[AIUTO] Impossibile accedere, errore "BAD CSRF"

Ciao a tutti,

Ho installato Discourse sul mio server e ha funzionato per lungo tempo senza alcun problema. Tuttavia, dopo l’ultimo aggiornamento, ho scoperto che tutti gli account utente non riescono ad accedere, inclusi quelli degli amministratori.

Dopo un po’ ho iniziato a sospettare che si trattasse di un problema legato a un plugin, quindi ho rimosso tutti i plugin e ho eseguito ./launcher rebuild app per far girare la versione pura e semplice di Discourse, ma senza successo. Al momento, sembra che il nostro sito sia in sola lettura e non sia possibile eseguire alcuna azione oltre alla lettura dei thread.

Ogni volta che si invia un modulo di accesso, viene visualizzato questo messaggio e non abbiamo idea di cosa significhi.

Il sito si trova all’indirizzo https://discuss.stickyricelove.com e siamo un’organizzazione non profit che si occupa di educazione e promozione della sessualità a Hong Kong, per adolescenti e per rispondere alle loro curiosità e dubbi.

Non vediamo l’ora di ricevere una risposta il più presto possibile:weary::sob:
Grazie.

It looks like one of your plugins is not compatible with the current version of Discourse. I suggest removing all third party (non-official) plugins and rebuilding.

It is already a clean build without plugins, only with the docker_manager. Should I remove that too?

Hmm, did you try upgrading at the command line?

Please SSH into your server and run:

cd /var/discourse
git pull
./launcher rebuild app

I have already tried this many many times, and it still shows the same error.

I’m now removing the docker_manager and rebuilding it.

Is this an install that followed our official install guide? Any errors in the rebuild?

Yes I have followed the exact steps carefully, and it’s a “no” for the errors. It builds smoothly that I can’t even tell what has gone wrong.

Will extract the backups and rebuild the VPS if nothing works out today. :sob:

Do you have this behind cloudflare or anything like that? @sam do you see anything in the pictured JS console errors that would indicate what is the issue?

We have consider that issue too, therefore a month ago we completely disabled all Cloudflare features, will also consider moving out Cloudflare since it brings enough troubles for us.

Will there be any override that I can force my current session as an admin? In that way I can get into the backend and see what’s the log telling :worried:

Hello,

I manage a small discourse forum for an opensource project and we have something that looks like the same problem. The error is exactly the same with google chrome, but is different with firefox : the login dialog works normally, the page is refreshed but it does not log me in (screenshots bellow).

It’s a dedicated host, and it doesn’t change much if I rebuild with beta, previous beta, or “tests-passed”. We don’t use cloudfare, but it’s behind a nginx reverse proxy (nothing too fancy). The discourse container is http, but nginx serves it in https through the reverse proxy, if that makes any difference.

I would appreciate any idea if there is something I can try.

Regards,

Stephane

@codinghorror @sam Will that be an upstream bug?

We have no repro of this, so it is likely something about your local setup.

Stiamo ricostruendo il VPS e installando una nuova istanza di Discourse; si è verificato quanto segue e il processo si è bloccato per un po’:

Is there a solution? We have the same problem…

It appears to us an upgrade issue. We have backup away the data, and performed a clean install and backup restoration.

However other than that, I have no idea what caused this issue.

Hello. I tried to run it without the nginx reverse proxy and it did not resolve the issue. Will run a reinstall tomorrow except if anyone think about something that could help by that time.

I noticed that by default, the launcher rebuild script was checking out the “tests-passed” version. Is it a bit dangerous ? should it be beta ? When I update from the admin web screen, it update to the most recent beta instead ?

I had to launch a rebuild before the problem appeared because the host ip from inside the container changed. The host is also my mailserver, and the mail config was in app.yml.

Is it possible that with the rebuild, I updated to a version that somehow corrupted the config ? (I launched the rebuild around 11/02/2016 07:00 PM if that’s any help).

Regards,

Stephane

In future if you feel your issue was not resolved, flag to reopen topic and DON’T accept an answer on the topic.

If you are running a reverse proxy 99.999% the issue is that you are not passing headers right to discourse.