Skip to content

GitLab

  • Menu
Projects Groups Snippets
  • Help
    • Help
    • Support
    • Community forum
    • Submit feedback
    • Contribute to GitLab
  • Sign in
  • software.hifis.net software.hifis.net
  • Project information
    • Project information
    • Activity
    • Labels
    • Members
  • Repository
    • Repository
    • Files
    • Commits
    • Branches
    • Tags
    • Contributors
    • Graph
    • Compare
  • Issues 31
    • Issues 31
    • List
    • Boards
    • Service Desk
    • Milestones
  • Merge requests 14
    • Merge requests 14
  • CI/CD
    • CI/CD
    • Pipelines
    • Jobs
    • Schedules
  • Deployments
    • Deployments
    • Environments
    • Releases
  • Monitor
    • Monitor
    • Incidents
  • Analytics
    • Analytics
    • Value stream
    • CI/CD
    • Repository
  • Wiki
    • Wiki
  • Snippets
    • Snippets
  • Activity
  • Graph
  • Create a new issue
  • Jobs
  • Commits
  • Issue Boards
Collapse sidebar
  • HIFIS
  • software.hifis.netsoftware.hifis.net
  • Issues
  • #198
Closed
Open
Created Nov 27, 2020 by Huste, Tobias (FWCC) - 111645@frust45Owner

Consulting form not working on Chromium/Chrome

On Chromium and Chrome the embedded consulting iframe is not working. When having filled out the first page and navigating to page 2 a CSRF error appears.

csrf

On Firefox the issue is currently not reproducible.

It seems to be related to the SameSite-Cookie enforcement in Chromium/Chrome. For testing I disabled this feature via chrome://flags/#same-site-by-default-cookies. With this setting disabled, the error disappears.

This is an overview site about the SameSite changes: (https://www.chromium.org/updates/same-site). As far as I remember, Firefox is also planning to introduce a similar behavior.

Immediate solution

As an immediate solution we might want to make the direct link more prominent.

Options for a long-term solution

  • Create a custom form implementation like Helmholtz AI
  • Do not embed the form as an iframe
  • More ideas?

\cc @frere76 @Drake81 @ashis.ravindran

Assignee
Assign to
Time tracking

Privacy | Imprint | Support | Status | Documentation | Changelog