• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

CSRF Login Issue Solution

Scheduled Pinned Locked Moved General pfSense Questions
1 Posts 1 Posters 2.8k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • 0
    0x10C
    last edited by Nov 20, 2016, 5:43 PM

    I've read a few people on the IRC and on these forums that have this issue where they get a message saying:

    CSRF check failed. Your form session may have expired, or you may not have cookies enabled.

    And they all say the same thing, it doesn't happen when they run Chrome in incognito mode. I also had this problem so I decided to figure out what the issue was and I have found the reason for it occurring.

    If you use LastPass, 1Password or another browser based automatic login filler which overrides the input method of your browser and you setup a login before you upgraded to the latest version of pfSense the Username and Password forms which these plugins try to insert your Username and Password into have changed names. (in pfSense 2.2.x -> 2.3.x).

    The solution is simple backup your username and password, erase the entries in your password manager (the forms it looks for) and create new generic ones just called username and password. Now when you login using your password manager you won't have the CSRF error message etc

    I hope this is helpful to someone after looking at a lot of threads on this error no one seems to have posted a solution yet but I was able to replicate the problem and find this solution with some time yesterday.

    1 Reply Last reply Reply Quote 4
    1 out of 1
    • First post
      1/1
      Last post
    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
      This community forum collects and processes your personal information.
      consent.not_received