<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CSRFFilter error in catalina.out in Alfresco Archive</title>
    <link>https://connect.hyland.com/t5/alfresco-archive/csrffilter-error-in-catalina-out/m-p/278695#M231825</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;I have reviewed all the tabs of that JIRA issue, and I can't find any identification of WHICH files were updated to fix this.&amp;nbsp; I would've thought this would be documented somewhere in one of the "Work Log" or "Activity" tabs.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;It references some kind of "list" that specifies POST requests not requiring this security.&amp;nbsp; That would be interesting too (and might be the source code I'm looking for).&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Thanks again for all the pointers.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;-AJ&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;PS: I probably posted this in the "End Users" section of the forum erroneously.&amp;nbsp; It's probably more apt for the Developers Discussions (in case any forum mods are looking and want to move this).&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 22 Feb 2013 16:19:39 GMT</pubDate>
    <dc:creator>aweber1nj</dc:creator>
    <dc:date>2013-02-22T16:19:39Z</dc:date>
    <item>
      <title>CSRFFilter error in catalina.out</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/csrffilter-error-in-catalina-out/m-p/278691#M231821</link>
      <description>Running some tests with 4.2.d, and we have a web proxy in front of tomcat on linux.&amp;nbsp; When we tried to use the default action to start a workflow, it threw this CSRFTokenFilter error: "Possible CSRF attack noted when comparing token in session and request header…"Is there a specific header that maybe</description>
      <pubDate>Fri, 15 Feb 2013 01:48:58 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/csrffilter-error-in-catalina-out/m-p/278691#M231821</guid>
      <dc:creator>aweber1nj</dc:creator>
      <dc:date>2013-02-15T01:48:58Z</dc:date>
    </item>
    <item>
      <title>Re: CSRFFilter error in catalina.out</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/csrffilter-error-in-catalina-out/m-p/278692#M231822</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Hello,&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Is it the same problem as described here?:&lt;/SPAN&gt;&lt;BR /&gt;&lt;A href="https://issues.alfresco.com/jira/browse/ALF-17872" rel="nofollow noopener noreferrer"&gt;https://issues.alfresco.com/jira/browse/ALF-17872&lt;/A&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Feb 2013 10:04:17 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/csrffilter-error-in-catalina-out/m-p/278692#M231822</guid>
      <dc:creator>scouil</dc:creator>
      <dc:date>2013-02-22T10:04:17Z</dc:date>
    </item>
    <item>
      <title>Re: CSRFFilter error in catalina.out</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/csrffilter-error-in-catalina-out/m-p/278693#M231823</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;However, that issue indicates it's fixed in 4.1.4, and I'm reporting this issue against 4.2 (Community).&amp;nbsp; So it may have re-appeared.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Either way, the JIRA article doesn't tell me WHY it is happening or give any information about how to fix it or pass any necessary headers that the servlet filter might be looking for.&amp;nbsp; And I still can't find the source code for that filter, or I might be a little further along.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Thanks,&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;AJ&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Feb 2013 13:56:27 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/csrffilter-error-in-catalina-out/m-p/278693#M231823</guid>
      <dc:creator>aweber1nj</dc:creator>
      <dc:date>2013-02-22T13:56:27Z</dc:date>
    </item>
    <item>
      <title>Re: CSRFFilter error in catalina.out</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/csrffilter-error-in-catalina-out/m-p/278694#M231824</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Hello aweber,&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Actually I don't think it's a regression. It was fixed about 2 weeks ago and may not have been ported to the community version code yet.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;And no, it doesn't directly tell you how to fix it.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;However what it does tell you:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;- It's the expected behavior that the POST request is sent without token. The bug is in Alfresco where the server shouldn't require it.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;- It has been fixed in revision r46356 on HEAD&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Starting from here, you can try to run a diff on r46356 and the previous version to see what have changed and see if you can produce a patch for your own version.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;But all this is if it's actually the same problem.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;If not you can still try to bypass your web proxy and directly reach your Alfresco server to see if your problem lies in your proxy configuration.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Good luck fixing your problem.&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Feb 2013 14:26:42 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/csrffilter-error-in-catalina-out/m-p/278694#M231824</guid>
      <dc:creator>scouil</dc:creator>
      <dc:date>2013-02-22T14:26:42Z</dc:date>
    </item>
    <item>
      <title>Re: CSRFFilter error in catalina.out</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/csrffilter-error-in-catalina-out/m-p/278695#M231825</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;I have reviewed all the tabs of that JIRA issue, and I can't find any identification of WHICH files were updated to fix this.&amp;nbsp; I would've thought this would be documented somewhere in one of the "Work Log" or "Activity" tabs.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;It references some kind of "list" that specifies POST requests not requiring this security.&amp;nbsp; That would be interesting too (and might be the source code I'm looking for).&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Thanks again for all the pointers.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;-AJ&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;PS: I probably posted this in the "End Users" section of the forum erroneously.&amp;nbsp; It's probably more apt for the Developers Discussions (in case any forum mods are looking and want to move this).&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Feb 2013 16:19:39 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/csrffilter-error-in-catalina-out/m-p/278695#M231825</guid>
      <dc:creator>aweber1nj</dc:creator>
      <dc:date>2013-02-22T16:19:39Z</dc:date>
    </item>
    <item>
      <title>Re: CSRFFilter error in catalina.out</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/csrffilter-error-in-catalina-out/m-p/278696#M231826</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Hello,&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Actually it is documented. He told you the revision it was fixed.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Now if you browse Alfresco svn log you'll see:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;r46356&amp;nbsp;&amp;nbsp;&amp;nbsp; ewinlof&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013/02/07 2:42:39PM&amp;nbsp;&amp;nbsp;&amp;nbsp; Fixed ALF-17872 "A user cannot start a workflow in Share UI." - Added start workflow to the list of POST requests that does NOT require a token (since it isn't a state changing request)&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;The only modified file is:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;/alfresco/HEAD/root/projects/slingshot/config/alfresco/share-config.xml&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;This corresponds to:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;lt;tomcat home&amp;gt;/webapps/share/WEB-INF/classes/alfresco/share-config.xml&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I've attached the diff of what have been modified this version (renamed as txt of this forum wouldn't let me upload it)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;The full file in its current version can be seen here: &lt;/SPAN&gt;&lt;A href="http://svn.alfresco.com/repos/alfresco-open-mirror/alfresco/HEAD/root/projects/slingshot/config/alfresco/share-config.xml" rel="nofollow noopener noreferrer"&gt;http://svn.alfresco.com/repos/alfresco-open-mirror/alfresco/HEAD/root/projects/slingshot/config/alfresco/share-config.xml&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Good luck with your patching &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://connect.hyland.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 25 Feb 2013 07:55:09 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/csrffilter-error-in-catalina-out/m-p/278696#M231826</guid>
      <dc:creator>scouil</dc:creator>
      <dc:date>2013-02-25T07:55:09Z</dc:date>
    </item>
  </channel>
</rss>

