cross site forgery blocked

Hi,

I am trying to add the text to the multilingual options and after typing in the text and saving it I got a red banner saying

Save request cross site forgery blocked. and it removed all my text and went back to the admin overview page.

I also just tried to reset my setup log and got another reference to cross site forgery blocked where it ignored my request and went to the admin overview page.

I have never seen this type of message before what does it mean?

It does not hang around for long so it is tricky to geta screenshot of it.

Cheers
Steve

Comments

  • acrylian Administrator, Developer
    See here about what CSF is: http://en.wikipedia.org/wiki/Cross-site_request_forgery

    So in simple words: This is a security check to prevent people not allowed to post any data on the backend. On any submit of content a token is passed that is checked. If they don't match it is blocked.

    If you are normally logged in that should not happen. Where exactly did it happen? What exactly did you do?
  • Didn't do anything to be honest, I logged in as administrator same as normal then enabled multilingual and started populating the translation fields. Sometimes it accepted my save changes and sometimes it didn't.

    Anyway I just redownloaded the master and uploaded zp-core and then ran setup and all seems ok now apart from the setup log is telling me to check all the files from all the themes.

    If it happens again I will try and get a screenshot.
  • acrylian Administrator, Developer
    Ok, please do so.

    all seems ok now apart from the setup log is telling me to check all the files from all the themes.
    Which is as expected as they don't match the file dates of zp-core.
Sign In or Register to comment.