PennyDreadfulMTG / perf-reports

2 stars 2 forks source link

500 error at /authenticate/callback/ #42669

Closed vorpal-buildbot closed 5 years ago

vorpal-buildbot commented 5 years ago

(mismatching_state) CSRF Warning! State not equal in request and response.

Reported on decksite by adna

            --------------------------------------------------------------------------------
            Request Method: GET
            Path: /authenticate/callback/?state=L6OTozTTvqUjhsHMuFNrzC4GlH4N92&code=NY2S85HFh9R8EHGDqh3uD7cuTtZi5K
            Cookies: {'__cfduid': 'd9899b9cb8f249b7b861915e64ee4f9a31548471597', '_ga': 'GA1.2.1012176152.1548471599', 'session': '.eJx9UV1PgzAU_S_3mRgYhdE9Tufc1mmMk2waQzooHxNa0g8zsuy_W0iUBxMfz7mn59x7eoGkZbKhnHENMy0Nc4BmTcVhltNaWZSxpmpENuJKpUJmSWUpQC7CfuRNMfZR5KGJF4ED_0x4UpiqHs1qkdKaWfmJQo-KgmX9QkrwIWDi-4EDjS5EYhSTnDa9mGa8lwtqdDlJlKZ6sMiReSPHjVoReb9_jnf7fXyadkuSlmJNRr0Wn8yedwGapkypHwzh63Qeo5eA6IY8LKKlDncEe6virn5qjW_fs3NbSaYSapvyAoRd7GHs3URR4IYYjfO-vNBFkes6IFluqfI3hM237ReOj-cD3S7EhnYnQ_WjJrfNWhxKG2LLbe0177ZF-yVV3llu6EzBhwODTaK7XgJzRiWTcHXgT2OayoLZNbmp6-s3x4mbNA.DzxN2g.kQEQxMcdB4dw-tVhHNli1BJv8ws', '_gid': 'GA1.2.906406599.1549450331'}
            Endpoint: authenticate_callback
            View Args: {}
            Person: 404938179934814218
            Referrer: https://discordapp.com/oauth2/authorize?response_type=code&client_id=338056190779195392&redirect_uri=https%3A%2F%2Fpennydreadfulmagic.com%2Fauthenticate%2Fcallback%2F&scope=identify+guilds&state=L6OTozTTvqUjhsHMuFNrzC4GlH4N92
            Request Data: {}
Host: pennydreadfulmagic.com
Accept-Encoding: gzip
Cf-Ipcountry: JP
X-Forwarded-For: 220.7.34.188, 103.22.200.74
Cf-Ray: 4a4d17abf9ce6eed-NRT
X-Forwarded-Proto: https
Cf-Visitor: {"scheme":"https"}
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:64.0) Gecko/20100101 Firefox/64.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: ja,en-US;q=0.7,en;q=0.3
Referer: https://discordapp.com/oauth2/authorize?response_type=code&client_id=338056190779195392&redirect_uri=https%3A%2F%2Fpennydreadfulmagic.com%2Fauthenticate%2Fcallback%2F&scope=identify+guilds&state=L6OTozTTvqUjhsHMuFNrzC4GlH4N92
Upgrade-Insecure-Requests: 1
Cookie: __cfduid=d9899b9cb8f249b7b861915e64ee4f9a31548471597; _ga=GA1.2.1012176152.1548471599; session=.eJx9UV1PgzAU_S_3mRgYhdE9Tufc1mmMk2waQzooHxNa0g8zsuy_W0iUBxMfz7mn59x7eoGkZbKhnHENMy0Nc4BmTcVhltNaWZSxpmpENuJKpUJmSWUpQC7CfuRNMfZR5KGJF4ED_0x4UpiqHs1qkdKaWfmJQo-KgmX9QkrwIWDi-4EDjS5EYhSTnDa9mGa8lwtqdDlJlKZ6sMiReSPHjVoReb9_jnf7fXyadkuSlmJNRr0Wn8yedwGapkypHwzh63Qeo5eA6IY8LKKlDncEe6virn5qjW_fs3NbSaYSapvyAoRd7GHs3URR4IYYjfO-vNBFkes6IFluqfI3hM237ReOj-cD3S7EhnYnQ_WjJrfNWhxKG2LLbe0177ZF-yVV3llu6EzBhwODTaK7XgJzRiWTcHXgT2OayoLZNbmp6-s3x4mbNA.DzxN2g.kQEQxMcdB4dw-tVhHNli1BJv8ws; _gid=GA1.2.906406599.1549450331
Cf-Connecting-Ip: 220.7.34.188
Cdn-Loop: cloudflare
X-Forwarded-Host: pennydreadfulmagic.com
X-Forwarded-Server: pennydreadfulmagic.com
Connection: Keep-Alive

MismatchingStateError (mismatching_state) CSRF Warning! State not equal in request and response. Stack Trace:

  File "/home/discord/.local/lib/python3.6/site-packages/flask/app.py", line 2309, in __call__
    return self.wsgi_app(environ, start_response)
  File "/home/discord/.local/lib/python3.6/site-packages/flask/app.py", line 2295, in wsgi_app
    response = self.handle_exception(e)
  File "/home/discord/.local/lib/python3.6/site-packages/flask/app.py", line 2292, in wsgi_app
    response = self.full_dispatch_request()
  File "/home/discord/.local/lib/python3.6/site-packages/flask/app.py", line 1815, in full_dispatch_request
    rv = self.handle_user_exception(e)
  File "/home/discord/.local/lib/python3.6/site-packages/flask/app.py", line 1718, in handle_user_exception
    reraise(exc_type, exc_value, tb)
  File "/home/discord/.local/lib/python3.6/site-packages/flask/_compat.py", line 35, in reraise
    raise value
  File "/home/discord/.local/lib/python3.6/site-packages/flask/app.py", line 1813, in full_dispatch_request
    rv = self.dispatch_request()
  File "/home/discord/.local/lib/python3.6/site-packages/flask/app.py", line 1799, in dispatch_request
    return self.view_functions[rule.endpoint](**req.view_args)
  File "./shared_web/flask_app.py", line 97, in authenticate_callback
    oauth.setup_session(request.url)
  File "./shared_web/oauth.py", line 27, in setup_session
    authorization_response=url)
  File "/home/discord/.local/lib/python3.6/site-packages/requests_oauthlib/oauth2_session.py", line 208, in fetch_token
    state=self._state)
  File "/home/discord/.local/lib/python3.6/site-packages/oauthlib/oauth2/rfc6749/clients/web_application.py", line 203, in parse_request_uri_response
    response = parse_authorization_code_response(uri, state=state)
  File "/home/discord/.local/lib/python3.6/site-packages/oauthlib/oauth2/rfc6749/parameters.py", line 271, in parse_authorization_code_response
    raise MismatchingStateError()

Exception_hash: b1e0b4491d6eb60c6eb30b28b4d0eb6e0ee0982e

vorpal-buildbot commented 5 years ago

500 error at /authenticate/callback/

(mismatching_state) CSRF Warning! State not equal in request and response.

Reported on decksite by bakert99

            --------------------------------------------------------------------------------
            Request Method: GET
            Path: /authenticate/callback/?state=L6OTozTTvqUjhsHMuFNrzC4GlH4N92&code=RTNFpV8GHAiexC7n2hFFEsT4VdrSLr
            Cookies: {'__cfduid': 'dbbaeaf004b46114da480ca1ea67b1fe41519487476', 'hide_intro': 'True', '_ga': 'GA1.2.336853490.1519750417', 'session': '.eJx1kNtuwjAQRP9ln6PKTpxAeGvpDQqiVxCtqsiNN8bCuch2Wiji3-sgUaRKfZyd2R377CBr0JS8wsrBwJkWA-CiVNVRCGXz2ohMCRgATeOEsZT2SJ8yRsIkhgD-d3Sdc43exeqgpETR1dm6OtyjLAqgdLLOWoum4mWX_eBrNC5N_UbNW7cKM-u465wmvp7fr75H00cqeKhuinEyuzyPWjXXxbw85V299oWDHfA8R2uPGoSdbtjLWGrFGjV5kKPnoS0mS_IaueXC-H3cNMqgzbhHQeMwpmGapNEZSdJe1Kcnv6OTENYnJACDhR-tfkvC5OnudjIbkofPq5EsvsajHInuLejMyM3Ql3icjf_Nm-fmmati62eyVVpYeA_gcCZz2y4CF8gNGtgH8Bea40aif2XVar3_Abpoj4o.Dzx_xQ.zpqyginyEi6W9gwuuBzNW5bgYLk', '_gid': 'GA1.2.1940173015.1548094837', 'deck_id': '36493'}
            Endpoint: authenticate_callback
            View Args: {}
            Person: 195644917081440265
            Referrer: https://discordapp.com/oauth2/authorize?response_type=code&client_id=338056190779195392&redirect_uri=https%3A%2F%2Fpennydreadfulmagic.com%2Fauthenticate%2Fcallback%2F&scope=identify+guilds&state=L6OTozTTvqUjhsHMuFNrzC4GlH4N92
            Request Data: {}
Host: pennydreadfulmagic.com
Accept-Encoding: gzip
Cf-Ipcountry: US
X-Forwarded-For: 136.25.151.171, 172.69.22.52
Cf-Ray: 4a4e5a640c576c10-SJC
X-Forwarded-Proto: https
Cf-Visitor: {"scheme":"https"}
Upgrade-Insecure-Requests: 1
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_14_2) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/71.0.3578.98 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,image/apng,*/*;q=0.8
Referer: https://discordapp.com/oauth2/authorize?response_type=code&client_id=338056190779195392&redirect_uri=https%3A%2F%2Fpennydreadfulmagic.com%2Fauthenticate%2Fcallback%2F&scope=identify+guilds&state=L6OTozTTvqUjhsHMuFNrzC4GlH4N92
Accept-Language: en-US,en;q=0.9,es;q=0.8
Cookie: __cfduid=dbbaeaf004b46114da480ca1ea67b1fe41519487476; hide_intro=True; _ga=GA1.2.336853490.1519750417; session=.eJx1UMtuwjAQ_Jc9R5WdOIFwa-krFETpA0SrKnLjjbEwSWQ7LRTx73WQWqRKPc7OzM7u7IGLjapg4EyLAQhli9qIXAkYAE3jhLGU9kifMkbCJIYA_md0XXCNnsXqiKREkTdobF0d91EWBbBxss5bi6bim077ztdoXJp6R81btwpz67jrmCa-nt-vvrLJAxU8VDflKJlenketmutyvjnpXb32gYM98KJAa38wCDvZsueR1Io1ajyT2dPQluMleYnccmG8H7eNMmhz7vxtcRjTME3S6IwkaS_q0xPftZMQ1ickAIOlH61-Q8Lk8e52PB2S2cdVJsvPUVYg0b0FnRq5HfoQX2fjv3n1vWHlVLnzM9kqLSy8BXBck7tdJ4EL5AYNHAL4W5rjRqK_smq1PnwDU6SI9w.Dfj1kQ.6zIYF2Bw9YqqBtAVtkhDIFSf-AA; _gid=GA1.2.1940173015.1548094837; deck_id=36493; session=.eJx1kNtuwjAQRP9ln6PKTpxAeGvpDQqiVxCtqsiNN8bCuch2Wiji3-sgUaRKfZyd2R377CBr0JS8wsrBwJkWA-CiVNVRCGXz2ohMCRgATeOEsZT2SJ8yRsIkhgD-d3Sdc43exeqgpETR1dm6OtyjLAqgdLLOWoum4mWX_eBrNC5N_UbNW7cKM-u465wmvp7fr75H00cqeKhuinEyuzyPWjXXxbw85V299oWDHfA8R2uPGoSdbtjLWGrFGjV5kKPnoS0mS_IaueXC-H3cNMqgzbhHQeMwpmGapNEZSdJe1Kcnv6OTENYnJACDhR-tfkvC5OnudjIbkofPq5EsvsajHInuLejMyM3Ql3icjf_Nm-fmmati62eyVVpYeA_gcCZz2y4CF8gNGtgH8Bea40aif2XVar3_Abpoj4o.Dzx_xQ.zpqyginyEi6W9gwuuBzNW5bgYLk
Cf-Connecting-Ip: 136.25.151.171
Cdn-Loop: cloudflare
X-Forwarded-Host: pennydreadfulmagic.com
X-Forwarded-Server: pennydreadfulmagic.com
Connection: Keep-Alive

MismatchingStateError (mismatching_state) CSRF Warning! State not equal in request and response. Stack Trace:

  File "/home/discord/.local/lib/python3.6/site-packages/flask/app.py", line 2309, in __call__
    return self.wsgi_app(environ, start_response)
  File "/home/discord/.local/lib/python3.6/site-packages/flask/app.py", line 2295, in wsgi_app
    response = self.handle_exception(e)
  File "/home/discord/.local/lib/python3.6/site-packages/flask/app.py", line 2292, in wsgi_app
    response = self.full_dispatch_request()
  File "/home/discord/.local/lib/python3.6/site-packages/flask/app.py", line 1815, in full_dispatch_request
    rv = self.handle_user_exception(e)
  File "/home/discord/.local/lib/python3.6/site-packages/flask/app.py", line 1718, in handle_user_exception
    reraise(exc_type, exc_value, tb)
  File "/home/discord/.local/lib/python3.6/site-packages/flask/_compat.py", line 35, in reraise
    raise value
  File "/home/discord/.local/lib/python3.6/site-packages/flask/app.py", line 1813, in full_dispatch_request
    rv = self.dispatch_request()
  File "/home/discord/.local/lib/python3.6/site-packages/flask/app.py", line 1799, in dispatch_request
    return self.view_functions[rule.endpoint](**req.view_args)
  File "./shared_web/flask_app.py", line 97, in authenticate_callback
    oauth.setup_session(request.url)
  File "./shared_web/oauth.py", line 27, in setup_session
    authorization_response=url)
  File "/home/discord/.local/lib/python3.6/site-packages/requests_oauthlib/oauth2_session.py", line 208, in fetch_token
    state=self._state)
  File "/home/discord/.local/lib/python3.6/site-packages/oauthlib/oauth2/rfc6749/clients/web_application.py", line 203, in parse_request_uri_response
    response = parse_authorization_code_response(uri, state=state)
  File "/home/discord/.local/lib/python3.6/site-packages/oauthlib/oauth2/rfc6749/parameters.py", line 271, in parse_authorization_code_response
    raise MismatchingStateError()

Exception_hash: b1e0b4491d6eb60c6eb30b28b4d0eb6e0ee0982e

Labels: decksite; MismatchingStateError

vorpal-buildbot commented 5 years ago

500 error at /authenticate/callback/

(mismatching_state) CSRF Warning! State not equal in request and response.

Reported on decksite by tidalslimshady


Request Data ``` Request Method: GET Path: /authenticate/callback/?state=t0KHgEqfqJVMCD7oMIw5vajfbrnHET&code=5eeuGKWcBG5Kh7HxQC7vLG0U0X7lyJ Cookies: {'__cfduid': 'd743ebfd29dbccfe3792e8230835e91bd1551782848', 'session': '.eJx9UctugzAQ_BefUQUYgsktSGmolFZNUtKXKuRiA06wobapkkb59y6RWg6Vepyd3dmd2RPKO64lVVxZNLW65w6iTAqFpiVtDCDGpZAtG7EwRatZLqCEAuLGXuD7OAjjyI8D30UO-odRedWLZhRr2qribDjBtOoiiX0ycZC0VZv3hmtFJQc1KxgMNEKamrIjKLW0t7WfG0vtwJcmnT0cnpos2-4if_6x2hdq_XmDH-Vyxb7GftvuOVg7IVoU3JgfjKJ4n22SRWdFP_N3i_fnxFt-RvNtlqUEezDPD53Q3OQUUvLCEAeRhwm5CjCJ4wiP_BDcxAXzroM0L6FU_y5ZX-sdDuMX756E6Ty73Ry3PJkl9fJARHoHSyDYDty8QoLwDlEORi95GfTmoItMbo9DC0o41Vyjs4P-ZGeprjicqfqmOX8DsuaZzA.D3BusA.3W9jLkX9zhsQlE8hkOTpUcvjrak'} Endpoint: authenticate_callback View Args: {} Person: 480914223459729420 Referrer: https://discordapp.com/oauth2/authorize?response_type=code&client_id=338056190779195392&redirect_uri=https%3A%2F%2Fpennydreadfulmagic.com%2Fauthenticate%2Fcallback%2F&scope=identify+guilds&state=t0KHgEqfqJVMCD7oMIw5vajfbrnHET Request Data: {} Host: pennydreadfulmagic.com Accept-Encoding: gzip Cf-Ipcountry: CA X-Forwarded-For: 67.22.75.202, 162.158.126.6 Cf-Ray: 4b92de554b30ca55-YUL X-Forwarded-Proto: https Cf-Visitor: {"scheme":"https"} Upgrade-Insecure-Requests: 1 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,image/apng,*/*;q=0.8 Referer: https://discordapp.com/oauth2/authorize?response_type=code&client_id=338056190779195392&redirect_uri=https%3A%2F%2Fpennydreadfulmagic.com%2Fauthenticate%2Fcallback%2F&scope=identify+guilds&state=t0KHgEqfqJVMCD7oMIw5vajfbrnHET Accept-Language: en-US,en;q=0.9 Cookie: __cfduid=d743ebfd29dbccfe3792e8230835e91bd1551782848; session=.eJx9UctugzAQ_BefUQUYgsktSGmolFZNUtKXKuRiA06wobapkkb59y6RWg6Vepyd3dmd2RPKO64lVVxZNLW65w6iTAqFpiVtDCDGpZAtG7EwRatZLqCEAuLGXuD7OAjjyI8D30UO-odRedWLZhRr2qribDjBtOoiiX0ycZC0VZv3hmtFJQc1KxgMNEKamrIjKLW0t7WfG0vtwJcmnT0cnpos2-4if_6x2hdq_XmDH-Vyxb7GftvuOVg7IVoU3JgfjKJ4n22SRWdFP_N3i_fnxFt-RvNtlqUEezDPD53Q3OQUUvLCEAeRhwm5CjCJ4wiP_BDcxAXzroM0L6FU_y5ZX-sdDuMX756E6Ty73Ry3PJkl9fJARHoHSyDYDty8QoLwDlEORi95GfTmoItMbo9DC0o41Vyjs4P-ZGeprjicqfqmOX8DsuaZzA.D3BusA.3W9jLkX9zhsQlE8hkOTpUcvjrak Cf-Connecting-Ip: 67.22.75.202 Cdn-Loop: cloudflare X-Forwarded-Host: pennydreadfulmagic.com X-Forwarded-Server: pennydreadfulmagic.com Connection: Keep-Alive ```

MismatchingStateError (mismatching_state) CSRF Warning! State not equal in request and response. Stack Trace: ``` Python traceback File "/home/discord/.local/lib/python3.6/site-packages/flask/app.py", line 2309, in __call__ return self.wsgi_app(environ, start_response) File "/home/discord/.local/lib/python3.6/site-packages/flask/app.py", line 2295, in wsgi_app response = self.handle_exception(e) File "/home/discord/.local/lib/python3.6/site-packages/flask/app.py", line 2292, in wsgi_app response = self.full_dispatch_request() File "/home/discord/.local/lib/python3.6/site-packages/flask/app.py", line 1815, in full_dispatch_request rv = self.handle_user_exception(e) File "/home/discord/.local/lib/python3.6/site-packages/flask/app.py", line 1718, in handle_user_exception reraise(exc_type, exc_value, tb) File "/home/discord/.local/lib/python3.6/site-packages/flask/_compat.py", line 35, in reraise raise value File "/home/discord/.local/lib/python3.6/site-packages/flask/app.py", line 1813, in full_dispatch_request rv = self.dispatch_request() File "/home/discord/.local/lib/python3.6/site-packages/flask/app.py", line 1799, in dispatch_request return self.view_functions[rule.endpoint](**req.view_args) File "./shared_web/flask_app.py", line 97, in authenticate_callback oauth.setup_session(request.url) File "./shared_web/oauth.py", line 27, in setup_session authorization_response=url) File "/home/discord/.local/lib/python3.6/site-packages/requests_oauthlib/oauth2_session.py", line 208, in fetch_token state=self._state) File "/home/discord/.local/lib/python3.6/site-packages/oauthlib/oauth2/rfc6749/clients/web_application.py", line 203, in parse_request_uri_response response = parse_authorization_code_response(uri, state=state) File "/home/discord/.local/lib/python3.6/site-packages/oauthlib/oauth2/rfc6749/parameters.py", line 271, in parse_authorization_code_response raise MismatchingStateError() ```

Exception_hash: b1e0b4491d6eb60c6eb30b28b4d0eb6e0ee0982e

Labels: decksite; MismatchingStateError