Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CSRF errors triggering logout if "Enable notifications" is set. #8

Open
tarcus69 opened this issue Oct 11, 2018 · 0 comments
Open

CSRF errors triggering logout if "Enable notifications" is set. #8

tarcus69 opened this issue Oct 11, 2018 · 0 comments

Comments

@tarcus69
Copy link

Hello, I and a number of other people are getting logged out of diaspora when using this, but it seems if I disable notifications, this issue goes away. The email from diaspora is as follows:

diaspora* has detected an attempt to access your session which might be unauthorised. To avoid any chance of your data being compromised, you have been signed out. Don’t worry; you can safely sign in again now.

A request has been made using a incorrect or missing CSRF token. This might be completely innocent, but it could be a cross-site request forgery (CSRF) attack.

This could have been caused by:

An add-on manipulating the request or making requests without the token;
A tab left open from a past session;
Another website making requests, with or without your permission;
Various other external tools;
Malicious code trying to access your data.
For more information on CSRF see https://www.owasp.org/index.php/Cross-SiteRequestForgery_(CSRF).

If you see this message repeatedly, please check the points above, including any browser add-ons.

Thank you, The diaspora* email robot!

Since disabling "Enable notifications" I haven't been logged out.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant