non-recognised security token

Post

Posted
Rating:
#1184 (In Topic #256)
Avatar
Standard member
Paul Flavel is in the usergroup ‘Honoured member’
I am getting the following error in admin. I am able to explore the admin area, but as soon as I try to save a setting i get:
  I have cleared the cache, both server side and browser. rebooted server. Waited a couple of hours, to see if the token refreshes. Nothing seems to fix it.
Even placed the website into safe mode, didn't fix the error.

Any ideas? Unable to do anything in the admin area. Actually I can't do anything on the site at all.

I then went and tried to register another name and get the following after accepting my sites terms.

A POST request was made with a non-recognised security token; this has been blocked as it represents a security threat.

Last edit: by Paul Flavel

Online now: No Back to the top

Post

Posted
Rating:
#1185
Avatar
Site director
Chris Graham is in the usergroup ‘Administrators’
Hi,

It's a weird one. It may be something to do with ModSecurity or Suhosin altering the requests, or our workaround to that being incompatible with our POST token security somehow.

Is it possible I could get admin access to the install to run some tests?

If so please email me at chris@ocproducts.com and I'll make sure whatever it is is resolved.

Best,
Chris


Become a fan of Composr on Facebook or add me as a friend. Add me on on Mastodon. Follow me on Minds (where I am most active). Support me on Patreon

Was I helpful?
  • If not, please let us know how we can do better (please try and propose any bigger ideas in such a way that they are fundable and scalable).
  • If so, please let others know about Composr whenever you see the opportunity or support me on Patreon.
  • If my reply is too Vulcan or expressed too much in business-strategy terms, and not particularly personal, I apologise. As a company & project maintainer, time is very limited to me, so usually when I write a reply I try and make it generic advice to all readers. I'm also naturally a joined-up thinker, so I always express my thoughts in combined business and technical terms. I recognise not everyone likes that, don't let my Vulcan-thinking stop you enjoying Composr on fun personal projects.
  • If my response can inspire a community tutorial, that's a great way of giving back to the project as a user.
Online now: No Back to the top

Post

Posted
Rating:
#1186
Avatar
Standard member
Paul Flavel is in the usergroup ‘Honoured member’
I had a backup which was only 6 hours old, so I ended up restoring it.
Everything seems ok for the moment. Hopefully it was a once off glitch.

Thankyou very much for the offer, if it happens again I will send through the details.
Online now: No Back to the top

Post

Posted
Rating:
#1211
Avatar
Site director
Chris Graham is in the usergroup ‘Administrators’
I believe I've resolved this one now. The session_cookie option is generated at install, and ends up in the compiled JavaScript files. If somehow old compiled JS files from another install are read (e.g. through browser cache, or accidental replacement), it will not match up the cookie name, so fail to get the session ID, so JavaScript will fail to be able to get the correct post token. It only affects certain areas that use JavaScript to generate the post token, like the config. It will be resolved in the next RC, as we'll generate the session_cookie option based on site URL rather than randomly.


Become a fan of Composr on Facebook or add me as a friend. Add me on on Mastodon. Follow me on Minds (where I am most active). Support me on Patreon

Was I helpful?
  • If not, please let us know how we can do better (please try and propose any bigger ideas in such a way that they are fundable and scalable).
  • If so, please let others know about Composr whenever you see the opportunity or support me on Patreon.
  • If my reply is too Vulcan or expressed too much in business-strategy terms, and not particularly personal, I apologise. As a company & project maintainer, time is very limited to me, so usually when I write a reply I try and make it generic advice to all readers. I'm also naturally a joined-up thinker, so I always express my thoughts in combined business and technical terms. I recognise not everyone likes that, don't let my Vulcan-thinking stop you enjoying Composr on fun personal projects.
  • If my response can inspire a community tutorial, that's a great way of giving back to the project as a user.
Online now: No Back to the top

Post

Posted
Rating:
#1212
Avatar
Standard member
Paul Flavel is in the usergroup ‘Honoured member’
Excellent work. Thankyou Chris.
Online now: No Back to the top
1 guest and 0 members have just viewed this.

Statistics

Forum statistics:
  • 2,052 topics, 7,195 posts, 10,830 members
  • Our newest member is Customcollective
Back to Top