Uploaded image for project: 'Jenkins'
  1. Jenkins
  2. JENKINS-32346

Invalid crumb running behind proxy

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Cannot Reproduce
    • Icon: Minor Minor
    • html5-notifier-plugin
    • Jenkins 1.625.3
      Red Hat Enterprise Linux Server 6.4
      Apache HTTP Server 2.2.15

      The Jenkins log is filled with these entries every several seconds (each unique crumb repeats every 30 seconds) with the HTML5 Notifier Plugin enabled, running Jenkins behind a proxy:

      Jan 07, 2016 11:18:00 AM hudson.security.csrf.CrumbFilter doFilter
      WARNING: Found invalid crumb <crumb>. Will check remaining parameters for a valid one...
      Jan 07, 2016 11:18:00 AM hudson.security.csrf.CrumbFilter doFilter
      WARNING: No valid crumb was included in request for /jenkins/html5-notifier-plugin/list. Returning 403.

      It doesn't appear any specific action is required for this to occur, other than an open session.

      My Jenkins instance is configured to run behind an Apache proxy, with "Prevent Cross Site Request Forgery exploits" and "Enable proxy compatibility" enabled under global security.

      A similar issue was recently resolved for the GitHub plugin: https://issues.jenkins-ci.org/browse/JENKINS-10263

            halkeye Gavin Mogan
            dpaulat Dan Paulat
            Votes:
            3 Vote for this issue
            Watchers:
            5 Start watching this issue

              Created:
              Updated:
              Resolved: