Skip to content

Access forbidden: CSRF check failed on logout #17065

@alvvdc

Description

@alvvdc

Steps to reproduce

  1. Install Lighttpd and PHP.
  2. Download Nextcloud server ZIP.
  3. Log in Nextcloud, and when you log out, in the most cases you get the next error:

Access forbidden
CSRF check failed

Screenshot at 2019-09-09 15-18-28

Expected behaviour

Log out succesfully.

Actual behaviour

When I try logout, I get the telled error. Then, if I refresh the website the session is still active.

In Network Firefox explorer (from F12) the logout request get a 412 status code:

Screenshot at 2019-09-09 15-27-30

This error is with Lighttpd web service, with Nginx works fine.

Server configuration

Operating system:
Debian / Raspbian
Web server:
Lighttpd
Database:
MariaDB
PHP version:
PHP 7.3
Nextcloud version: (see Nextcloud admin page)
16.0.4
Updated from an older Nextcloud/ownCloud or fresh install:
Fresh install
Where did you install Nextcloud from:
https://download.nextcloud.com/server/releases/nextcloud-16.0.4.zip

Metadata

Metadata

Assignees

No one assigned

    Labels

    1. to developAccepted and waiting to be taken care ofbugpapercutAnnoying recurring UX issue with possibly simple fix.security

    Type

    No type

    Projects

    No projects

    Milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions