Diagrams have poor usability still in 21.x LTS due CSRF and ticket expiration
- Status
- Closed
- Subject
- Diagrams have poor usability still in 21.x LTS due CSRF and ticket expiration
- Version
- 21.x
22.x - Category
- Bug
- Conflict of two features (each works well independently)
- Usability
- Feature
- Diagram (Drawings, Diagrams, Flowcharts and more)
Edit interface (UI) - Resolution status
- Fixed or Solved
- Submitted by
- Xavier de Pedro
- Keep informed
- lindon, Marc Laporte, Jorge Sá Pereira
- Lastmod by
- Xavier de Pedro
- Rating
- Related-to
-
- PluginDiagram not showing diagram if file stored in file gallery
- CSRF False positives
- Potential cross-site request forgery (CSRF) detected. Operation blocked. Required headers are missing.
- "The following mandatory fields are missing: Category" after anti-CSRF prompt
- Voting in a poll gives CSRF warning.
- Description
We have been experiencing in our team at work several issues while attempting to use Tiki Diagrams in production in Tiki 21.x LTS
There might be 2 related (for the end user) issues. It seems as if some ticket expires too soon and some error related to CSRF is shown. Maybe after editing the diagram for more than 20 minutes or so (even if Tiki is set to remember the login for days or weeks, which seems to work when we are not using the diagram feature).
Diagrams are created to store their contents in a wiki page (because in file gallery we face some other issue still, as reported in another bug report)
2 error messages are shown in similar conditions (unclear yet the exact difference; these reports were sent by work colleagues of mine, so far)
Error message 1:"An error occurred, please try again.
Potential cross-site request forgery (CSRF) detected. Operation blocked. Reloading the page may help."Error message 2:
"An error occurred, please try again.
Potential cross-site request forgery (CSRF) detected. Operation blocked. Ticket has expired. Reload the page"In case it matters: the https certificate seems to be not recognized (by the browser used to reproduce the issue) as valid.
- Solution
- we don't see this issue since many months ago (in that updated tiki21 site)
- Importance
- 7
- Easy to solve?
- 3
- Priority
- 21
- Demonstrate Bug on Tiki 19+
-
This bug has been demonstrated on show2.tiki.org
Please demonstrate your bug on show2.tiki.org
Show.tiki.org is not configured properlyThe public/private keys configured to connect to show2.tiki.org were not accepted. Please make sure you are using RSA keys. Thanks.
- Demonstrate Bug (older Tiki versions)
-
This bug has been demonstrated on show.tikiwiki.org
Please demonstrate your bug on show.tikiwiki.org
Show.tiki.org is not configured properlyThe public/private keys configured to connect to show.tikiwiki.org were not accepted. Please make sure you are using RSA keys. Thanks.
- Ticket ID
- 7547
- Created
- Monday 28 September, 2020 12:07:35 UTC
by Xavier de Pedro - LastModif
- Thursday 05 August, 2021 21:06:18 UTC