<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://community.appian.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/"><channel><title>KB-1588 "There is no valid CSRF token in this request" error thrown when navigating through Appian with Apache</title><link>https://community.appian.com/support/w/kb/977/kb-1588-there-is-no-valid-csrf-token-in-this-request-error-thrown-when-navigating-through-appian-with-apache</link><description /><dc:language>en-US</dc:language><generator>Telligent Community 12</generator><item><title>KB-1588 "There is no valid CSRF token in this request" error thrown when navigating through Appian with Apache</title><link>https://community.appian.com/support/w/kb/977/kb-1588-there-is-no-valid-csrf-token-in-this-request-error-thrown-when-navigating-through-appian-with-apache</link><pubDate>Wed, 26 Jan 2022 23:54:48 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:f638937c-fd87-4479-b798-152271590677</guid><dc:creator>Elly Meng</dc:creator><comments>https://community.appian.com/support/w/kb/977/kb-1588-there-is-no-valid-csrf-token-in-this-request-error-thrown-when-navigating-through-appian-with-apache#comments</comments><description>Current Revision posted to Appian Knowledge Base by Elly Meng on 1/26/2022 11:54:48 PM&lt;br /&gt;
&lt;h2&gt;Symptoms&lt;/h2&gt;
&lt;p&gt;When navigating throughout an Appian environment using Apache as a web server, users may see the following error in the application server log:&lt;/p&gt;
&lt;pre&gt;WARN com.appiancorp.security.csrf.CsrfTokenManager - There is no valid CSRF token in this request [URI=/suite/framework/backgroundAction.none]&lt;/pre&gt;
&lt;h2&gt;Cause&lt;/h2&gt;
&lt;p&gt;Appian uses CSRF cookies that need to be accessible via JavaScript. Users may see the error if their Apache web server has been configured to set cookies to HttpOnly due to security policies of their organization. If so, the CSRF cookies don&amp;#39;t work.&lt;/p&gt;
&lt;h2&gt;Action&lt;/h2&gt;
&lt;p&gt;By default, the Apache Web Server should not be setting cookies to HttpOnly.&amp;nbsp;Please consult your web server admins to see if this setting is in place in the&amp;nbsp;&lt;b&gt;httpd.conf&lt;/b&gt;&amp;nbsp;file and request a change back to the default settings as laid out in the Appian documentation:&amp;nbsp;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a class="external-link" href="https://docs.appian.com/suite/help/latest/Configuring_Apache_Web_Server_with_Appian.html" rel="nofollow"&gt;Configuring Apache Web Server with Appian [Appian 18.3 and Later]&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="external-link" href="https://docs.appian.com/suite/help/18.2/Configuring_Apache_Web_Server_with_JBoss.html" rel="nofollow"&gt;Configuring Apache Web Server with JBoss [Appian 18.2 and Earlier]&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Affected Versions&lt;/h2&gt;
&lt;p&gt;This article applies to all self-managed versions of Appian using&amp;nbsp;Apache as a web&amp;nbsp;server.&lt;/p&gt;
&lt;p&gt;Last Reviewed: January 2022&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;

&lt;div style="font-size: 90%;"&gt;Tags: apache, web server, infrastructure, cookies&lt;/div&gt;
</description></item><item><title>KB-1588 "There is no valid CSRF token in this request" error thrown when navigating through Appian with Apache</title><link>https://community.appian.com/support/w/kb/977/kb-1588-there-is-no-valid-csrf-token-in-this-request-error-thrown-when-navigating-through-appian-with-apache/revision/10</link><pubDate>Wed, 10 Feb 2021 04:01:19 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:f638937c-fd87-4479-b798-152271590677</guid><dc:creator>Parmida Borhani</dc:creator><comments>https://community.appian.com/support/w/kb/977/kb-1588-there-is-no-valid-csrf-token-in-this-request-error-thrown-when-navigating-through-appian-with-apache#comments</comments><description>Revision 10 posted to Appian Knowledge Base by Parmida Borhani on 2/10/2021 4:01:19 AM&lt;br /&gt;
&lt;h2&gt;Symptoms&lt;/h2&gt;
&lt;p&gt;When navigating throughout an Appian environment using Apache as a web server, users may see the following error in the application server log:&lt;/p&gt;
&lt;pre&gt;WARN com.appiancorp.security.csrf.CsrfTokenManager - There is no valid CSRF token in this request [URI=/suite/framework/backgroundAction.none]&lt;/pre&gt;
&lt;h2&gt;Cause&lt;/h2&gt;
&lt;p&gt;Appian uses CSRF cookies that need to be accessible via JavaScript. Users may see the error if their Apache web server has been configured to set cookies to HttpOnly due to security policies of their organization. If so, the CSRF cookies don&amp;#39;t work.&lt;/p&gt;
&lt;h2&gt;Action&lt;/h2&gt;
&lt;p&gt;By default, the Apache Web Server should not be setting cookies to HttpOnly.&amp;nbsp;Please consult your web server admins to see if this setting is in place in the&amp;nbsp;&lt;b&gt;httpd.conf&lt;/b&gt;&amp;nbsp;file and request a change back to the default settings as laid out in the Appian documentation:&amp;nbsp;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a class="external-link" href="https://docs.appian.com/suite/help/latest/Configuring_Apache_Web_Server_with_Appian.html" rel="nofollow"&gt;Configuring Apache Web Server with Appian [Appian 18.3 and Later]&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="external-link" href="https://docs.appian.com/suite/help/18.2/Configuring_Apache_Web_Server_with_JBoss.html" rel="nofollow"&gt;Configuring Apache Web Server with JBoss [Appian 18.2 and Earlier]&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Affected Versions&lt;/h2&gt;
&lt;p&gt;This article applies to all versions of Appian using&amp;nbsp;Apache as a web&amp;nbsp;server.&lt;/p&gt;
&lt;p&gt;Last Reviewed: February 2021&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;

&lt;div style="font-size: 90%;"&gt;Tags: apache, web server, infrastructure, cookies&lt;/div&gt;
</description></item><item><title>KB-1588 "There is no valid CSRF token in this request" error thrown when navigating through Appian with Apache</title><link>https://community.appian.com/support/w/kb/977/kb-1588-there-is-no-valid-csrf-token-in-this-request-error-thrown-when-navigating-through-appian-with-apache/revision/9</link><pubDate>Sun, 07 Feb 2021 22:41:27 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:f638937c-fd87-4479-b798-152271590677</guid><dc:creator>Parmida Borhani</dc:creator><comments>https://community.appian.com/support/w/kb/977/kb-1588-there-is-no-valid-csrf-token-in-this-request-error-thrown-when-navigating-through-appian-with-apache#comments</comments><description>Revision 9 posted to Appian Knowledge Base by Parmida Borhani on 2/7/2021 10:41:27 PM&lt;br /&gt;
&lt;h2&gt;Symptoms&lt;/h2&gt;
&lt;p&gt;When navigating throughout an Appian environment using Apache as a web server, users may see the following error in the application server log:&lt;/p&gt;
&lt;pre&gt;WARN com.appiancorp.security.csrf.CsrfTokenManager - There is no valid CSRF token in this request [URI=/suite/framework/backgroundAction.none]&lt;/pre&gt;
&lt;h2&gt;Cause&lt;/h2&gt;
&lt;p&gt;Appian uses CSRF cookies that need to be accessible via JavaScript. Users may see the error if their Apache web server has been configured to set cookies to HttpOnly due to security policies of their organization. If so, the CSRF cookies don&amp;#39;t work.&lt;/p&gt;
&lt;h2&gt;Action&lt;/h2&gt;
&lt;p&gt;By default, the Apache Web Server should not be setting cookies to HttpOnly.&amp;nbsp;Please consult your web server admins to see if this setting is in place in the&amp;nbsp;&lt;b&gt;httpd.conf&lt;/b&gt;&amp;nbsp;file and request a change back to the default settings as laid out in the Appian documentation:&amp;nbsp;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a class="external-link" href="https://docs.appian.com/suite/help/latest/Configuring_Apache_Web_Server_with_Appian.html" rel="nofollow"&gt;Configuring Apache Web Server with Appian [Appian 18.3 and Later]&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="external-link" href="https://docs.appian.com/suite/help/18.2/Configuring_Apache_Web_Server_with_JBoss.html" rel="nofollow"&gt;Configuring Apache Web Server with JBoss [Appian 18.2 and Earlier]&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Affected Versions&lt;/h2&gt;
&lt;p&gt;This article applies to all versions of Appian using&amp;nbsp;Apache as a web&amp;nbsp;server.&lt;/p&gt;
&lt;p&gt;Last Reviewed:&amp;nbsp;August 2020&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;

&lt;div style="font-size: 90%;"&gt;Tags: apache, web server, infrastructure, cookies&lt;/div&gt;
</description></item><item><title>KB-1588 "There is no valid CSRF token in this request" error thrown when navigating through Appian with Apache</title><link>https://community.appian.com/support/w/kb/977/kb-1588-there-is-no-valid-csrf-token-in-this-request-error-thrown-when-navigating-through-appian-with-apache/revision/8</link><pubDate>Tue, 11 Aug 2020 21:14:15 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:f638937c-fd87-4479-b798-152271590677</guid><dc:creator>James Lee</dc:creator><comments>https://community.appian.com/support/w/kb/977/kb-1588-there-is-no-valid-csrf-token-in-this-request-error-thrown-when-navigating-through-appian-with-apache#comments</comments><description>Revision 8 posted to Appian Knowledge Base by James Lee on 8/11/2020 9:14:15 PM&lt;br /&gt;
&lt;h2&gt;Symptoms&lt;/h2&gt;
&lt;p&gt;When navigating throughout an Appian environment using Apache as a web server, users may see the following error in the application server log:&lt;/p&gt;
&lt;pre&gt;WARN com.appiancorp.security.csrf.CsrfTokenManager - There is no valid CSRF token in this request [URI=/suite/framework/backgroundAction.none]&lt;/pre&gt;
&lt;h2&gt;Cause&lt;/h2&gt;
&lt;p&gt;Appian uses CSRF cookies that need to be accessible via JavaScript. Users may see the error if their Apache web server has been configured to set cookies to HttpOnly due to security policies of their organization. If so, the CSRF cookies don&amp;#39;t work.&lt;/p&gt;
&lt;h2&gt;Action&lt;/h2&gt;
&lt;p&gt;By default, the Apache Web Server should not be setting cookies to HttpOnly.&amp;nbsp;Please consult your web server admins to see if this setting is in place in the&amp;nbsp;&lt;b&gt;httpd.conf&lt;/b&gt;&amp;nbsp;file and request a change back to the default settings as laid out in the Appian documentation:&amp;nbsp;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a class="external-link" href="https://docs.appian.com/suite/help/latest/Configuring_Apache_Web_Server_with_Appian.html" rel="nofollow"&gt;Configuring Apache Web Server with Appian [Appian 18.3 and Later]&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="external-link" href="https://docs.appian.com/suite/help/18.2/Configuring_Apache_Web_Server_with_JBoss.html" rel="nofollow"&gt;Configuring Apache Web Server with JBoss [Appian 18.2 and Earlier]&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Affected Versions&lt;/h2&gt;
&lt;p&gt;This article applies to all versions of Appian using&amp;nbsp;Apache as a web&amp;nbsp;server.&lt;/p&gt;
&lt;p&gt;Last Reviewed:&amp;nbsp;August 2020&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;

&lt;div style="font-size: 90%;"&gt;Tags: web server, infrastructure, cookies&lt;/div&gt;
</description></item><item><title>KB-1588 "There is no valid CSRF token in this request" error thrown when navigating through Appian with Apache</title><link>https://community.appian.com/support/w/kb/977/kb-1588-there-is-no-valid-csrf-token-in-this-request-error-thrown-when-navigating-through-appian-with-apache/revision/7</link><pubDate>Tue, 27 Nov 2018 16:55:32 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:f638937c-fd87-4479-b798-152271590677</guid><dc:creator>Parmida Borhani</dc:creator><comments>https://community.appian.com/support/w/kb/977/kb-1588-there-is-no-valid-csrf-token-in-this-request-error-thrown-when-navigating-through-appian-with-apache#comments</comments><description>Revision 7 posted to Appian Knowledge Base by Parmida Borhani on 11/27/2018 4:55:32 PM&lt;br /&gt;
&lt;h2&gt;Symptoms&lt;/h2&gt;
&lt;p&gt;When navigating throughout an Appian environment using Apache as a web server, users may see the following error in the application server log:&lt;/p&gt;
&lt;pre&gt;WARN com.appiancorp.security.csrf.CsrfTokenManager - There is no valid CSRF token in this request [URI=/suite/framework/backgroundAction.none]&lt;/pre&gt;
&lt;h2&gt;Cause&lt;/h2&gt;
&lt;p&gt;Appian uses CSRF cookies that need to be accessible via JavaScript. Users may see the error if their Apache web server has been configured to set cookies to HttpOnly due to security policies of their organization. If so, the CSRF cookies don&amp;#39;t work.&lt;/p&gt;
&lt;h2&gt;Action&lt;/h2&gt;
&lt;p&gt;By default, the Apache Web Server should not be setting cookies to HttpOnly.&amp;nbsp;Please consult your web server admins to see if this setting is in place in the&amp;nbsp;&lt;strong&gt;httpd.conf&lt;/strong&gt;&amp;nbsp;file and request a change back to the default settings as laid out in the Appian documentation here: &lt;a href="https://docs.appian.com/suite/help/latest/Configuring_Apache_Web_Server_with_JBoss.html"&gt;Configuring Apache Web Server with JBoss&lt;/a&gt;&lt;/p&gt;
&lt;h2&gt;Affected Versions&lt;/h2&gt;
&lt;p&gt;This article applies to all versions of Appian using&amp;nbsp;Apache as a web&amp;nbsp;server.&lt;/p&gt;
&lt;p&gt;Last Reviewed: May 2018&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;

&lt;div style="font-size: 90%;"&gt;Tags: web server, infrastructure, cookies&lt;/div&gt;
</description></item><item><title>KB-1588 "There is no valid CSRF token in this request" error thrown when navigating through Appian with Apache</title><link>https://community.appian.com/support/w/kb/977/kb-1588-there-is-no-valid-csrf-token-in-this-request-error-thrown-when-navigating-through-appian-with-apache/revision/6</link><pubDate>Mon, 23 Jul 2018 10:22:39 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:f638937c-fd87-4479-b798-152271590677</guid><dc:creator>Jordan Horwat</dc:creator><comments>https://community.appian.com/support/w/kb/977/kb-1588-there-is-no-valid-csrf-token-in-this-request-error-thrown-when-navigating-through-appian-with-apache#comments</comments><description>Revision 6 posted to Appian Knowledge Base by Jordan Horwat on 7/23/2018 10:22:39 AM&lt;br /&gt;
&lt;h2&gt;Symptoms&lt;/h2&gt;
&lt;p&gt;When navigating throughout an Appian environment using Apache as a web server, users may see the following error in the application server log:&lt;/p&gt;
&lt;pre&gt;WARN com.appiancorp.security.csrf.CsrfTokenManager - There is no valid CSRF token in this request [URI=/suite/framework/backgroundAction.none]&lt;/pre&gt;
&lt;h2&gt;Cause&lt;/h2&gt;
&lt;p&gt;Appan uses CSRF cookies that need to be accessible via JavaScript. Users may see the error if their Apache web server has been configured to set cookies to HttpOnly due to security policies of their organization. If so, the CSRF cookies don&amp;#39;t work.&lt;/p&gt;
&lt;h2&gt;Action&lt;/h2&gt;
&lt;p&gt;By default, the Apache Web Server should not be setting cookies to HttpOnly.&amp;nbsp;Please consult your web server admins to see if this setting is in place in the&amp;nbsp;&lt;strong&gt;httpd.conf&lt;/strong&gt;&amp;nbsp;file and request a change back to the default settings as laid out in the Appian documentation here: &lt;a href="https://docs.appian.com/suite/help/latest/Configuring_Apache_Web_Server_with_JBoss.html"&gt;Configuring Apache Web Server with JBoss&lt;/a&gt;&lt;/p&gt;
&lt;h2&gt;Affected Versions&lt;/h2&gt;
&lt;p&gt;This article applies to all versions of Appian using&amp;nbsp;Apache as a web&amp;nbsp;server.&lt;/p&gt;
&lt;p&gt;Last Reviewed: May 2018&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;

&lt;div style="font-size: 90%;"&gt;Tags: web server, infrastructure, cookies&lt;/div&gt;
</description></item><item><title>KB-1588 "There is no valid CSRF token in this request" error thrown when navigating through Appian with Apache</title><link>https://community.appian.com/support/w/kb/977/kb-1588-there-is-no-valid-csrf-token-in-this-request-error-thrown-when-navigating-through-appian-with-apache/revision/5</link><pubDate>Tue, 29 May 2018 14:17:37 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:f638937c-fd87-4479-b798-152271590677</guid><dc:creator>Nick Vigilante</dc:creator><comments>https://community.appian.com/support/w/kb/977/kb-1588-there-is-no-valid-csrf-token-in-this-request-error-thrown-when-navigating-through-appian-with-apache#comments</comments><description>Revision 5 posted to Appian Knowledge Base by Nick Vigilante on 5/29/2018 2:17:37 PM&lt;br /&gt;
&lt;h2&gt;Symptoms&lt;/h2&gt;
&lt;p&gt;When navigating throughout an Appian environment using Apache as a web server, users may see the following error in the application server log:&lt;/p&gt;
&lt;pre&gt;WARN com.appiancorp.security.csrf.CsrfTokenManager - There is no valid CSRF token in this request [URI=/suite/framework/backgroundAction.none]&lt;/pre&gt;
&lt;h2&gt;Cause&lt;/h2&gt;
&lt;p&gt;Appan uses CSRF cookies that need to be accessible via JavaScript. Users may see the error if their Apache web server has been configured to set cookies to HttpOnly due to security policies of their organization. If so, the CSRF cookies don&amp;#39;t work.&lt;/p&gt;
&lt;h2&gt;Action&lt;/h2&gt;
&lt;p&gt;By default, the Apache Web Server should not be setting cookies to HttpOnly.&amp;nbsp;Please consult your web server admins to see if this setting is in place in the&amp;nbsp;&lt;strong&gt;httpd.conf&lt;/strong&gt;&amp;nbsp;file and request a change back to the default settings as laid out in the Appian documentation here: &lt;a href="https://docs.appian.com/suite/help/latest/Configuring_Apache_Web_Server_with_JBoss.html"&gt;Configuring Apache Web Server with JBoss&lt;/a&gt;&lt;/p&gt;
&lt;h2&gt;Affected Versions&lt;/h2&gt;
&lt;p&gt;This article applies to all versions of Appian using&amp;nbsp;Apache as a web&amp;nbsp;server.&lt;/p&gt;
&lt;p&gt;Last Reviewed: May 2018&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;

&lt;div style="font-size: 90%;"&gt;Tags: web server, cookies&lt;/div&gt;
</description></item><item><title>There is no valid CSRF token in this request</title><link>https://community.appian.com/support/w/kb/977/kb-1588-there-is-no-valid-csrf-token-in-this-request-error-thrown-when-navigating-through-appian-with-apache/revision/4</link><pubDate>Tue, 29 May 2018 10:15:04 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:f638937c-fd87-4479-b798-152271590677</guid><dc:creator>Sean Kim</dc:creator><comments>https://community.appian.com/support/w/kb/977/kb-1588-there-is-no-valid-csrf-token-in-this-request-error-thrown-when-navigating-through-appian-with-apache#comments</comments><description>Revision 4 posted to Appian Knowledge Base by Sean Kim on 5/29/2018 10:15:04 AM&lt;br /&gt;
&lt;h2&gt;Symptoms&lt;/h2&gt;
&lt;p&gt;When navigating throughout an Appian environment using Apache as a web server, users may see the following error in the application server log:&lt;/p&gt;
&lt;pre&gt;WARN com.appiancorp.security.csrf.CsrfTokenManager - There is no valid CSRF token in this request [URI=/suite/framework/backgroundAction.none]&lt;/pre&gt;
&lt;h2&gt;Cause&lt;/h2&gt;
&lt;p&gt;Appan uses CSRF cookies that need to be accessible via JavaScript. Users may see the error if their Apache web server has been configured to set cookies to HttpOnly due to security policies of their organization. If so, the CSRF cookies don&amp;#39;t work.&lt;/p&gt;
&lt;h2&gt;Action&lt;/h2&gt;
&lt;p&gt;By default, the Apache Web Server should not be setting cookies to HttpOnly.&amp;nbsp;Please consult your web server admins to see if this setting is in place in the&amp;nbsp;&lt;strong&gt;httpd.conf&lt;/strong&gt;&amp;nbsp;file and request a change back to the default settings as laid out in the Appian documentation here: &lt;a href="https://docs.appian.com/suite/help/latest/Configuring_Apache_Web_Server_with_JBoss.html"&gt;Configuring Apache Web Server with JBoss&lt;/a&gt;&lt;/p&gt;
&lt;h2&gt;Affected Versions&lt;/h2&gt;
&lt;p&gt;This article applies to all versions of Appian using&amp;nbsp;Apache as a web&amp;nbsp;server.&lt;/p&gt;
&lt;p&gt;Last Reviewed: May 2018&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;

&lt;div style="font-size: 90%;"&gt;Tags: web server, cookies&lt;/div&gt;
</description></item><item><title>There is no valid CSRF token in this request</title><link>https://community.appian.com/support/w/kb/977/kb-1588-there-is-no-valid-csrf-token-in-this-request-error-thrown-when-navigating-through-appian-with-apache/revision/3</link><pubDate>Wed, 23 May 2018 08:03:18 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:f638937c-fd87-4479-b798-152271590677</guid><dc:creator>Sean Kim</dc:creator><comments>https://community.appian.com/support/w/kb/977/kb-1588-there-is-no-valid-csrf-token-in-this-request-error-thrown-when-navigating-through-appian-with-apache#comments</comments><description>Revision 3 posted to Appian Knowledge Base by Sean Kim on 5/23/2018 8:03:18 AM&lt;br /&gt;
&lt;h2&gt;Symptoms&lt;/h2&gt;
&lt;p&gt;When navigating throughout an Appian environment using Apache as a web server, users may see the following error in the application server log:&lt;/p&gt;
&lt;pre&gt;WARN com.appiancorp.security.csrf.CsrfTokenManager - There is no valid CSRF token in this request [URI=/suite/framework/backgroundAction.none]&lt;/pre&gt;
&lt;h2&gt;Cause&lt;/h2&gt;
&lt;p&gt;Appan uses CSRF cookies that need to be accessible via JavaScript. Users may see the error if their Apache web server has been configured to set cookies to HttpOnly due to security policies of their organization. If so, the CSRF cookies don&amp;#39;t work.&lt;/p&gt;
&lt;h2&gt;Action&lt;/h2&gt;
&lt;p&gt;By default, the Apache Web Server should not be setting cookies to HttpOnly.&amp;nbsp;Please consult your web server admins to see if this setting is in place in the&amp;nbsp;&lt;strong&gt;httpd.conf&lt;/strong&gt;&amp;nbsp;file and request a change back to the default settings as laid out in the Appian documentation here: &lt;a href="https://docs.appian.com/suite/help/18.1/Configuring_Apache_Web_Server_with_JBoss.html"&gt;https://docs.appian.com/suite/help/18.1/Configuring_Apache_Web_Server_with_JBoss.html&lt;/a&gt;&lt;/p&gt;
&lt;h2&gt;Affected Versions&lt;/h2&gt;
&lt;p&gt;This article applies to all versions of Appian using&amp;nbsp;Apache as a web&amp;nbsp;server.&lt;/p&gt;
&lt;p&gt;Last Reviewed: May 2018&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;

&lt;div style="font-size: 90%;"&gt;Tags: web server, cookies&lt;/div&gt;
</description></item><item><title>There is no valid CSRF token in this request</title><link>https://community.appian.com/support/w/kb/977/kb-1588-there-is-no-valid-csrf-token-in-this-request-error-thrown-when-navigating-through-appian-with-apache/revision/2</link><pubDate>Tue, 22 May 2018 12:56:50 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:f638937c-fd87-4479-b798-152271590677</guid><dc:creator>Sean Kim</dc:creator><comments>https://community.appian.com/support/w/kb/977/kb-1588-there-is-no-valid-csrf-token-in-this-request-error-thrown-when-navigating-through-appian-with-apache#comments</comments><description>Revision 2 posted to Appian Knowledge Base by Sean Kim on 5/22/2018 12:56:50 PM&lt;br /&gt;
&lt;h2&gt;Symptoms&lt;/h2&gt;
&lt;p&gt;When navigating throughout an Appian environment using Apache as a web server, users may see the following error in the application server log:&lt;/p&gt;
&lt;pre&gt;WARN com.appiancorp.security.csrf.CsrfTokenManager - There is no valid CSRF token in this request [URI=/suite/framework/backgroundAction.none]&lt;/pre&gt;
&lt;h2&gt;Cause&lt;/h2&gt;
&lt;p&gt;Appan uses CSRF cookies that need to be accessible via JavaScript. Users may see the error if their Apache web server has been configured to set all cookies to HttpOnly due to security policies of their organization. If so, the CSRF cookies don&amp;#39;t work.&lt;/p&gt;
&lt;h2&gt;Action&lt;/h2&gt;
&lt;p&gt;In the&amp;nbsp;&lt;strong&gt;httpd.conf&lt;/strong&gt;&amp;nbsp;file, change the Set-Cookie configuration to allow for a RegEx that excludes the CSRF tokens. The names of the CSRF tokens are&amp;nbsp;&lt;code&gt;_appianCsrfToken&lt;/code&gt;&lt;strong&gt;&amp;nbsp;&lt;/strong&gt;and&amp;nbsp;&lt;code&gt;_appianMultipartCsrfToken.&amp;nbsp;&lt;/code&gt;Please consult your web server admins for additional information.&lt;/p&gt;
&lt;h2&gt;Affected Versions&lt;/h2&gt;
&lt;p&gt;This article applies to all versions of Appian using&amp;nbsp;Apache as a web&amp;nbsp;server.&lt;/p&gt;
&lt;p&gt;Last Reviewed: May 2018&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;

&lt;div style="font-size: 90%;"&gt;Tags: web server, cookies&lt;/div&gt;
</description></item><item><title>There is no valid CSRF token in this request</title><link>https://community.appian.com/support/w/kb/977/kb-1588-there-is-no-valid-csrf-token-in-this-request-error-thrown-when-navigating-through-appian-with-apache/revision/1</link><pubDate>Mon, 21 May 2018 16:00:41 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:f638937c-fd87-4479-b798-152271590677</guid><dc:creator>Sean Kim</dc:creator><comments>https://community.appian.com/support/w/kb/977/kb-1588-there-is-no-valid-csrf-token-in-this-request-error-thrown-when-navigating-through-appian-with-apache#comments</comments><description>Revision 1 posted to Appian Knowledge Base by Sean Kim on 5/21/2018 4:00:41 PM&lt;br /&gt;
&lt;h2&gt;Symptoms&lt;/h2&gt;
&lt;p&gt;When navigating throughout an Appian environment, users may see the following error in the server log:&lt;/p&gt;
&lt;pre&gt;WARN com.appiancorp.security.csrf.CsrfTokenManager - There is no valid CSRF token in this request [URI=/suite/framework/backgroundAction.none]&lt;/pre&gt;
&lt;h2&gt;Cause&lt;/h2&gt;
&lt;p&gt;Appan uses CSRF cookies that need to be accessible via JavaScript. Users may see the above error if all cookies in the Apache web server have been set to HTTPOnly.&amp;nbsp; If so, the CSRF cookies don&amp;#39;t work.&lt;/p&gt;
&lt;h2&gt;Action&lt;/h2&gt;
&lt;p&gt;In the httpd.conf file, change the Set-Cookie configuration to allow for a regex that excludes the CSRF tokens. The names of the CSRF tokens are&amp;nbsp;&lt;strong&gt;_appianCsrfToken&amp;nbsp;&lt;/strong&gt;and&amp;nbsp;&lt;strong&gt;_appianMultipartCsrfToken.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;More information on how to exclude cookies from the HttpOnly setting can be found here:&amp;nbsp;https://www.tunetheweb.com/security/http-security-headers/secure-cookies/&lt;/p&gt;
&lt;h2&gt;&amp;nbsp;&lt;/h2&gt;
&lt;h2&gt;Affected Versions&lt;/h2&gt;
&lt;p&gt;This article applies to all versions of Appian using&amp;nbsp;Apache as a web&amp;nbsp;server.&lt;/p&gt;
&lt;p&gt;Last Reviewed: May 2018&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;

&lt;div style="font-size: 90%;"&gt;Tags: web server, cookies&lt;/div&gt;
</description></item></channel></rss>