Firewall rule to "Allow" an URL not working


I created a firewall rule to allow a specific URL and prevent it to block users.

I put this rule at position #1 but users are still blocked when submitting forms.

Anything wrong?

Thank you

You should see entries in the Firewall Events Activity Log. Clicking on a log entry should show you the setting that blocked it.

If you clicked on it, you’d probably get more information on the WAF setting that triggered the block.

Rule message: XSS - JavaScript URI

Rule group: Cloudflare Specials

Looks to be from:

But I thought firewall rules will prevent any other rule to be triggered by cloudflare?

I suppose, I have to do this instead of allow?

That sounds like a good idea. Hopefully that fixes it.

