When i try to call login api second time without X-CSRF-Token in header it gives me "CSRF validation failed" error in response(considering logged in successfully in first attempt). Also it removes entry from drupal's sessions table. Is it right behavior of login api ?

Comments

amar.deokar created an issue. See original summary.

tyler.frankenstein’s picture

Status: Active » Postponed (maintainer needs more info)

When i try to call login api second time without X-CSRF-Token in header it gives me "CSRF validation failed" error in response(considering logged in successfully in first attempt).

The X-CSRF-Token is required for all POST requests, not just the first.

Also it removes entry from drupal's sessions table. Is it right behavior of login api ?

I'm not entirely sure what you mean here, but I would imagine it would remove any previous entries from the session table when creating a new one upon login.

amar.deokar’s picture

I think accessing api as anonymous user with POST method doesn't not require X-CSRF-Token. Login api is one of the example of it. It doesn't require X-CSRF-Token.

My question is if user is already logged in and if he tries to login again then what should be the behavior ?
Currently it returns "CSRF validation failed" error & removes entry of user from sessions table who is currently logged in.
Note : Session authentication is enabled.

kylebrowning’s picture

All anonymous POST requests still require XSRF as it prevents from being a fake request.

If the user is already logged in, POST;ing to user/login will return 406 Not Acceptable, as you are already logged in.

amar.deokar’s picture

@kylebrowning thanks for reply. But as per below code if original user is anonymous(i.e. uid == 0 ) then token validation has not been done. (services.module)

 573 function _services_sessions_authenticate_call($module, $controller) {
 574   global $user;
 575   $original_user = services_get_server_info('original_user');
 576   if ($original_user->uid == 0) {
 577     return;
 578   }
.......
.......

Also agree with

If the user is already logged in, POST;ing to user/login will return 406 Not Acceptable, as you are already logged in.

This is true only if you pass X-CSRF-Token in header for user/login.
Note : I am using drupal 7.50.

amar.deokar’s picture

@tyler.frankenstein, Can you please help me to sort out my issue.

I am using
drupal 7.50.
services module 7.x-3.15+2-dev.
REST server as server.
session authentication for verifying user.

Please tell me if any extra info is needed.

tyler.frankenstein’s picture

I'm not sure I understand the problem here. My advice would be to prevent your application from letting people try to login again if they are already logged in. That's what I do with DrupalGap and no one has reported an any issues with a second login attempt.

amar.deokar’s picture

tyler.frankenstein’s picture

Status: Postponed (maintainer needs more info) » Closed (duplicate)

Closing as duplicate of #2804641: Bug in user logout api