Welcome to the LimeSurvey Community Forum

Ask the community, share ideas, and connect with other LimeSurvey users!

Error: CSRF token could not be verified

  • GaleriaReisen
  • GaleriaReisen's Avatar Topic Author
  • Offline
  • New Member
  • New Member
More
2 months 3 weeks ago #255395 by GaleriaReisen
Error: CSRF token could not be verified was created by GaleriaReisen
Please help us help you and fill where relevant:
Your LimeSurvey version: Version 5.6.53
==================

Hi everyone,
we have embedded two surveys via iFrame on two websites. We are only using LimeSurvey Cloud and don't use an API. 

The first one works great but the second is showing the "CSRF token could not be verified" error to some users when they try to submit the survey. 

We don't know how this problem occurs since both surveys are implemented in the same manner. The only difference is that the second survey has the same ID for both domains since it makes it easier to evaluate. 
We use alias domains and the iFrame embedding is enabled. 

Does somebody have any idea how to solve this? 
 

Please Log in to join the conversation.

  • DenisChenu
  • DenisChenu's Avatar
  • Offline
  • LimeSurvey Community Team
  • LimeSurvey Community Team
More
2 months 3 weeks ago #255397 by DenisChenu
Replied by DenisChenu on topic Error: CSRF token could not be verified
The system need server update about session samesite (at minima)

manual.limesurvey.org/index.php?title=Op....28New_in_3.24.3_.29

You need to contact LimeSurvey GMBH

Even with this settings : the original server can disallow any external iframe !

See : developer.mozilla.org/en-US/docs/Web/HTTP/CSP

Assistance on LimeSurvey forum and LimeSurvey core development are on my free time.
I'm not a LimeSurvey GmbH member, professional service on demand , plugin development .
I don't answer to private message.

Please Log in to join the conversation.

Lime-years ahead

Online-surveys for every purse and purpose