This project is archived and is in readonly mode.
Rails 2.3.2 sessions problem - active record
-
Richard Delph
Just wondering if anyone has encountered the same error as described above when using the active record session store?
-
Richard Delph
With the help of someone else who has encountered this error it seems I just needed to comment out the line
protect_from_forgery
in the application controller and this seemed to have sorted it. though the error still stands with new sessions being created when inserting the line
config.action_controller.allow_forgery_protection = false
in the dev environment file...
Rich
-
ronin-52463 (at lighthouseapp)
I've had the same problem and didn't find any solution.
I think that disabling protections will go around the problem and not solve it.
-
Tony Pitale
+1 using anything other than cookie sessions
-
philip (at packetnode)
+1 here. Went back to 2.1.1 and it went away.
-
John Smilanick
I have similar session issues under slightly different circumstances. I overloaded render_optional_error_file (called from rescue_action_in_public) and read some data from the session to display custom 500 and 404 layouts based on the session data. No matter what happens after the session is loaded the session gets reset and the user gets logged out (might be caused by a new session_id). Since these are both related to error handling I thought this might be relevant.
-
Robin Wunderlin
Same problem here.
Looks like the authenticity_token of the form is not saved correctly by the session.
So after submitting the form the comparison of the param value and the session value doesn't work correctly.(Removing "protect_from_forgery" is not a solution) -> I changed to cookies. (Till the problem is solved)
-
Robin Wunderlin
- Title changed from Rails 2.3.2 sessions problem to Rails 2.3.2 sessions problem - active record
-
windix
I had exactly the same problem here yesterday.
(My environment: ROR 2.3.2, MySQL 5.1.35 on Mac OS X 10.5.7)
I logged authenticity_token and found it changed for each request but the params value submitted by the form still used the old value which caused the problem.
It's the same as Robin Wunderlin mentioned above.
But curiously, I restarted my Mac this morning and it seems works fine now.
-
Mauricio Gomes
I've had the same problem with ActiveRecord sessions and I was skeptical about windix's solution. I rebooted my mac though and my AuthenticityToken problems seemed to have gone away. It doesn't really make sense...
-
Sebastian Nanek
Perhaps trying to use edge rails may help with your problem.
-
Robin Wunderlin
Works well with 2.3.3
-
Geoff
I appear to be having the same issue in 2.3.4.
App was working fine with cookie store but client requested we switch to active record store and i keep getting ActionController::InvalidAuthenticityToken errors on all form submissions. The authenticity_token is getting sent in the request but apparently is not valid.
I'm seeing sessions get created in the sessions table as well. Very strange.
-
realbite
Had the same problem... new sessions table entry for every request and getting ActionController::InvalidAuthenticityToken. Solved it by just clearing the cookie cache in the Browser.
-
kristian.hellquist (at gmail)
"I'm seeing sessions get created in the sessions table as well. Very strange."
I hade similar problem. When I specified:
ActionController::Base.session_options[:expire_after]=2.years
New sessions weren't created every request.
This might not have anything to do with ActionController::InvalidAuthenticityToken, but maybe helps someone