I everybody! I have a WordPress enviroment running over Apache Web Server.
I've noticed that every image requested within the HTML SRC attribute, gets 404 error code. But, the same image using the same URI requested by browser navbar returns 200. The main difference between them is where the initiatior is located:
Requested initiated by src image attribute:
GET /wp-content/gallery/media/Reuniones_Berg_2-300x225.jpg HTTP/1.1
Host: www.transparencia.sasipa.cl
Connection: keep-alive
sec-ch-ua: "Chromium";v="94", "Google Chrome";v="94", ";Not A Brand";v="99"
DNT: 1
sec-ch-ua-mobile: ?0
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/94.0.4606.81 Safari/537.36
sec-ch-ua-platform: "Windows"
Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
Sec-Fetch-Site: same-origin
Sec-Fetch-Mode: no-cors
Sec-Fetch-Dest: image
Referer: https://www.transparencia.sasipa.cl/
Accept-Encoding: gzip, deflate, br
Accept-Language: es-UY,es-CL;q=0.9,es;q=0.8,en-US;q=0.7,en;q=0.6,de-DE;q=0.5,de;q=0.4,es-419;q=0.3
Cookie: ...
Response:
HTTP/1.1 404 Not Found
Date: Mon, 25 Oct 2021 21:43:40 GMT
Server: Apache
Expires: Wed, 11 Jan 1984 05:00:00 GMT
Cache-Control: no-cache, must-revalidate, max-age=0
Link: <https://www.transparencia.sasipa.cl/wp-json/>; rel="https://api.w.org/"
Keep-Alive: timeout=5, max=100
Connection: Keep-Alive
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8
Image requested by copy-paste on browser navigation bar:
GET /wp-content/gallery/media/1380344777.jpg HTTP/1.1
Host: www.transparencia.sasipa.cl
Connection: keep-alive
Cache-Control: max-age=0
sec-ch-ua: "Chromium";v="94", "Google Chrome";v="94", ";Not A Brand";v="99"
sec-ch-ua-mobile: ?0
sec-ch-ua-platform: "Windows"
DNT: 1
Upgrade-Insecure-Requests: 1
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/94.0.4606.81 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9
Sec-Fetch-Site: none
Sec-Fetch-Mode: navigate
Sec-Fetch-User: ?1
Sec-Fetch-Dest: document
Accept-Encoding: gzip, deflate, br
Accept-Language: es-UY,es-CL;q=0.9,es;q=0.8,en-US;q=0.7,en;q=0.6,de-DE;q=0.5,de;q=0.4,es-419;q=0.3
Cookie: ...
If-Modified-Since: Thu, 15 Nov 2018 15:03:12 GMT
Response:
HTTP/1.1 200 OK
Date: Mon, 25 Oct 2021 21:35:41 GMT
Server: Apache
Last-Modified: Thu, 15 Nov 2018 15:03:12 GMT
Accept-Ranges: bytes
Keep-Alive: timeout=5, max=100
Connection: Keep-Alive
No error_log file is generated by PHP. Here is my .htaccess:
# BEGIN cPanel-generated php ini directives, do not edit
# Manual editing of this file may result in unexpected behavior.
# To make changes to this file, use the cPanel MultiPHP INI Editor (Home >> Software >> MultiPHP INI Editor)
# For more information, read our documentation (https://go.cpanel.net/EA4ModifyINI)
<IfModule php7_module>
php_flag display_errors Off
php_value max_execution_time 30
php_value max_input_time 60
php_value max_input_vars 1000
php_value memory_limit 200M
php_value post_max_size 200M
php_value session.gc_maxlifetime 1440
php_value session.save_path "/var/cpanel/php/sessions/ea-php74"
php_value upload_max_filesize 200M
php_flag zlib.output_compression Off
</IfModule>
<IfModule lsapi_module>
php_flag display_errors Off
php_value max_execution_time 30
php_value max_input_time 60
php_value max_input_vars 1000
php_value memory_limit 200M
php_value post_max_size 200M
php_value session.gc_maxlifetime 1440
php_value session.save_path "/var/cpanel/php/sessions/ea-php74"
php_value upload_max_filesize 200M
php_flag zlib.output_compression Off
</IfModule>
# END cPanel-generated php ini directives, do not edit
# BEGIN WordPress
# The directives (lines) between "BEGIN WordPress" and "END WordPress" are
# dynamically generated, and should only be modified via WordPress filters.
# Any changes to the directives between these markers will be overwritten.
<IfModule mod_rewrite.c>
RewriteEngine On
RewriteRule .* - [E=HTTP_AUTHORIZATION:%{HTTP:Authorization}]
RewriteBase /
RewriteRule ^index\.php$ - [L]
RewriteCond %{REQUEST_FILENAME} !-f
RewriteCond %{REQUEST_FILENAME} !-d
RewriteRule . /index.php [L]
</IfModule>
# END WordPress
Any ideas why this is happening? I think it is a misconfiguration when referred or a CORS policy but I can't find anything.