Closed (duplicate)
Project:
Services
Version:
7.x-3.x-dev
Component:
Code
Priority:
Normal
Category:
Support request
Assigned:
Unassigned
Reporter:
Created:
9 Sep 2016 at 16:40 UTC
Updated:
1 Oct 2016 at 15:35 UTC
Jump to comment: Most recent
Comments
Comment #2
tyler.frankenstein commentedThe X-CSRF-Token is required for all POST requests, not just the first.
I'm not entirely sure what you mean here, but I would imagine it would remove any previous entries from the session table when creating a new one upon login.
Comment #3
amar.deokar commentedI think accessing api as anonymous user with POST method doesn't not require X-CSRF-Token. Login api is one of the example of it. It doesn't require X-CSRF-Token.
My question is if user is already logged in and if he tries to login again then what should be the behavior ?
Currently it returns "CSRF validation failed" error & removes entry of user from sessions table who is currently logged in.
Note : Session authentication is enabled.
Comment #4
kylebrowning commentedAll anonymous POST requests still require XSRF as it prevents from being a fake request.
If the user is already logged in, POST;ing to user/login will return 406 Not Acceptable, as you are already logged in.
Comment #5
amar.deokar commented@kylebrowning thanks for reply. But as per below code if original user is anonymous(i.e. uid == 0 ) then token validation has not been done. (services.module)
Also agree with
This is true only if you pass X-CSRF-Token in header for user/login.
Note : I am using drupal 7.50.
Comment #6
amar.deokar commented@tyler.frankenstein, Can you please help me to sort out my issue.
I am using
drupal 7.50.
services module 7.x-3.15+2-dev.
REST server as server.
session authentication for verifying user.
Please tell me if any extra info is needed.
Comment #7
tyler.frankenstein commentedI'm not sure I understand the problem here. My advice would be to prevent your application from letting people try to login again if they are already logged in. That's what I do with DrupalGap and no one has reported an any issues with a second login attempt.
Comment #8
amar.deokar commentedPlease see issue https://www.drupal.org/node/2804641 .
Comment #9
tyler.frankenstein commentedClosing as duplicate of #2804641: Bug in user logout api