<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic CSRF Filter with Chrome! in Alfresco Archive</title>
    <link>https://connect.hyland.com/t5/alfresco-archive/csrf-filter-with-chrome/m-p/293355#M246485</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Hi guys,&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Really simple problem here I hope…&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Ive configured the CSRF filter to work and allow requests from a reverse proxy, and all is well using the override code in share-custom-config…&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;lt;config evaluator="string-compare" condition="CSRFPolicy" replace="true"&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;properties&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt; &amp;lt;token&amp;gt;Alfresco-CSRFToken&amp;lt;/token&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt; &amp;lt;referer&amp;gt;&lt;/SPAN&gt;&lt;A href="https://www.serverxx/*" rel="nofollow noopener noreferrer"&gt;https://www.serverxx/*&lt;/A&gt;&lt;SPAN&gt; etc etc &amp;lt;/referer&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt; &amp;lt;origin&amp;gt;&lt;/SPAN&gt;&lt;A href="https://www.serverxx/*" rel="nofollow noopener noreferrer"&gt;https://www.serverxx/*&lt;/A&gt;&lt;SPAN&gt; etc etc *&amp;lt;/origin&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt; &amp;lt;/properties&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp; &amp;lt;/config&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;All works wonderfully in IE, but with Chrome, the CSRF filter is triggered ALL the time. &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Does anyone know why this is, and what I can do as a workaround?!&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;many thanks.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 11 Feb 2015 18:35:27 GMT</pubDate>
    <dc:creator>t16</dc:creator>
    <dc:date>2015-02-11T18:35:27Z</dc:date>
    <item>
      <title>CSRF Filter with Chrome!</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/csrf-filter-with-chrome/m-p/293355#M246485</link>
      <description>Hi guys,Really simple problem here I hope…Ive configured the CSRF filter to work and allow requests from a reverse proxy, and all is well using the override code in share-custom-config…&amp;lt;config evaluator="string-compare" condition="CSRFPolicy" replace="true"&amp;gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;properties&amp;gt; &amp;lt;token&amp;amp;g</description>
      <pubDate>Wed, 11 Feb 2015 18:35:27 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/csrf-filter-with-chrome/m-p/293355#M246485</guid>
      <dc:creator>t16</dc:creator>
      <dc:date>2015-02-11T18:35:27Z</dc:date>
    </item>
    <item>
      <title>Re: CSRF Filter with Chrome!</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/csrf-filter-with-chrome/m-p/293356#M246486</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Have you made any progress with this?&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;(Also works in Firefox)&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Thanks.&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 24 Sep 2015 08:29:18 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/csrf-filter-with-chrome/m-p/293356#M246486</guid>
      <dc:creator>idwright</dc:creator>
      <dc:date>2015-09-24T08:29:18Z</dc:date>
    </item>
    <item>
      <title>Re: CSRF Filter with Chrome!</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/csrf-filter-with-chrome/m-p/293357#M246487</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Has anyone been able to resolve this?&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Thanks&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Nov 2015 17:50:10 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/csrf-filter-with-chrome/m-p/293357#M246487</guid>
      <dc:creator>thamilanga</dc:creator>
      <dc:date>2015-11-09T17:50:10Z</dc:date>
    </item>
    <item>
      <title>Re: CSRF Filter with Chrome!</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/csrf-filter-with-chrome/m-p/293358#M246488</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Hi folks,&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;we are having the exactly same problem here. We are using Alfresco Community 5.1 with Alfresco Share behind an nginx used as SSL offloader. The CSRF filter is triggered always when using Chrome (OSX, Linux, Windows) or Safari (OSX) or Chromium or Epiphany (both on Linux). The filter is not triggered (i.e. Share web access works) when using IE11 or Edge on Windows 10 respectively IE11 on Windows 7. There are also no problems with Firefox (OSX, Linux, Windows), so Firefox can be used as a workaround. Our working hypothesis is thus, that the problem is somehow tied to Webkit based browsers.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Can anybody confirm (or disprove) this hypothesis or can shed some more light on the issue?&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Best regards, V. Mayer&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Jul 2016 14:09:26 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/csrf-filter-with-chrome/m-p/293358#M246488</guid>
      <dc:creator>vmayer</dc:creator>
      <dc:date>2016-07-13T14:09:26Z</dc:date>
    </item>
    <item>
      <title>Re: CSRF Filter with Chrome!</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/csrf-filter-with-chrome/m-p/293359#M246489</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Hi folks,&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I just wanted to share my solution, even though I haven't explored further why this makes a difference. Below you can find a snippet from my share-config-custom.xml:&lt;/SPAN&gt;&lt;BR /&gt;&lt;PRE class="language-none line-numbers"&gt;&lt;CODE&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;properties&amp;gt;&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;!– There is normally no need to override this property –&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;token&amp;gt;Alfresco-CSRFToken&amp;lt;/token&amp;gt;&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;!–&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Override and set this property with a regexp that if you have placed Share behind a proxy that&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; does not rewrite the Referer header.&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; –&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;referer&amp;gt;&lt;A href="https://myserver.mysld.tld/share/.*" rel="nofollow noopener noreferrer"&gt;https://myserver.mysld.tld/share/.*&lt;/A&gt;&amp;lt;/referer&amp;gt;&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;!–&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Override and set this property with a regexp that if you have placed Share behind a proxy that&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; does not rewrite the Origin header.&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; –&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;origin&amp;gt;&lt;A href="https://myserver.mysld.tld" rel="nofollow noopener noreferrer"&gt;https://myserver.mysld.tld&lt;/A&gt;&amp;lt;/origin&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;/properties&amp;gt;&lt;BR /&gt;&lt;SPAN class="line-numbers-rows"&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/PRE&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;It didn't work as described before, if there still was a trailing slash (or anything more than that) in the origin element. Initially I had the identical content in the origin element as&amp;nbsp; the one in the referer element. After deleting everything after the server name including the slash in the URL within the origin element resulting in the snippet above, all problems were gone.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Best regards, V. Mayer&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Jul 2016 13:50:18 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/csrf-filter-with-chrome/m-p/293359#M246489</guid>
      <dc:creator>vmayer</dc:creator>
      <dc:date>2016-07-28T13:50:18Z</dc:date>
    </item>
  </channel>
</rss>

