Bug 43712 - school installer fails on Cross Site Request Forgery attack detected. Please provide the UMCSessionId cookie value as HTTP request header X-Xsrf-Protection
school installer fails on Cross Site Request Forgery attack detected. Please ...
Status: CLOSED DUPLICATE of bug 42114
Product: UCS@school
Classification: Unclassified
Component: UMC - Installer
UCS@school 4.2
Other Linux
: P5 normal (vote)
: ---
Assigned To: UCS@school maintainers
:
Depends on: 43711
Blocks:
  Show dependency treegraph
 
Reported: 2017-03-03 11:25 CET by Daniel Tröder
Modified: 2023-06-12 15:39 CEST (History)
1 user (show)

See Also:
What kind of report is it?: Bug Report
What type of bug is this?: 6: Setup Problem: Issue for the setup process
Who will be affected by this bug?: 2: Will only affect a few installed domains
How will those affected feel about the bug?: 5: Blocking further progress on the daily work
User Pain: 0.343
Enterprise Customer affected?:
School Customer affected?:
ISV affected?:
Waiting Support:
Flags outvoted (downgraded) after PO Review:
Ticket number:
Bug group (optional):
Max CVSS v3 score:


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Daniel Tröder univentionstaff 2017-03-03 11:25:49 CET
When running the installer of UCS@school 4.2 v1 on a slave to create an educational server:

(after manually fixing Bug #43711)

03.03.17 11:20:25.393  MODULE      ( PROCESS ) : Could not connect to the DC Master m120.uni.dtr: 401 on m120.uni.dtr (auth): {"status": 401, "message": "Cross Site Request Forgery attack detected. Please provide the \"UMCSessionId\" cookie value as HTTP request header \"X-Xsrf-Protection\".", "location": "https://m120.uni.dtr/univention/auth"}
Comment 1 Daniel Tröder univentionstaff 2017-03-03 11:28:33 CET
Possibly related: Bug #34498, Bug #39733
Comment 2 Florian Best univentionstaff 2017-03-03 11:39:49 CET

*** This bug has been marked as a duplicate of bug 42408 ***
Comment 3 Florian Best univentionstaff 2017-03-03 14:09:13 CET

*** This bug has been marked as a duplicate of bug 42114 ***
Comment 4 Florian Best univentionstaff 2017-03-03 14:09:30 CET
Fixed in svn r77323.