Problem/Motivation

CSRF token does not work for the user without session
Javascript crash with 2.7.0 with the anonymous user , works fine with 2.5.0 and the anonymous user.

Steps to reproduce

create an internal intranet site, allow anonymous to upload files, test with 2.7.0 to see broken, then test with 2.5.0 to see it working.

composer require "drupal/dropzonejs": "2.5.0 as 2.7.0" -W

fixes it but find exactly the problem code and schedule that for a fix.

Proposed resolution

use 2.5.0 instead of 2.7.0 OR
patch dropzonejs with this patch:
#3197207: Anonymous users cannot upload caused by invalid csrf-token
OR apply this core patch:
#2730351-105: CSRF check always fails for users without a session
https://www.drupal.org/files/issues/2022-06-18/2730351-105.patch

Remaining tasks

#3197207: Anonymous users cannot upload caused by invalid csrf-token

User interface changes

unable to upload a file, gets a 404 error.

API changes

TBD

Data model changes

Issue fork dropzonejs-3316184

Command icon Show commands

Start within a Git clone of the project using the version control instructions.

Or, if you do not have SSH keys set up on git.drupalcode.org:

Comments

joseph.olstad created an issue. See original summary.

immaculatexavier made their first commit to this issue’s fork.

jamesyao’s picture

@joseph.olstad
The issue is related to that CSRF token does not work for the user without session because the CSRF checker fails as the CSRF seed is not stored anywhere. The Core Path (https://www.drupal.org/files/issues/2022-06-18/2730351-105.patch) works with 2.7.0.

joseph.olstad’s picture

@jamesyao, thanks for this information!

joseph.olstad’s picture

Title: for Anonymous users use 2.5.0 instead of 2.7.0 - "drupal/dropzonejs": "2.5.0 as 2.7.0", » Sessionless users have no CSRF token - use 2.5.0 instead of 2.7.0
Issue summary: View changes
joseph.olstad’s picture

Issue summary: View changes
joseph.olstad’s picture

joseph.olstad’s picture

Status: Active » Needs review
joseph.olstad’s picture

joseph.olstad’s picture

rather than core patch, patch dropzonejs with patch in #3197207: Anonymous users cannot upload caused by invalid csrf-token