Monday, October 4, 2010

Security: Token is not accepted anymore when creating/updating user

Good new week, everybody.

I just noticed that I can't create/updated users anymore in my app.
I'm always getting a white screen of death when trying it. I tracked
it down to the security component that checks the submitted form data
(_validatePost()), and the token submitted through the form doesn't
equal the check value.

I'm trying to track down where's the problem (it does only happen when
creating/updating a user; all the other models work), but it's rather
difficult for me because I'm new to the check/token-paradigm...

So maybe someone could point me to an explanation of this? The source
code of CakePHP isn't too well documented on this topic, sadly.

As far as I can see, a token is some sort of "validation value" that
is generated when the form is displayed to the user. Then after
submitting, the token is re-generated and compared to the submit
token. But I don't really understand what's this useful for.

Thanks a lot for help, I'm working on this issues for hours now and
I'm quite lost at the moment.
Joshua

Check out the new CakePHP Questions site http://cakeqs.org and help others with their CakePHP related questions.

You received this message because you are subscribed to the Google Groups "CakePHP" group.
To post to this group, send email to cake-php@googlegroups.com
To unsubscribe from this group, send email to
cake-php+unsubscribe@googlegroups.com For more options, visit this group at http://groups.google.com/group/cake-php?hl=en

0 Comments:

Post a Comment

Subscribe to Post Comments [Atom]

<< Home


Real Estate