Hi Maxim,

thanks for your help. Because the test server works, I suspected that it might be a problem with my https-proxy. I had a "Redirect/ https://domain.org/openmeetings"; rule in my apache2 site conf together with some ProxyPass(Reverse) rules.

I changed to RewriteEngine rules according to your post: https://stackoverflow.com/questions/51721771/apache-openmeetings-4-0-4-csrf-attack-when-using-apache2-as-proxypass/51783235#51783235.

Now everything works as expected.

Best regards and a happy new year,
Thomas


Am 30.12.20 um 14:08 schrieb Maxim Solodovnik:
both versions works for me :(
unfortunately i can't fix the issue until i can reproduce it :(((


On Wed, 30 Dec 2020 at 19:38, Thomas Scholzen <[email protected] <mailto:[email protected]>> wrote:

    Just testet this https://om.alteametasoft.com/openmeetings/
    <https://om.alteametasoft.com/openmeetings/>

    Shall I will test the other, too?

    Am 30.12.20 um 12:16 schrieb Maxim Solodovnik:
    Just to clarify

    https://om.alteametasoft.com:8443/next/
    <https://om.alteametasoft.com:8443/next/> has more or less latest
    6.0.0-SNAPSHOT installed
    https://om.alteametasoft.com/openmeetings/
    <https://om.alteametasoft.com/openmeetings/> has 5.1.0 with few
    fixes from 6.0.0

    both work for you as expected?

    On Tue, 29 Dec 2020 at 21:04, Thomas Scholzen
    <[email protected] <mailto:[email protected]>> wrote:

        I am using Version5.1.0 Revision 6691181
        Builddate2020-12-01T15:49:37Z.

        I could not reproduce the problem on the test server.

        Best regards,

        Thomas

        Am 29.12.20 um 14:37 schrieb Maxim Solodovnik:
        What version are you using?
        Is it reproducible for at om.alteametasoft** demo servers?

        from mobile (sorry for typos ;)

        On Tue, Dec 29, 2020, 20:33 Thomas Scholzen
        <[email protected] <mailto:[email protected]>> wrote:

            Hi Maxim,

            thanks for your help. The problem is that by using a
            link a second time within the valid period (or endless
            link) there is no login possible. If the "access denied"
            page would appear, the user could logoff. But instead
            the circling login icon is going on endlessly. Only when
            shortening the link to the domain without the hash, the
            user can logout and subsequently login with the complete
            invitation link.

            Best regards,
            Thomas

            Am 29.12.20 um 12:24 schrieb Maxim Solodovnik:
            Hello Thomas,


            On Tue, 29 Dec 2020 at 02:05, Thomas Scholzen
            <[email protected] <mailto:[email protected]>> wrote:

                Dear all,

                if external users enter via an invitation hash they
                can only logoff by closing the browser (tab). When
                trying to relogin using the same invitation


            What do you mean by "relogin using the same invitation"?
            The invitation is endless or period?

                the login hangs at the circling icon. Only when
                going to domain.org/openmeetings
                <http://domain.org/openmeetings> an „access denied“
                warning is shown and the user can press „logoff“.
                After this the user can use the invitation to login
                again.

                Is there a misconfiguration in my OM setup? I
                appreciate any help with this.

                Best regards,
                Thomas



-- Best regards,
            Maxim



-- Best regards,
    Maxim



--
Best regards,
Maxim

Reply via email to