Top Menu

Jump to content
Home
    Modules
      • Projects
      • Activity
      • Work packages
      • Gantt charts
      • Calendars
      • Team planners
      • Boards
      • News
    • Getting started
    • Introduction video
      Welcome to OpenProject Community
      Get a quick overview of project management and team collaboration with OpenProject. You can restart this video from the help menu.

    • Help and support
    • Upgrade to Enterprise edition
    • User guides
    • Videos
    • Shortcuts
    • Community forum
    • Enterprise support

    • Additional resources
    • Data privacy and security policy
    • Digital accessibility (DE)
    • OpenProject website
    • Security alerts / Newsletter
    • OpenProject blog
    • Release notes
    • Report a bug
    • Development roadmap
    • Add and edit translations
    • API documentation
  • Sign in
      Forgot your password?

      or sign in with your existing account

      Google

Side Menu

  • Overview
  • Activity
    Activity
  • Roadmap
  • Work packages
    Work packages
  • Gantt charts
    Gantt charts
  • Calendars
    Calendars
  • Team planners
    Team planners
  • Boards
    Boards
  • News
  • Forums

Content

Support Installation & Updates
  1. OpenProject
  2. Forums
  3. Support Installation & Updates
  4. Upgrade on Univention 4.3-3 errata390 - from OP 4.3 --> 8.1 - 422 Unable to verify Cross-Site Request Forgery token. Did you try to submit data on multiple browsers or tabs? Please close all tabs and try again.

Upgrade on Univention 4.3-3 errata390 - from OP 4.3 --> 8.1 - 422 Unable to verify Cross-Site Request Forgery token. Did you try to submit data on multiple browsers or tabs? Please close all tabs and try again.

Added by Cascade Sun over 6 years ago

Hello and thanks for looking at this. All was running great in v7.3, but now I am getting the 422 error after upgrade to 8.1, even after having added the X-Forwarded-Proto in my Apache2 configuration. It does not recognize a new admin-admin account, and will not let any of the previous users log in at all. No PM has access to their projects.

it does seem to see the original users I had built in from v7.3, as well as the original admin account I had renamed with a different password. I can tell it sees those because it doesnt give an invalid password error, but instead when it is a valid user from the previous setup, it responds with the error: 422 - “Unable to verify Cross-Site Request Forgery token. Did you try to submit data on multiple browsers or tabs? Please close all tabs and try again.” My URL looks like this: https://www.rightdomain.com/openproject/login

Now, the UCS config is set to force SSL, and we use Lets Encrypt for the domain and subdomain - I tried to just enter the http with the correct URL to try and force it to use just the http: but it just redirects to https. I did add the RequestHeader set “X-Forwarded-Proto” and restarted apache2, but still there. So I am unable to even get in to the administration panel inside of OP to reset it to https from http, if that is what happened. I am loathe to stop forcing SSL in UCS as I also have owncloud and wordpress using it. Do you think it would break anything if I deselected “force SSL” in the Univention Management Console? Is that perhaps what I need to do to login again, and then set the OP administration to https from within the app itself, or can I do that from the CLI or the UMC?

To be clear, I cannot access the Open Project instance through the web interface at all now. There is no option to set the http protocol in Univention for it. Can I change this through the CLI or UMC?


Replies (4)

RE: Upgrade on Univention 4.3-3 errata390 - from OP 4.3 --> 8.1 - 422 Unable to verify Cross-Site Request Forgery token. Did you try to submit data on multiple browsers or tabs? Please close all tabs and try again. - Added by Oliver Günther over 6 years ago

Hello,

this is a known issue of the UCS setup in combination with HTTPS access to OpenProject. The UCS team is working on a fix. It is indeed connected to the X-Forwarded-Proto header that needs to be set from both the outer and inner Apache worker.

Best regards,

Oliver

RE: Upgrade on Univention 4.3-3 errata390 - from OP 4.3 --> 8.1 - 422 Unable to verify Cross-Site Request Forgery token. Did you try to submit data on multiple browsers or tabs? Please close all tabs and try again. - Added by Cascade Sun over 6 years ago

THANK YOU! I have been digging everywhere and this is the closest I have gotten to the answer, and it is what i suspected as well. Thanks again

RE: Upgrade on Univention 4.3-3 errata390 - from OP 4.3 --> 8.1 - 422 Unable to verify Cross-Site Request Forgery token. Did you try to submit data on multiple browsers or tabs? Please close all tabs and try again. - Added by Oliver Günther over 6 years ago

There has been an update by UCS that resolves this issue. I have posted a reply on your other thread. Please click here for details

RE: Upgrade on Univention 4.3-3 errata390 - from OP 4.3 --> 8.1 - 422 Unable to verify Cross-Site Request Forgery token. Did you try to submit data on multiple browsers or tabs? Please close all tabs and try again. - Added by Cascade Sun over 6 years ago

Hello - problem still persists in Univention with OP 8.2. https://help.univention.com/t/openproject-8-1-0-422-error/10268/15

  • (1 - 4/4)
Loading...