Problem/Motivation
CSRF token does not work for the user without session
Javascript crash with 2.7.0 with the anonymous user , works fine with 2.5.0 and the anonymous user.
Steps to reproduce
create an internal intranet site, allow anonymous to upload files, test with 2.7.0 to see broken, then test with 2.5.0 to see it working.
composer require "drupal/dropzonejs": "2.5.0 as 2.7.0" -W
fixes it but find exactly the problem code and schedule that for a fix.
Proposed resolution
use 2.5.0 instead of 2.7.0 OR
patch dropzonejs with this patch:
#3197207: Anonymous users cannot upload caused by invalid csrf-token
OR apply this core patch:
#2730351-105: CSRF check always fails for users without a session
https://www.drupal.org/files/issues/2022-06-18/2730351-105.patch
Remaining tasks
#3197207: Anonymous users cannot upload caused by invalid csrf-token
User interface changes
unable to upload a file, gets a 404 error.
API changes
TBD
Data model changes
Issue fork dropzonejs-3316184
Show commands
Start within a Git clone of the project using the version control instructions.
Or, if you do not have SSH keys set up on git.drupalcode.org:
Comments
Comment #3
jamesyao commented@joseph.olstad
The issue is related to that CSRF token does not work for the user without session because the CSRF checker fails as the CSRF seed is not stored anywhere. The Core Path (https://www.drupal.org/files/issues/2022-06-18/2730351-105.patch) works with 2.7.0.
Comment #4
joseph.olstad@jamesyao, thanks for this information!
Comment #5
joseph.olstadComment #6
joseph.olstadComment #7
joseph.olstadComment #8
joseph.olstadComment #9
joseph.olstadComment #10
joseph.olstadrather than core patch, patch dropzonejs with patch in #3197207: Anonymous users cannot upload caused by invalid csrf-token