Project

General

Profile

Actions

Bug #25359

closed

Essential form protection tokens are dropped when beeing logged in for a "long" time

Added by Helmut Hummel about 13 years ago. Updated almost 13 years ago.

Status:
Closed
Priority:
Should have
Assignee:
Category:
-
Target version:
Start date:
2011-03-20
Due date:
% Done:

100%

Estimated time:
TYPO3 Version:
4.5
PHP Version:
Tags:
Complexity:
Is Regression:
Sprint Focus:

Description

Problem:
The backend form protection uses the session data field to store created tokens. Since this database field has a certain size, the framework starts dropping tokens, when it holds a certain amount of tokens.

When doing so, it is very likely that tokens which are seldom replaced (like the ExtDirect token or the clear cache tokens) will be dropped, resulting in token validation error messages

Solution:
I suggest to abandon the extra security feature of having unique tokens, because it turned out to add a complexity which is almost impossible to handle

(issue imported from #M17991)


Related issues 2 (0 open2 closed)

Related to TYPO3 Core - Bug #24671: Protect C(R)UD actions against CSRFClosedErnesto Baschny2011-01-20

Actions
Related to TYPO3 Core - Bug #25164: Copy & Paste: "Validating the security token of this form has failed. Please reload the form and submit it again."Closed2011-02-24

Actions
Actions

Also available in: Atom PDF