<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[CSRF constantly triggering on login]]></title><description><![CDATA[<p dir="auto">Any ideas what might be causing this, or if there is a way to disable the check?</p>
<p dir="auto">I always manually logout at end of a session, Next time I login I have to go through an extended process to get to the dashboard (it used to be less in your face on older builds).</p>
<p dir="auto">Browser is Vivaldi.</p>
]]></description><link>https://forum.netgate.com/topic/157150/csrf-constantly-triggering-on-login</link><generator>RSS for Node</generator><lastBuildDate>Mon, 15 Jun 2026 01:17:49 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/157150.rss" rel="self" type="application/rss+xml"/><pubDate>Sat, 26 Sep 2020 23:36:48 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to CSRF constantly triggering on login on Fri, 13 Nov 2020 04:12:25 GMT]]></title><description><![CDATA[<p dir="auto">To follow up on my post, I eventually realized that the Lockwise on my phone was auto-submitting the form when credentials were picked (unlike the Firefox web browser).  However with a slight delay on the page load I didn't notice that and submitted the form myself (again).  That explains all my symptoms.</p>
]]></description><link>https://forum.netgate.com/post/945330</link><guid isPermaLink="true">https://forum.netgate.com/post/945330</guid><dc:creator><![CDATA[SteveITS]]></dc:creator><pubDate>Fri, 13 Nov 2020 04:12:25 GMT</pubDate></item><item><title><![CDATA[Reply to CSRF constantly triggering on login on Mon, 02 Nov 2020 15:23:11 GMT]]></title><description><![CDATA[<p dir="auto">I was using Firefox Lockwise on my iPhone.  To my knowledge it doesn't store anything besides login/password...?</p>
<p dir="auto">Something else I've noticed that is odd.  With Lockwise, if I get to the red CSRF screen (https://forum.netgate.com/topic/152075/missing-or-expired-csrf-token) and tap the <strong>Back</strong> button in Safari, I end up at the dashboard (i.e. I don't have to accept the error, or log in again).</p>
<p dir="auto">And note it isn't an issue in Firefox for Windows, which is the same password list.</p>
<p dir="auto">I'm not trying to insist it's a pfSense issue, just weird behavior.</p>
]]></description><link>https://forum.netgate.com/post/943464</link><guid isPermaLink="true">https://forum.netgate.com/post/943464</guid><dc:creator><![CDATA[SteveITS]]></dc:creator><pubDate>Mon, 02 Nov 2020 15:23:11 GMT</pubDate></item><item><title><![CDATA[Reply to CSRF constantly triggering on login on Tue, 20 Oct 2020 14:32:10 GMT]]></title><description><![CDATA[<p dir="auto">If the browser or a password manager aggressively caches the form against all directives from the firewall, what do you expect the firewall to do?</p>
<p dir="auto">The firewall is stopping the clients from acting in an insecure manner, which is the best thing for a firewall to do.</p>
<p dir="auto">Maybe we can find some tricky way around it without reducing security, but clearly the problem here is squarely on the client(s) not behaving properly.</p>
]]></description><link>https://forum.netgate.com/post/941195</link><guid isPermaLink="true">https://forum.netgate.com/post/941195</guid><dc:creator><![CDATA[jimp]]></dc:creator><pubDate>Tue, 20 Oct 2020 14:32:10 GMT</pubDate></item><item><title><![CDATA[Reply to CSRF constantly triggering on login on Wed, 14 Oct 2020 14:46:17 GMT]]></title><description><![CDATA[<p dir="auto">Like in the other thread, one cause of the problem has been determined to be when the page is idle for too long.</p>
<p dir="auto">Auto refresh might feel a bit of a scuffed solution, so a more elegant solution would be after e.g. 1 hour (depends on the token expiry), then it will auto load a holding page once instead of auto refresh, which you first have to click before seeing the login page, then you have a fresh token and no CSRF issue.</p>
]]></description><link>https://forum.netgate.com/post/940221</link><guid isPermaLink="true">https://forum.netgate.com/post/940221</guid><dc:creator><![CDATA[chrcoluk]]></dc:creator><pubDate>Wed, 14 Oct 2020 14:46:17 GMT</pubDate></item><item><title><![CDATA[Reply to CSRF constantly triggering on login on Tue, 13 Oct 2020 20:46:38 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/noncarbonatedclack">@<bdi>noncarbonatedclack</bdi></a> I was in Safari on my phone at the time.  On my PC it's easily duplicated in Firefox by logging out and leaving the tab open to the login page for a few hours...which means it is therefore a correct message, that the token expired.</p>
<p dir="auto">The page headers show "cache-control: no-store, no-cache, must-revalidate" but maybe iOS Safari doesn't follow that?  I didn't look into it much except for noting the reload "fixed" it.</p>
]]></description><link>https://forum.netgate.com/post/940154</link><guid isPermaLink="true">https://forum.netgate.com/post/940154</guid><dc:creator><![CDATA[SteveITS]]></dc:creator><pubDate>Tue, 13 Oct 2020 20:46:38 GMT</pubDate></item><item><title><![CDATA[Reply to CSRF constantly triggering on login on Tue, 13 Oct 2020 20:34:21 GMT]]></title><description><![CDATA[<p dir="auto">@teamits said in <a href="/post/940094">CSRF constantly triggering on login</a>:</p>
<blockquote>
<p dir="auto">I ran into this sort of behavior when setting up an SG-2100 the other day and thought of this post.  When I pulled up the login page on my iPhone it was, I'm assuming, using a cached version, as the initial login attempt would always fail.  I found if I always reload the page before logging in it was fine.  This was even if I had logged out, closed the "tab"/page in Safari, closed Safari, etc.</p>
</blockquote>
<p dir="auto">Hm interesting. Let me give this a shot and see in a little bit.</p>
<p dir="auto">You're seeing this in safari? Any other browsers?<br />
I meant to test all browsers on my computer and see what happens and post, but haven't gotten to it yet.</p>
]]></description><link>https://forum.netgate.com/post/940153</link><guid isPermaLink="true">https://forum.netgate.com/post/940153</guid><dc:creator><![CDATA[noncarbonatedclack]]></dc:creator><pubDate>Tue, 13 Oct 2020 20:34:21 GMT</pubDate></item><item><title><![CDATA[Reply to CSRF constantly triggering on login on Tue, 13 Oct 2020 14:17:07 GMT]]></title><description><![CDATA[<p dir="auto">I ran into this sort of behavior when setting up an SG-2100 the other day and thought of this post.  When I pulled up the login page on my iPhone it was, I'm assuming, using a cached version, as the initial login attempt would always fail.  I found if I always reload the page before logging in it was fine.  This was even if I had logged out, closed the "tab"/page in Safari, closed Safari, etc.</p>
]]></description><link>https://forum.netgate.com/post/940094</link><guid isPermaLink="true">https://forum.netgate.com/post/940094</guid><dc:creator><![CDATA[SteveITS]]></dc:creator><pubDate>Tue, 13 Oct 2020 14:17:07 GMT</pubDate></item><item><title><![CDATA[Reply to CSRF constantly triggering on login on Sun, 11 Oct 2020 04:12:42 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/chrcoluk">@<bdi>chrcoluk</bdi></a> I have this issue with Vivaldi as well. Doesn't happen in incognito mode apparently for me.</p>
<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/jimp">@<bdi>jimp</bdi></a> I've been able to reproduce this on a VM install of pfsense, and an install on a physical machine. Both were version 2.4.5-RELEASE-p1.</p>
<p dir="auto">I just spun up a test VM, and through initial config it was fine. Then the CSRF started triggering, before I've even made any changes.</p>
]]></description><link>https://forum.netgate.com/post/939738</link><guid isPermaLink="true">https://forum.netgate.com/post/939738</guid><dc:creator><![CDATA[noncarbonatedclack]]></dc:creator><pubDate>Sun, 11 Oct 2020 04:12:42 GMT</pubDate></item><item><title><![CDATA[Reply to CSRF constantly triggering on login on Thu, 01 Oct 2020 15:14:11 GMT]]></title><description><![CDATA[<p dir="auto">Most common way I've seen that happen is if you click the login button multiple times, like a double click/tap.</p>
]]></description><link>https://forum.netgate.com/post/937910</link><guid isPermaLink="true">https://forum.netgate.com/post/937910</guid><dc:creator><![CDATA[jimp]]></dc:creator><pubDate>Thu, 01 Oct 2020 15:14:11 GMT</pubDate></item></channel></rss>