• I'm using the latest NodeBB v1.16 via Cloudron.

    An error that must be related to one of the more recent NodeBB updates is that forum users report strange errors where they only get the single word "Error" in some situations when they use the forum.

    These situations seem to coincide with log entries in the server log that look like this:

    Dec 22 19:42:18 2020-12-22T18:42:18.963Z [4567/289] - error: /api/v3/topics/6185
    Dec 22 19:42:18 invalid csrf token

    I have seen that "Invalid csrf token" has been discussed in this forum before, but those discussions were many years ago. Could this strange behavior be related to this recent addition to NodeBB, maybe? Any other idea?

  • GNU/Linux Admin

    @klaus6 said in Invalid CSRF Token, again:

    Could this strange behavior be related to this recent addition to NodeBB, maybe? Any other idea?

    Probably, yes. That said, it is exceeding difficult to debug because it just doesn't reproduce for the majority of users.

    You're the first I've heard reporting this issue, so I'd need to know what's special about your users, how many are affected, etc.

    Perhaps it is related to long-lived browser windows... if in a different tab they've logged out and back in, then the CSRF token is indeed expired. That would cause the error you see.

Suggested Topics

| |