<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Alfresco cookie Alfresco-CSRF Token in Alfresco Forum</title>
    <link>https://connect.hyland.com/t5/alfresco-forum/alfresco-cookie-alfresco-csrf-token/m-p/483457#M39428</link>
    <description>&lt;P&gt;Hi &lt;a href="https://connect.hyland.com/t5/user/viewprofilepage/user-id/37534"&gt;@cco&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;I have same problem. Can you tell please what kind of configuration was done in apache file?&lt;/P&gt;</description>
    <pubDate>Thu, 17 Oct 2024 11:35:33 GMT</pubDate>
    <dc:creator>href</dc:creator>
    <dc:date>2024-10-17T11:35:33Z</dc:date>
    <item>
      <title>Alfresco cookie Alfresco-CSRF Token</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/alfresco-cookie-alfresco-csrf-token/m-p/7029#M3380</link>
      <description>Hi all,I am using JMeter (v2.9) to test performance of application based on Alfresco(v5.0.3).I can not get cookie Alfresco-CSRF Token.By viewing request in Firefox tools, Alfresco-CSRF Token is given in the Response Header in the request GET /share/page following the request POST /share/page/login.W</description>
      <pubDate>Tue, 18 Apr 2017 10:19:17 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/alfresco-cookie-alfresco-csrf-token/m-p/7029#M3380</guid>
      <dc:creator>cco</dc:creator>
      <dc:date>2017-04-18T10:19:17Z</dc:date>
    </item>
    <item>
      <title>Re: Alfresco cookie Alfresco-CSRF Token</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/alfresco-cookie-alfresco-csrf-token/m-p/7030#M3381</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;not sure if missed something in your description - the client, in your case jmeter, must have a mechanism to receive and store the cookies. &amp;nbsp;Is your jmeter cookie manager enabled and have set CookieManager.save.cookies=true?&lt;/P&gt;&lt;P&gt;Did you follow articles that describe jmeters use in the context of CSRF protection (i.e. &lt;A class="link-titled" href="https://www.blazemeter.com/blog/how-load-test-csrf-protected-web-sites" title="https://www.blazemeter.com/blog/how-load-test-csrf-protected-web-sites" rel="nofollow noopener noreferrer"&gt;How to Load Test CSRF-Protected Web Sites | BlazeMeter&lt;/A&gt;&amp;nbsp;)?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;or tried to just turn off or configure the Alfresco CSRF protection temporarily?&amp;nbsp;&lt;A class="link-titled" href="http://docs.alfresco.com/community/concepts/csrf-policy.html" title="http://docs.alfresco.com/community/concepts/csrf-policy.html" rel="nofollow noopener noreferrer"&gt;Cross-Site Request Forgery (CSRF) filters | Alfresco Documentation&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Apr 2017 16:49:58 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/alfresco-cookie-alfresco-csrf-token/m-p/7030#M3381</guid>
      <dc:creator>mehe</dc:creator>
      <dc:date>2017-04-18T16:49:58Z</dc:date>
    </item>
    <item>
      <title>Re: Alfresco cookie Alfresco-CSRF Token</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/alfresco-cookie-alfresco-csrf-token/m-p/7031#M3382</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Martin,&lt;/P&gt;&lt;P&gt;In Jmeter, Cookie Manager is used. But unfortunaly, no cookie CSRF was present in response header. So no parsing was possible.&lt;/P&gt;&lt;P&gt;The problem was that 3 servers ECM, SHARE and SolR sent your own header and i got JSESSIONID cookie instead of CSRF cookie.&lt;/P&gt;&lt;P&gt;It was resolved by changing apache configuration.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Apr 2017 08:09:35 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/alfresco-cookie-alfresco-csrf-token/m-p/7031#M3382</guid>
      <dc:creator>cco</dc:creator>
      <dc:date>2017-04-19T08:09:35Z</dc:date>
    </item>
    <item>
      <title>Re: Alfresco cookie Alfresco-CSRF Token</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/alfresco-cookie-alfresco-csrf-token/m-p/7032#M3383</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The GET on /share/page should redirect you with a 302 response to the actual starting page, normally the user dashboard. The GET for the user dashboard should then provide you with the CSRF token, as these are generated on each page rendition request.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Apr 2017 08:24:04 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/alfresco-cookie-alfresco-csrf-token/m-p/7032#M3383</guid>
      <dc:creator>afaust</dc:creator>
      <dc:date>2017-04-19T08:24:04Z</dc:date>
    </item>
    <item>
      <title>Re: Alfresco cookie Alfresco-CSRF Token</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/alfresco-cookie-alfresco-csrf-token/m-p/7033#M3384</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sorry bothering you with the basic stuff, but it's sometimes hard to see how deep the analysis of the problem went before &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://connect.hyland.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&amp;nbsp;glad to hear you've got it working&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Apr 2017 08:27:58 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/alfresco-cookie-alfresco-csrf-token/m-p/7033#M3384</guid>
      <dc:creator>mehe</dc:creator>
      <dc:date>2017-04-19T08:27:58Z</dc:date>
    </item>
    <item>
      <title>Re: Alfresco cookie Alfresco-CSRF Token</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/alfresco-cookie-alfresco-csrf-token/m-p/483457#M39428</link>
      <description>&lt;P&gt;Hi &lt;a href="https://connect.hyland.com/t5/user/viewprofilepage/user-id/37534"&gt;@cco&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;I have same problem. Can you tell please what kind of configuration was done in apache file?&lt;/P&gt;</description>
      <pubDate>Thu, 17 Oct 2024 11:35:33 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/alfresco-cookie-alfresco-csrf-token/m-p/483457#M39428</guid>
      <dc:creator>href</dc:creator>
      <dc:date>2024-10-17T11:35:33Z</dc:date>
    </item>
  </channel>
</rss>

