grouper-users - [grouper-users] Grouper UI CSRF error -- required token is missing from the request
Subject: Grouper Users - Open Discussion List
List archive
[grouper-users] Grouper UI CSRF error -- required token is missing from the request
Chronological Thread
- From: Shaun Koh <>
- To: "" <>
- Subject: [grouper-users] Grouper UI CSRF error -- required token is missing from the request
- Date: Thu, 3 Nov 2016 04:21:38 +0000
- Accept-language: en-US, en-NZ
- Ironport-phdr: 9a23:oAaD3RFu+Mafiwt5CjPtg51GYnF86YWxBRYc798ds5kLTJ75oM+wAkXT6L1XgUPTWs2DsrQf2rCQ4/2rAzVIyK3CmUhKSIZLWR4BhJdetC0bK+nBN3fGKuX3ZTcxBsVIWQwt1Xi6NU9IBJS2PAWK8TWM5DIfUi/yKRBybrysXNWD1YLniqvootX6WEZhvHKFe7R8LRG7/036l/I9ps9cEJs30QbDuXBSeu5blitCLFOXmAvgtI/rpMYwu3cYh/V0vcFaVrjicr59UKdVFi8OMmYp6dftuAWZCwaD+zFUBmoMlQdQDhKA8Qr3RIzZsy3mu/B71TXAe8D6UOZndy6l6vJQSBb1jm8kMD5xpHrXg9F2yqFcoDqouhd8x4fSbMecP7x4bPWOLpshWWNdU5MJBGR6CYSmYt5XAg==
Hi there, We’ve run into an error when attempting to access the UI that says `Maybe your session timed out and you need to start again. This should not happen under normal operation. CSRF error.`. We use Shibb SSO for our authN and from the debug/error logs, it seems that users are being successfully matched against subjects in the DB though the redirect to /grouper/grouperUi is being marked as a potential CSRF attack apparently
due to missing token in the request: 2016-11-03 17:02:40,432: [http-8080-3] DEBUG GrouperUiFilter.remoteUser(638) - - httpServletRequest.getRemoteUser(): null, UOAid header: ${some_user_id}, remoteUser overall: ${some_user_id}, 2016-11-03 17:02:40,433: [http-8080-3] INFO EventLog.info(156) - - [ccc13c1558c14e6f8d9eb7bb0892c8ac,'GrouperSystem','application'] session: start (1ms) 2016-11-03 17:02:40,433: [http-8080-3] INFO CsrfGuardLogger.log(26) - - CsrfGuard analyzing request /grouper/index.jsp 2016-11-03 17:02:40,481: [http-8080-3] INFO CsrfGuardLogger.log(26) - - CsrfGuard analyzing request /grouper/grouperUi 2016-11-03 17:02:40,482: [http-8080-3] ERROR CsrfGuardLogger.log(47) - - potential cross-site request forgery (CSRF) attack thwarted (user:<anonymous>, ip:${some_ip}, method:GET, uri:/grouper/grouperUi, error:required token is missing
from the request) I’ve had a look at similar threads in the mailing lists though none of the solutions worked for us. Also, this only happens in our DEV environment and not TEST which worked seamlessly until 2-3 days ago. -- I do not recall us making any changes that may have caused this issue. Any help or suggestions would be much appreciated. Best Regards, Shaun K. |
- [grouper-users] Grouper UI CSRF error -- required token is missing from the request, Shaun Koh, 11/03/2016
- [grouper-users] RE: Grouper UI CSRF error -- required token is missing from the request, Hyzer, Chris, 11/03/2016
- [grouper-users] RE: Grouper UI CSRF error -- required token is missing from the request, Shaun Koh, 11/03/2016
- Re: [grouper-users] Grouper UI CSRF error -- required token is missing from the request, Jeffrey Eaton, 11/03/2016
- RE: [grouper-users] Grouper UI CSRF error -- required token is missing from the request, Shaun Koh, 11/03/2016
- Re: [grouper-users] Grouper UI CSRF error -- required token is missing from the request, Waldbieser, Carl, 11/04/2016
- Re: [grouper-users] Grouper UI CSRF error -- required token is missing from the request, Hyzer, Chris, 11/04/2016
- RE: [grouper-users] Grouper UI CSRF error -- required token is missing from the request, Hyzer, Chris, 11/05/2016
- Re: [grouper-users] Grouper UI CSRF error -- required token is missing from the request, Hyzer, Chris, 11/04/2016
- Re: [grouper-users] Grouper UI CSRF error -- required token is missing from the request, Waldbieser, Carl, 11/04/2016
- RE: [grouper-users] Grouper UI CSRF error -- required token is missing from the request, Shaun Koh, 11/03/2016
- Re: [grouper-users] Grouper UI CSRF error -- required token is missing from the request, Jeffrey Eaton, 11/03/2016
- [grouper-users] RE: Grouper UI CSRF error -- required token is missing from the request, Shaun Koh, 11/03/2016
- [grouper-users] RE: Grouper UI CSRF error -- required token is missing from the request, Hyzer, Chris, 11/03/2016
Archive powered by MHonArc 2.6.19.