# CSRF login error after upgrade to 2.5.0.beta4

**URL:** https://meta.discourse.org/t/csrf-login-error-after-upgrade-to-2-5-0-beta4/150423
**Category:** Support
**Created:** [5 במאי,‏ 2020,‏ 10:51am UTC](https://meta.discourse.org/t/csrf-login-error-after-upgrade-to-2-5-0-beta4/150423 "2020-05-05T10:51:49Z")
**Posts on this page:** 1
**Showing post:** 5

<div class="post-metadata">

### Author: ![rossierd](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/rossierd/32/164604_2.png) [@rossierd](https://meta.discourse.org/u/rossierd)
#### Post date: [23 במאי,‏ 2020,‏ 6:03pm UTC](https://meta.discourse.org/t/csrf-login-error-after-upgrade-to-2-5-0-beta4/150423/5 "2020-05-23T18:03:36Z")

</div>

I’ve had exactly the same issue after the upgrade to 2.5.0.beta4 ([Moved site behind proxy, favicon and header not using https anymore - #7 by rossierd](https://meta.discourse.org/t/moved-site-behind-proxy-favicon-and-header-not-using-https-anymore/131486/7)).

Were you able to fix the issue? I can imagine that the upgrade came with a new version of nginx (or its config) which leads to this issue (but pure hypothetical ;-))  
I tried to find a way to disable CSRF in nginx ([GitHub - gartnera/nginx\_csrf\_prevent: Prevent CSRF with nginx · GitHub](https://github.com/gartnera/nginx_csrf_prevent)) but I think nginx must be recompiled, and I don’t know if we need the complete development environment of Discourse to do that.

---

_[View the full topic](https://meta.discourse.org/t/csrf-login-error-after-upgrade-to-2-5-0-beta4/150423)._
