Create
cancel
Showing results for 
Search instead for 
Did you mean: 
Sign up Log in

Next challenges

Recent achievements

Recognition

  • Give kudos
  • My kudos

Leaderboard

  • Global

Trophy case

Kudos (beta program)

Kudos logo

You've been invited into the Kudos (beta program) private group. Chat with others in the program, or give feedback to Atlassian.

View group

It's not the same without you

Join the community to find out what other Atlassian users are discussing, debating and creating.

Atlassian Community Hero Image Collage

Crowd session immediately expires in Firefox Edited

Crowd 3.4.0 on linux, behind nginx for SSL.

 

When I login into Crowd for some admin tasks using Firefox, I am taken to first page (which sadly in my case is still "please configure your mail server") and then when I click any menu item to go there, I am kicked out to login page. When I enter login/password - I am taken to required page, but next click also takes me back to login page.

All works fine from Chrome.

Not sure if this is relevant, but I am seeing the following in Crowd logs:
2019-05-17 13:46:30,576 http-nio-127.0.0.1-8095-exec-17 WARN [common.security.jersey.XsrfResourceFilter] XSRF failure not being enforced for request: https://crowdserver/crowd/rest/usermanagement/1/session/H-cUUA5J5uCUPQ2pOw3oDwAAAAAAAoABbG9jYWwuYWRtaW4uY3Jvd2Q%3D , origin: null , referrer: null, method: DELETE
2019-05-17 13:51:55,616 http-nio-127.0.0.1-8095-exec-23 WARN [common.security.jersey.XsrfResourceFilter] XSRF failure not being enforced for request: https://crowdserver/crowd/rest/usermanagement/1/session/LP4E6EfJNvxt-eVNOJJSGwAAAAAAAoABbG9jYWwuYWRtaW4uY3Jvd2Q%3D , origin: null , referrer: null, method: DELETE
2019-05-17 13:53:45,626 http-nio-127.0.0.1-8095-exec-10 WARN [common.security.jersey.XsrfResourceFilter] XSRF failure not being enforced for request: https://crowdserver/crowd/rest/usermanagement/1/session/Iq_iW-SEINOTxPKJCjkdLQAAAAAAAoABbG9jYWwuYWRtaW4uY3Jvd2Q%3D , origin: null , referrer: null, method: DELETE

and this kind of coincides with my activity.

is there any misconfiguration? or is it a bug?

 

1 answer

0 votes
Andy Heinzer Atlassian Team May 22, 2019

Hi Sergey,

I suspect this is a misconfiguration of Crowd, but it's hard to tell for sure with the information we so far.  I would recommend taking a closer look at Cross Site Request Forgery (CSRF) protection changes in Atlassian REST.  It explains a few conditions in which might trigger these CSRF/XSRF errors like this.

I'd also be interested to learn what site address you are accessing Crowd on when you see this error.

Since we know you're using Crowd with an nginx proxy, I'd be interested to learn more about the settings you have in the crowd server.xml file.  This file governs Crowds tomcat webserver, what ports it is open on.  There has to be at least one <connector> here, but there could be more.  When you setup a reverse proxy, there should be other parameters added to that connector such as proxyName, proxyPort, and scheme for example.  Without these, Crowd can be expected to have problems understanding where requests are really coming from.

There is also a document that might help with checking this configuration such as Configuring Crowd to Work with SSL. But also a non SSL nginx guide in the KB How to use NGINX to proxy requests for Crowd.

If you have to make any changes to that server.xml file, save it, and restart Crowd for these settings to take effect.

Please let me know.

Andy

Suggest an answer

Log in or Sign up to answer
TAGS
Community showcase
Published in Confluence Cloud

Share your Confluence Cloud experience for a chance to win $500!

Take our 5-minute survey to win a $500 Visa gift card! Are you currently using Confluence Cloud? We want to hear from you! Fill out this quick survey about your Confluence Cloud experience so we ...

81 views 1 5
Read article

Community Events

Connect with like-minded Atlassian users at free events near you!

Find an event

Connect with like-minded Atlassian users at free events near you!

Unfortunately there are no Community Events near you at the moment.

Host an event

You're one step closer to meeting fellow Atlassian users at your local event. Learn more about Community Events

Events near you