Skip to content

Development Proxy

403 Errors

The PSI development instance (https://discovery.development.psi.ch) is accessible only from restricted networks. Connecting from a disallowed IP address returns a 403 error.

Example 403 Forbidden error

To resolve this, connect through an allowed system. For operators, the recommended approach is to configure a SOCKS5 proxy.

Intended audience

This guide is for operators testing the Ingestor against the development SciCat instance at https://discovery.development.psi.ch.

Prerequisites

You need SSH access to an allowed server, usually the Ingestor server, which PSI should already have whitelisted.

Start the proxy

SSH from the command line

If you can connect to the Ingestor with SSH, start a SOCKS5 proxy with the -D option:

ssh -D 9999 ingestor.example.com

Alternatively, configure it in ~/.ssh/config so it starts automatically when you connect to the Ingestor:

Host ingestor.example.com
    DynamicForward 9999

PuTTY (Windows)

When using PuTTY, add D9999 in Connection → SSH → Tunnels. See the PuTTY documentation.

Enable the proxy in your browser

Configure your browser to use the SOCKS5 proxy. The recommended option is the FoxyProxy extension, available for Firefox, Chrome, and Edge.

After installing the extension, add a proxy with these values:

Setting Value
Title OpenEM
Type SOCKS5
Hostname localhost
Port 9999

Enable the proxy after adding it. The FoxyProxy menu-bar icon should be coloured to match the OpenEM proxy entry.

Testing

Open https://discovery.development.psi.ch. A successful connection confirms that the proxy is active.