Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Fix CSRF token issues #1057

Merged
merged 4 commits into from
Aug 6, 2024
Merged

Fix CSRF token issues #1057

merged 4 commits into from
Aug 6, 2024

Conversation

zurdi15
Copy link
Member

@zurdi15 zurdi15 commented Aug 5, 2024

RomM now detects if csrf token verification failed at login, regenerating the csrf token and attempting to login again, fixing once and for all the csrf token issues (hopefully 🥲)

Also added autocompletion option to login form

@zurdi15 zurdi15 requested a review from gantoine August 5, 2024 07:49
@zurdi15 zurdi15 self-assigned this Aug 5, 2024
@zurdi15 zurdi15 added bug Something isn't working ui/ux UI/UX improvements or suggestions labels Aug 5, 2024
Copy link

github-actions bot commented Aug 5, 2024

Test Results

72 tests  ±0   72 ✅ ±0   22s ⏱️ +2s
 1 suites ±0    0 💤 ±0 
 1 files   ±0    0 ❌ ±0 

Results for commit ada7f5f. ± Comparison against base commit cbab9f6.

♻️ This comment has been updated with latest results.

identityApi.logout().then(({ data }) => {
identityApi.logout().then(async ({ data }) => {
// Refetch CSRF token
await refetchCSRFToken();
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reset the CSRF token and logout and fetch a new one

router.push(next);
.then(async () => {
// Refetch CSRF token
await refetchCSRFToken();
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Same here but after login (new one will be fetched as well)

required
prepend-inner-icon="mdi-account"
type="text"
label="Username"
variant="underlined"
@keyup.enter="login()"
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

don't need these since you're using a password field

@gantoine gantoine merged commit 76d6798 into master Aug 6, 2024
9 checks passed
@gantoine gantoine deleted the fix/csrf-token branch August 6, 2024 23:18
@zurdi15 zurdi15 mentioned this pull request Aug 7, 2024
spiceratops added a commit to spiceratops/k8s-gitops that referenced this pull request Aug 20, 2024
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
| [rommapp/romm](https://github.com/rommapp/romm) | minor | `3.3.0` ->
`3.4.0` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.

---

### Release Notes

<details>
<summary>rommapp/romm (rommapp/romm)</summary>

### [`v3.4.0`](https://github.com/rommapp/romm/releases/tag/3.4.0)

[Compare
Source](https://github.com/rommapp/romm/compare/3.3.0...3.4.0)

#### What's Changed

- feat: Added link to home button by
[@&#8203;zurdi15](https://github.com/zurdi15) in
[rommapp/romm#1054
- feat: Public collections by
[@&#8203;gantoine](https://github.com/gantoine) in
[rommapp/romm#1028
- feat: Added aditional platform icons by
[@&#8203;Casuallynoted](https://github.com/Casuallynoted) in
[rommapp/romm#1038
- feat: Store and re-use last saved bios/save/state/core by
[@&#8203;gantoine](https://github.com/gantoine) in
[rommapp/romm#1037
- feat: Clickable filter buttons on details view by
[@&#8203;gantoine](https://github.com/gantoine) in
[rommapp/romm#1040
- feat: Add button to show duplicates by
[@&#8203;gantoine](https://github.com/gantoine) in
[rommapp/romm#1043
- fix: Scanning selected roms by
[@&#8203;gantoine](https://github.com/gantoine) in
[rommapp/romm#1042
- fix: Use namespaced cookie for session by
[@&#8203;adamantike](https://github.com/adamantike) in
[rommapp/romm#1009
- fix: Replace game-and-watch with g-and-w by
[@&#8203;gantoine](https://github.com/gantoine) in
[rommapp/romm#1026
- fix: Backend URL redirection logic by
[@&#8203;adamantike](https://github.com/adamantike) in
[rommapp/romm#1058
- fix: Enable flake8-async rules in ruff and fix warnings by
[@&#8203;adamantike](https://github.com/adamantike) in
[rommapp/romm#1030
- fix: Initialize context on scheduled task by
[@&#8203;adamantike](https://github.com/adamantike) in
[rommapp/romm#1033
- fix: Return early if IGDB finds an exact match by
[@&#8203;adamantike](https://github.com/adamantike) in
[rommapp/romm#1032
- fix: CSRF token issues by
[@&#8203;zurdi15](https://github.com/zurdi15) in
[rommapp/romm#1057
- fix: Link from related games by
[@&#8203;gantoine](https://github.com/gantoine) in
[rommapp/romm#1045
- fix: Typos in frontend by
[@&#8203;HellLord77](https://github.com/HellLord77) in
[rommapp/romm#1048
- fix: Firmware pagination by
[@&#8203;gantoine](https://github.com/gantoine) in
[rommapp/romm#1041
- fix: Multi-file download in gallery view by
[@&#8203;gantoine](https://github.com/gantoine) in
[rommapp/romm#1044
- fix: Remove persistent overlay prevents back navigation by
[@&#8203;gantoine](https://github.com/gantoine) in
[rommapp/romm#1036
- misc: Add Redis async cache by
[@&#8203;adamantike](https://github.com/adamantike) in
[rommapp/romm#1010
- misc: Create config.batocera-retrobat.yml by
[@&#8203;TyroneSlothrop](https://github.com/TyroneSlothrop) in
[rommapp/romm#1013
- misc: Migrate MobyGamesHandler to async by
[@&#8203;adamantike](https://github.com/adamantike) in
[rommapp/romm#1011
- misc: Migrate filesystem resource handler to async by
[@&#8203;adamantike](https://github.com/adamantike) in
[rommapp/romm#1017
- misc: Replace pytest-vcr dependency with pytest-recording by
[@&#8203;adamantike](https://github.com/adamantike) in
[rommapp/romm#1021
- misc: Refactor scan process by splitting single function by
[@&#8203;adamantike](https://github.com/adamantike) in
[rommapp/romm#1024
- misc: Migrate IGDBBaseHandler to async by
[@&#8203;adamantike](https://github.com/adamantike) in
[rommapp/romm#1023
- misc: Use PYTEST_VERSION variable to detect Pytest runs by
[@&#8203;adamantike](https://github.com/adamantike) in
[rommapp/romm#1034
- misc: Use async interface for stream-zip by
[@&#8203;adamantike](https://github.com/adamantike) in
[rommapp/romm#1035
- misc: Add workflow that runs typecheck on PRs by
[@&#8203;gantoine](https://github.com/gantoine) in
[rommapp/romm#1055
- misc: Make backend handle URLs with trailing slash by
[@&#8203;adamantike](https://github.com/adamantike) in
[rommapp/romm#1059
- misc: Drop ROMM_AUTH_USERNAME and ROMM_AUTH_PASSWORD env variables by
[@&#8203;gantoine](https://github.com/gantoine) in
[rommapp/romm#1060

#### New Contributors

- [@&#8203;TyroneSlothrop](https://github.com/TyroneSlothrop) made
their first contribution in
[rommapp/romm#1013

**Full Changelog**:
rommapp/romm@3.3.0...3.4.0

</details>

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined),
Automerge - At any time (no schedule defined).

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzOC4yMS4zIiwidXBkYXRlZEluVmVyIjoiMzguMjEuMyIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOlsicmVub3ZhdGUvY29udGFpbmVyIiwidHlwZS9taW5vciJdfQ==-->
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working ui/ux UI/UX improvements or suggestions
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants