Open nurradityam opened 6 months ago
Hi @nurradityam, This is by design really and applies to all forms within BookStack.
@ssddanbrown Can you clarify how CSRF tokens are reissued on session timeout, creation & end?
For example—say there are two tabs of bookstack open at the login page. A user can use one page to log into the app, do their thing and then close that tab. Come back in a few minutes to the previously open login tab, attempt a login and they'll receive a 419. Is there any keep-alive support for bookstack-issued CSRF tokens?
Describe the Bug
I just noticed the login page when configured with Single Sign On did not automatically refreshed, so if a user logged out or inactive in login page for a long time then try login, it show 419 Page Expired error, the current workaround was refreshing the page
Steps to Reproduce
Expected Behaviour
after click login it should redirected to SSO login page
Screenshots or Additional Context
No response
Browser Details
No response
Exact BookStack Version
v24.02.2