Uploaded image for project: 'Community Platforms'
  1. Community Platforms
  2. COM-19886

Admin login fails with missing CSRF token

    XMLWordPrintable

Details

    • Icon: Bug Bug
    • Resolution: Invalid
    • Icon: High High
    • None
    • None
    • login
    • None

    Description

      When trying to login on `/ez` I get the following error: `User does not have access to '' 'Missing or invalid CSRF token'` - this affects one particular build, but not other builds of the eZ Platform.

      Payload sent:
      ```
      {"SessionInput":{"login":"admin","password":"publish"}}
      ```

      Error received:
      ```
      {
      "ErrorMessage": {
      "_media-type": "application\/vnd.ez.api.ErrorMessage+json",
      "errorCode": 401,
      "errorMessage": "Unauthorized",
      "errorDescription": "User does not have access to '' 'Missing or invalid CSRF token'",
      "trace": "#0 [internal function]: eZ\\Publish\\Core\\REST\\Server\\Controller\\User->createSession(Object(Symfony\\Component\\HttpFoundation\\Request))\n#1 \/app\/vendor\/symfony\/symfony\/src\/Symfony\/Component\/HttpKernel\/HttpKernel.php(139): call_user_func_array(Array, Array)\n#2 \/app\/vendor\/symfony\/symfony\/src\/Symfony\/Component\/HttpKernel\/HttpKernel.php(62): Symfony\\Component\\HttpKernel\\HttpKernel->handleRaw(Object(Symfony\\Component\\HttpFoundation
      Request), 1)\n#3 \/app\/vendor\/symfony\/symfony\/src\/Symfony\/Component\/HttpKernel\/DependencyInjection\/ContainerAwareHttpKernel.php(69): Symfony\\Component\\HttpKernel\\HttpKernel->handle(Object(Symfony\\Component\\HttpFoundation
      Request), 1, true)\n#4 \/app\/vendor\/symfony\/symfony\/src\/Symfony\/Component\/HttpKernel\/Kernel.php(184): Symfony\\Component\\HttpKernel\\DependencyInjection\\ContainerAwareHttpKernel->handle(Object(Symfony\\Component\\HttpFoundation
      Request), 1, true)\n#5 \/app\/web\/app.php(66): Symfony\\Component\\HttpKernel\\Kernel->handle(Object(Symfony\\Component\\HttpFoundation\\Request))\n#6

      {main}

      ",
      "file": "\/app\/vendor\/ezsystems\/ezpublish-kernel\/eZ\/Publish\/Core\/REST\/Server\/Controller\/User.php",
      "line": 1000
      }
      }
      ```

      Attachments

        Activity

          People

            Unassigned Unassigned
            mmatulka@inviqa.com mmatulka@inviqa.com
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: