Re: [rt-users] Some users getting CSRF warnings when creating tickets?

2016-09-27 Thread Todd Wade
On 9/27/16 9:17 AM, Alex Hall wrote: That makes me wonder: would having two subdomains do it? I have tickets.domain.com and rt.domain.com both going to the same thing, but rt.autodist.com is the actual domain in the configuration files. Yes this would do it. There is a config option to allow

Re: [rt-users] Some users getting CSRF warnings when creating tickets?

2016-09-27 Thread Sean Cwiek
Hey Alex, We’ve seen this when users are jumping between the http and https versions of our RT instance. Advising everyone to login at the https address seemed to resolve it for us. Thanks. -Sean From: rt-users [mailto:rt-users-boun...@lists.bestpractical.com] On Behalf Of Alex Hall Sent:

Re: [rt-users] Some users getting CSRF warnings when creating tickets?

2016-09-27 Thread Alex Hall
That makes me wonder: would having two subdomains do it? I have tickets.domain.com and rt.domain.com both going to the same thing, but rt.autodist.com is the actual domain in the configuration files. I wonder if starting from tickets.domain.com would cause this warning, as the browser sees one