Uploaded image for project: 'Atlas'
  1. Atlas
  2. ATLAS-4883

Atlas UI CSRF token error

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Open
    • Major
    • Resolution: Unresolved
    • None
    • None
    • atlas-core
    • None

    Description

      => Customer is facing issues , as sometimes the basic search is not working and the error:
      +++++
      Missing header or invalid Header value for CSRF Vulnerability Protection
      +++++

      is coming up intermittently on the right corner of the WebUI.

      Please refer to the screenshots attached to the Jira

       

      ---------------------

      Dev analysis

      steps to reproduce

      1. Set the session-timeout to 1 min in web.xml file.
      2. Wait for 1 min after Atlas login. 
      3. Do basic search and response will get as 400 error code with Missing header or invalid Header value for CSRF Vulnerability Protection.
      4. Also while doing metric API (Statistics) call we get the 409 error code and it redirect to login page. Which should be a correct way.

      As the sever-side session get timed-out and user was in-active. so it get 400 error code.

      Fix will provide redirection to  login-page or any other solution.

       

       
       

      Attachments

        1. 1-_Atlas_webUI_with_error.png
          114 kB
          Paresh Devalia
        2. 2-_Atlas_webUI_with_error.png
          123 kB
          Paresh Devalia

        Activity

          People

            pareshD Paresh Devalia
            pareshD Paresh Devalia
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

            Dates

              Created:
              Updated: