So frustrated. "Request was rejected because user is not permitted to perform this operation"

I am also using Cloudflare and suspected a configuration change in Cloudflares Managed Rulesets might be the cause of my issue. By disabling Cloudflare on this domain (not simply the caching), image upload worked. So I investigated further.

It appears there is a conflict with the OWASP default ruleset used by Cloudflare. Setting the OWASP Anomaly Score to Medium (40 and higher) and the Paranoia Level to PL1, seems to enable uploads. I was originally configured for High (25 and higher) and PL2. I believe those were “default settings” for Cloudflare. Perhaps a ticket should be submitted to Cloudlfare to look at their default WAF Managed rulesets.

Hope this helps anyone else facing this issue.

1 Like