[Tickets #9289] Cannot save preferences after upgrade to 1.2.7. We cannot verify that this request was really sent by you. It could be a malicious request.

bugs at horde.org bugs at horde.org
Wed Oct 6 04:39:29 UTC 2010


DO NOT REPLY TO THIS MESSAGE. THIS EMAIL ADDRESS IS NOT MONITORED.

Ticket URL: http://bugs.horde.org/ticket/9289
------------------------------------------------------------------------------
  Ticket             | 9289
  Created By         | software-horde at interfasys.ch
  Summary            | Cannot save preferences after upgrade to 1.2.7. We
                     | cannot verify that this request was really sent by you.
                     | It could be a malicious request.
  Queue              | Horde Groupware Webmail Edition
  Version            | 1.2.7
  Type               | Bug
  State              | Unconfirmed
  Priority           | 3. High
  Milestone          |
  Patch              |
  Owners             |
------------------------------------------------------------------------------


software-horde at interfasys.ch (2010-10-06 00:39) wrote:

The users cannot save their preferences anymore.
They get the dreaded "We cannot verify that this request was really  
sent by you. It could be a malicious request. If you intended to  
perform this action, you can retry it now"

It also happens without having to save anything, by just going to the page:
services/prefs.php?app=imp&group=identities

There is nothing in the Horde log, appart from
IMAP errors: SECURITY PROBLEM: insecure server advertised AUTH=PLAIN

I've tried disabling tokens, cookies, nothing helped.
The server is running a dual IP stack (v4 and v6). Net_DNS has been  
removed because it doesn't work with IPv6.
We're using PHP sessions.






More information about the bugs mailing list