion
12 Oct 2024 11:32
I’m still having issues with people that have more than seven characters
I’m not sure if it’s seven is is the only one with errors
Raiden
8 Nov 2024 19:44
IM having this issue with 2 characters
Flangel
9 Nov 2024 19:18
im having this issue with 2 users. im clear installed SEAT today, and try to link character. from first eve acc all ok, from second this error.
may be workaround?
Raiden
9 Nov 2024 19:52
I had to wait several hours. And it seemed to resolve itself. Issue with eve I think
Akov
14 Nov 2024 21:45
what I tell people when this happens (and it always happens randomly)
1. If you are already logged in on the eve website, log out
2. If you are logged out on the eve website, login
3. Try again
It has something to do with Ccp appending headers to the request as it gets redirected. But can never figure out why the redirect happens "some times"
but the 3 above steps have a 100% cure rate
Crypta Electrica
15 Nov 2024 03:34
https://github.com/esi/esi-issues/issues/267
Akov
15 Nov 2024 04:40
right, but it doesnt explain why its random
Crypta Electrica
15 Nov 2024 04:40
This is true.. And I cant find the sso-issues issue for it... But that is the problem that is presenting here
Akov
15 Nov 2024 04:41
yea