We see a 403 Forbidden when clicking on "Drag a component". It can be simulated in AEM OOTB
Env: probably any but using macOS mojave 10.14.6
Browser: Chrome Version 84.0.4147.89 (Official Build) (64-bit)
Click on the "Drag a component" that is present above the footer
Check the console log and network log
there will be a redirection and we get
http://localhost:4512/mnt/overlay/wcm/core/content/editor/_jcr_content/content/items/content/content/items/styleselector.form.html/content/we-retail/us/en/about-us/_jcr_content/root/responsivegrid/*/ 403 (Forbidden)
Sling will have no idea how to resolve */
But what you're seeing is a non-issue, the asterisk is used as some selector in the front end and try adding a trailing / to any path it will also 403.
How are you impacted by this specifically?
Verified on 6.4 instance. Looks fine for me.
Please do double check if the user has create/modify permission.
Can you confirm if you have permission (read, write, modify, delete) enabled for this path /content/we-retail/us/en/about-us/?