Forms are broken on landfill due to CSRF

RESOLVED FIXED in Q2 2011

Status

addons.mozilla.org Graveyard
Code Quality
RESOLVED FIXED
7 years ago
2 years ago

People

(Reporter: clouserw, Assigned: clouserw)

Tracking

unspecified
Q2 2011

Details

(Assignee)

Description

7 years ago
We've got a couple open bugs with the new CSRF system which I hope fixes this for free, but I don't want this to get lost so I'm filing.

Any form interaction on landfill is busted - logging in is the easiest example.  Oddly (as in, we should figure out why) occasionally if I refresh the POST to log in it lets me in on the second try.
Anonymous CSRF depends on the cache. Do you have memcached over there?

I'm guessing you can't tell whether this is broken on logged-in forms.
(Assignee)

Comment 2

7 years ago
(In reply to comment #1)
> Anonymous CSRF depends on the cache. Do you have memcached over there?

I will in a second!

> I'm guessing you can't tell whether this is broken on logged-in forms.

It fails the same way when logged in.  I can also bypass it by refreshing the POST.
(Assignee)

Comment 3

7 years ago
memcache fixed me up, good call sir!
Status: NEW → RESOLVED
Last Resolved: 7 years ago
Resolution: --- → FIXED
Product: addons.mozilla.org → addons.mozilla.org Graveyard
You need to log in before you can comment on or make changes to this bug.