Skip to content

Avoid "CSRF failed" pages #7155

@MorrisJobke

Description

@MorrisJobke
  • create a password protected share
  • open the link and get a password prompt
  • send your machine to sleep and open it on the next day
  • enter the password
  • press the "access link" button
  • expected: I get access
  • actual: "Access forbidden. CSRF check failed"

We should make the access forbidden page a bit less technical and make the error inline, so that the user just get an "Login failed - please try again" instead of the pure error page.

cc @nextcloud/security @nextcloud/designers @rullzer Does that make sense?

Metadata

Metadata

Type

No type

Projects

No projects

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions