[Tickets #7669] Re: Clarify that actions prevented by CSRF tokens can be retried

bugs at horde.org bugs at horde.org
Mon Dec 8 22:53:55 UTC 2008


DO NOT REPLY TO THIS MESSAGE. THIS EMAIL ADDRESS IS NOT MONITORED.

Ticket URL: http://bugs.horde.org/ticket/7669
------------------------------------------------------------------------------
  Ticket             | 7669
  Updated By         | meinzerj at reed.edu
  Summary            | Clarify that actions prevented by CSRF tokens can be
                     | retried
  Queue              | IMP
  Version            | 4.3
  Type               | Bug
  State              | Resolved
  Priority           | 2. Medium
  Milestone          |
  Patch              |
  Owners             | Chuck Hagenbuch
------------------------------------------------------------------------------


meinzerj at reed.edu (2008-12-08 17:53) wrote:

There is one more case where this feature needs improvement.  When our  
users click "Log Out" after idling for > 30 minutes, they receive an  
unstyled white page with only the following text:

"This request cannot be completed because the link you followed or the  
form you submitted was only valid for 30 minutes."

There is no indication that the action can be retried.  Indeed, it  
looks like a server error to many users because it is just text on an  
otherwise blank page.  Worse, they may be misled into thinking that  
they have logged out.





More information about the bugs mailing list