Skip to content

Conversation

@blizzz
Copy link
Member

@blizzz blizzz commented Feb 16, 2023

backport of #35419

If CSRF fails but the user is logged in that they probably logged in in
another tab. This is fine. We can just redirect.
If CSRF fails and the user is also not logged in then something is
fishy. E.g. because Nextcloud contantly regenrates the session and the
CSRF token and the user is stuck in an endless login loop.

Signed-off-by: Christoph Wurst <[email protected]>
@blizzz blizzz added bug 3. to review Waiting for reviews labels Feb 16, 2023
@blizzz blizzz requested review from a team, ArtificialOwl, ChristophWurst, artonge, come-nc, icewind1991 and szaimen and removed request for a team February 16, 2023 08:44
@blizzz blizzz added 4. to release Ready to be released and/or waiting for tests to finish and removed 3. to review Waiting for reviews labels Feb 16, 2023
@szaimen szaimen closed this Mar 14, 2023
@blizzz blizzz reopened this Mar 14, 2023
@blizzz blizzz merged commit d78baf4 into stable23 Mar 14, 2023
@blizzz blizzz deleted the backport/35419/stable23 branch March 14, 2023 13:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

4. to release Ready to be released and/or waiting for tests to finish bug

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants