little-pager-97837
09/27/2022, 10:56 AM{
"id": "security_csrf_violation",
"code": 403,
"reason": "Please retry the flow and optionally clear your cookies. The request was rejected to protect you from Cross-Site-Request-Forgery (CSRF) which could cause account takeover, leaking personal information, and other serious security issues.",
"status": "Forbidden",
"details": {
"docs": "<https://www.ory.sh/kratos/docs/debug/csrf>",
"hint": "The anti-CSRF cookie was found but the CSRF token was not included in the HTTP request body (csrf_token) nor in the HTTP Header (X-CSRF-Token).",
"reject_reason": "The HTTP Cookie Header was set and a CSRF token was sent but they do not match. We recommend deleting all cookies for this domain and retrying the flow."
},
"message": "the request was rejected to protect you from Cross-Site-Request-Forgery"
}
little-pager-97837
09/27/2022, 10:56 AMsteep-lamp-91158
little-pager-97837
10/05/2022, 9:22 AMcurl "<https://127.0.0.1:4433/self-service/registration?flow=f305421e-149f-4dbc-981e-446af9ac8529>" ^
-H "authority: 127.0.0.1:4433" ^
-H "accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9" ^
-H "accept-language: en-US,en;q=0.9" ^
-H "cache-control: max-age=0" ^
-H "content-type: application/x-www-form-urlencoded" ^
-H "origin: <http://127.0.0.1:4455>" ^
-H "referer: <http://127.0.0.1:4455/>" ^
-H "sec-ch-ua: ^\^"Google Chrome^\^";v=^\^"105^\^", ^\^"Not)A;Brand^\^";v=^\^"8^\^", ^\^"Chromium^\^";v=^\^"105^\^"" ^
-H "sec-ch-ua-mobile: ?0" ^
-H "sec-ch-ua-platform: ^\^"Windows^\^"" ^
-H "sec-fetch-dest: document" ^
-H "sec-fetch-mode: navigate" ^
-H "sec-fetch-site: cross-site" ^
-H "sec-fetch-user: ?1" ^
-H "upgrade-insecure-requests: 1" ^
-H "user-agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/105.0.0.0 Safari/537.36" ^
--data-raw "csrf_token=HQaRUZf^%^2BduX2b^%^2FbEV74pvCqPAQdjE^%^2BculN27YNdOMLlL0Xz169nFWHB5DXXOIcsQEEWHUvrE3RagQ5^%^2F9RSukIA^%^3D^%^3D&traits.username=dimon&password=lolkek98&traits.name.first=dsdssd&traits.name.last=dsds&method=password" ^
--compressed ^
--insecure
request, cookies are includedlittle-pager-97837
10/05/2022, 9:23 AMlittle-pager-97837
10/05/2022, 9:27 AMsteep-lamp-91158
little-pager-97837
10/05/2022, 9:33 AMlittle-pager-97837
10/05/2022, 9:34 AMlittle-pager-97837
10/05/2022, 9:39 AMsteep-lamp-91158
Cookie
headerlittle-pager-97837
10/05/2022, 9:44 AMsteep-lamp-91158
little-pager-97837
10/05/2022, 9:44 AMlittle-pager-97837
10/05/2022, 9:44 AMsteep-lamp-91158
steep-lamp-91158
little-pager-97837
10/05/2022, 9:46 AMlittle-pager-97837
10/05/2022, 9:46 AMlittle-pager-97837
10/05/2022, 9:47 AMlittle-pager-97837
10/05/2022, 9:47 AMlittle-pager-97837
10/05/2022, 10:00 AMsteep-lamp-91158
steep-lamp-91158
steep-lamp-91158