Forum Index >  glFusion >  glFusion Support New Topic Post Reply
 Security tocket is invalid.
First | Previous | 1 2 | Next | Last    |  Printable Version
By: savco (offline)  Mar 29 2011 21:45 pm (Read 3684 times)  
savco

This msg. shows up every time I want to publish a story with Fire Fox. I have posted this issue a while ago but it still persists.
This is how it goes:

Trying to publish a story resluts in a msg. " Security Token is Invalid - Possible session timeout."
I have installed the IE tab and when I switch the rendering engine I do not see the issue. I dont see this issue wiht IE 9 as well.
It is clearly related to FF.

Im using:

Fire Fox 4.0 updated yesratday and the issue still persists.
glfusion 1.2.1.pl3 and chameleon 2.1.11


ideas ?

s

PS

I have switched off all the plugins and addons with FireFox and the issue is still there..so its not plug in problem.

Forum Regular Member
Regular Member

Group Comfort
Level:
: 0

Registered: 04/11/08
Posts: 76

Profile Email    
  Quote
By: Mark (offline)  Mar 30 2011 07:41 am  
Mark

When you receive the security token invalid message, are you then able to submit the story? What should happen is you are given another chance to submit when the token has expired.

I'm sure we've been through some of this before, but let's regroup and run through the checklist:

The token check does the following:

1. The token is retrieved from the database. If no token is found, the expired message is displayed. There was a bug that was fixed in v1.2.1.pl5 that would cause this error message when more than one token was displayed on a page. Generally this only affects editing / deleting comments and should not be a problem with story editing. But, I think it would be wise to update to the latest patch level and let's see if this solves the issue.

2. Compares the referring URL with the URL that set the token. For example, when you edit a story the URL used to begin the edit is admin/story.php. When you hit save, the URL that is submitting the form is checked, it should also be admin/story.php in this example. Possible trouble spots: Accessing the site as http://yoursitehere.com, but having http://www.yoursitehere.com as the site_url setting (notice the www. difference).

3. Tokens are valid for 20 minutes. If you spend more than 20 minutes editing the story, you will receive the expired message. You should be able to simply hit submit again to recover without any data loss.

I think the best next step would be to update to the latest patch level.

Thanks!
Mark

Forum Admin
Admin

Group Comfort
Level:
: +110

Registered: 10/21/05
Posts: 6331
Location: The Great State of
Texas

Profile      
  Quote
By: savco (offline)  Mar 30 2011 10:34 am  
savco

Downloaded and installed the pl5 files, however the site still shows pl3 ?

The issue still exists.

s

Forum Regular Member
Regular Member

Group Comfort
Level:
: 0

Registered: 04/11/08
Posts: 76

Profile Email    
  Quote
By: Mark (offline)  Mar 30 2011 10:36 am  
Mark

Make sure you are overwriting the older files when FTP'ing up to your site. The version number is stored in lib-common.php (public_html/ directory). If it is still showing .pl3 then it did not get overwritten with the never version from .pl5.

Thanks!
Mark

Forum Admin
Admin

Group Comfort
Level:
: +110

Registered: 10/21/05
Posts: 6331
Location: The Great State of
Texas

Profile      
  Quote
By: savco (offline)  Mar 30 2011 11:06 am  
savco

Ok its all good now...may be I missed it the first time..

the issue still persists.

1. I do use the same HTTP www.etc.com as listed the configuration www.etc.com
2. The time is not an issue since I just put test and try to publish.

s


PS it could be chameleon issue..

Forum Regular Member
Regular Member

Group Comfort
Level:
: 0

Registered: 04/11/08
Posts: 76

Profile Email    
  Quote
By: Mark (offline)  Mar 30 2011 11:19 am  
Mark

I don't think it is a chameleon issue, not if you are running the latest version.

Any chance I could get admin access to the site with the problem and poke around a bit?

Thanks!
Mark

Forum Admin
Admin

Group Comfort
Level:
: +110

Registered: 10/21/05
Posts: 6331
Location: The Great State of
Texas

Profile      
  Quote
By: savco (offline)  Mar 30 2011 22:21 pm  
savco

Sure, will get in touch with you tomorrow morning.

Forum Regular Member
Regular Member

Group Comfort
Level:
: 0

Registered: 04/11/08
Posts: 76

Profile Email    
  Quote
By: max (offline)  Mar 31 2011 03:14 am  
max

I'm getting the same error also. Unlike the original poster, it started just recently after the latest pl5 or FF4 update.

error.log:

CheckToken: Token failed - no token found or more than 1 token found in database

Forum Newbie
Newbie

Group Comfort
Level:
: 0

Registered: 06/25/07
Posts: 14

Profile Email    
  Quote
By: Mark (offline)  Mar 31 2011 07:27 am  
Mark

Max - you are getting this error when editing / saving a story?

Savco / Max - Do you guys see the problem if you try a different browser? I'm curious if this is a FireFox only issue...If it works in other browsers, but not in FireFox, the first question I would ask is what add-ons do you have installed? I'm wondering if one of them might be messing with the security token cookies?

I've done some pretty extensive testing with FFv4 and glFusion v1.2.1.pl5 with both Nouveau and Chameleon themes, so fare everything is working as it should. Not to say there isn't a problem somewhere, I'm just having a difficult time recreating it.

Thanks!
Mark

Forum Admin
Admin

Group Comfort
Level:
: +110

Registered: 10/21/05
Posts: 6331
Location: The Great State of
Texas

Profile      
  Quote
By: savco (offline)  Mar 31 2011 11:08 am  
savco

The issue seems to FF related:

1. IE9 does not give this error.
2. I have installed the FF IE tab addon which is switching the rendering engine within the FF to IE and this works OK.

Max is you e-mail still: mark at glfusion I can sent you my admin pass so you can poke around a bit.

s

PS Mark I could not send you a PM because "Security Token Failure" with FireFox... ;-) no kidding.

Forum Regular Member
Regular Member

Group Comfort
Level:
: 0

Registered: 04/11/08
Posts: 76

Profile Email    
  Quote
By: Mark (offline)  Mar 31 2011 11:17 am  
Mark

There seem to be several IE Tab add-ons, can you tell me specifically which one you are using (name, version, maybe even publisher). I want to test it out here.

My guess is that it is screwing with the cookies used to store the token, especially since you are having the same problem here. I don't think it is anything site related, more with how the browser is handling the cookies.

A quick test would be to disable the add-on and see if the problem goes away. At least then we'll know what it is and can then focus on why.

Thanks!
Mark

Forum Admin
Admin

Group Comfort
Level:
: +110

Registered: 10/21/05
Posts: 6331
Location: The Great State of
Texas

Profile      
  Quote
By: savco (offline)  Mar 31 2011 11:22 am  
savco

OK Im using:

IE Tab Plus 1.98.2011 you can get it from: ietab.com

I did switched it off and has no effect..I have also disabled all of the adware and adblock plus as well as noscript addons. I switched off the firewall as well and these have no effects.

s

Forum Regular Member
Regular Member

Group Comfort
Level:
: 0

Registered: 04/11/08
Posts: 76

Profile Email    
  Quote
By: max (offline)  Mar 31 2011 12:16 pm  
max


Tried IE9 and Chrome, didn't get any errors.

In Firefox 4 it happens once after re-submitting "Authentication Required" when time-out occurs. It has happened when posting a new story or editing a static page. If I try again right after, it's ok.

I also got a bizarre error when posting a new image to MediaGallery:

MG_saveSWFUpload error: Unable to locate uploaded file. Check your webserver error logs and also make sure your post_max_size and max_upload_size parameters in php.ini are set larger than the file you are trying to upload.



If I try again right after -- it's ok -- just like with stories/static pages.

At one restart of Firefox, my bookmark bar was empty ==> conclusion: my install of Firefox is broken, will uninstall and start clean.

My addons don't get involved during usage: Download Statusbar, FoxClocks, Update Scanner and Web Developer.

Forum Newbie
Newbie

Group Comfort
Level:
: 0

Registered: 06/25/07
Posts: 14

Profile Email    
  Quote
By: max (offline)  Mar 31 2011 15:28 pm  
max

OK, I tried with a fresh FF4 and Chrome on another computer and recreated the problem with these steps:

1. Log in
2. Go to Static Pages
3. Wait the 20 minutes for session expiration
4. Click edit a static page -- the user/pass comes up to re-authenticate
5. Save static page (no need to actually edit anything) **security token invalid message**
6. Try to save again. This will work.

Forum Newbie
Newbie

Group Comfort
Level:
: 0

Registered: 06/25/07
Posts: 14

Profile Email    
  Quote
By: Mark (offline)  Mar 31 2011 15:32 pm  
Mark

Max - what you describe is how it is supposed to work...

Basically, the security token timed out after 20 minutes (by design, they can only live so long or they end up offering no protection). You submit, are told the toke is invalid but you have another chance to submit (with a new, fresh token).

So, it is doing what it is supposed to do. Try the same test, but don't wait 20 minutes, only wait 15 and you should see the save happen just fine without any token errors.

Thanks!
Mark

Forum Admin
Admin

Group Comfort
Level:
: +110

Registered: 10/21/05
Posts: 6331
Location: The Great State of
Texas

Profile      
  Quote
New Topic Post Reply

First | Previous | 1 2 | Next | Last

 All times are CDT. The time is now 04:28 pm.
Normal Topic Normal Topic
Locked Topic Locked Topic
Sticky Topic Sticky Topic
New Post New Post
Sticky Topic w/ New Post Sticky Topic w/ New Post
Locked Topic w/ New Post Locked Topic w/ New Post
View Anonymous Posts 
Able to Post 
HTML Allowed 
Censored Content