Skip to content

Conversation

@blizzz
Copy link
Member

@blizzz blizzz commented Feb 16, 2023

backport of #35419

If CSRF fails but the user is logged in that they probably logged in in
another tab. This is fine. We can just redirect.
If CSRF fails and the user is also not logged in then something is
fishy. E.g. because Nextcloud contantly regenrates the session and the
CSRF token and the user is stuck in an endless login loop.

Signed-off-by: Christoph Wurst <[email protected]>
@blizzz blizzz added bug 3. to review Waiting for reviews labels Feb 16, 2023
@blizzz blizzz added this to the Nextcloud 24.0.11 milestone Feb 16, 2023
@blizzz blizzz mentioned this pull request Mar 13, 2023
@blizzz blizzz merged commit 0a9f73c into stable24 Mar 15, 2023
@blizzz blizzz deleted the backport/35419/stable24 branch March 15, 2023 13:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

3. to review Waiting for reviews bug

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants