Hi,

I have configured fresh ESB pack with Nginx reverse proxy. Now when I try
to log into ESB console I get a "Error 403 - Forbidden". In the carbon log
it shows

TID: [-1234] [] [2016-09-01 15:46:17,417]  WARN
{org.owasp.csrfguard.log.JavaLogger} -  potential cross-site request
forgery (CSRF) attack thwarted (user:<anonymous>, ip:127.0.0.1,
method:POST, uri:/carbon//admin/js/csrfPrevention.js, error:required token
is missing from the request) {org.owasp.csrfguard.log.JavaLogger}
TID: [-1234] [] [2016-09-01 15:46:21,821]  WARN
{org.owasp.csrfguard.log.JavaLogger} -  potential cross-site request
forgery (CSRF) attack thwarted (user:<anonymous>, ip:127.0.0.1,
method:POST, uri:/carbon//admin/login_action.jsp, error:required token is
missing from the request) {org.owasp.csrfguard.log.JavaLogger}

Any ideas to fix this?

Best Regards
Jithendra

--
Jithendra Sirimanne
*Systems Engineer*
Mobile: +94 (0) 716 374696 <+94+(0)+716+374696>
Tel      : +94 112 145 345
Email  : [email protected]
_______________________________________________
Dev mailing list
[email protected]
http://wso2.org/cgi-bin/mailman/listinfo/dev

Reply via email to