[BlueOnyx:25749] Re: CSRF mismatch: The action you have requested is not allowed.

Michael Stauber mstauber at blueonyx.it
Fri Nov 25 16:20:59 -05 2022


Hi Keith,

> Just did 2 fresh install of 5210R and I've faced with this again
> 
> CSRF mismatch: The action you have requested is not allowed.
> 
> On two different fresh installs
> 
> Just thought I would let you know Michael

This is how it's supposed to be: Upon a fresh install of BlueOnyx 5210R 
CSRF is disabled automatically until you finish the web based setup 
wizard. Then it gets turned on automatically. It protects both GET and 
POST requests.

Where did the error happen? During the web based initial setup or past it?

On the Login page? Or past it?

Anyway: If you want, you can turn off CSRF protection this way from SSH 
as root. This goes all into one line:

echo "Find System"|/usr/sausalito/bin/cceclient|grep ^104|awk '{ print 
"SET " $3 " csrf_protection = 0"}'|/usr/sausalito/bin/cceclient

-- 
With best regards

Michael Stauber



More information about the Blueonyx mailing list