<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
</head>
<body text="#000000" bgcolor="#FFFFFF">
<p>Hi Maher,</p>
<p>This depends if you have just created a new repository/archive or if you have upgraded to 3.4.1 for an existing archive.&nbsp; For the latter you will need to manually copy EPRINTS_PATH/lib/defaultcfg_zero/cfg.d/csrf_protection.pl to you archive (i.e.&nbsp; EPRINTS_PATH/archives/ARCHIVE_NAME/cfg.d/csrf_protection.pl).&nbsp;
 Otherwise csrf_protection.pl should have automatically added to you archive on creation.&nbsp; Either way it is best you change the csrf_token_salt config variable to something else.&nbsp; Generating a suitable token salt can be done using OpenSSL:</p>
<p>openssl rand -base64 8</p>
<p>8 characters should be more than sufficient, as the current time is also used in generating each token.&nbsp; Using the default token salt gives you improved security but is not ideal as a determined hacker could work out valid tokens they could use.<br>
</p>
<p>Regards</p>
<p>David Newman<br>
</p>
<div class="moz-cite-prefix">On 07/11/2019 11:54, Maher Abdellatif Ahmad Qahwash via Eprints-tech wrote:<br>
</div>
<blockquote type="cite" cite="mid:EMEW3|bf11d3b032b497f1741148e520f759d0vA6ByN14eprints-tech-bounces|ecs.soton.ac.uk|iusqyv-1cdqpr-vplyzfaoa4g8-tq4mvbirqwgvipmefslddipf-m1eg6h15p4ea-euqbc4-9z0a53-cmaxwo75gs1neqs6lf91355hyi0zil-mji7dm-7j80rn-kndinb-yhlz8lhuiq3c-6sl9rh-on1t2m.1573127510576@email.android.com">
<div dir="auto">Hi
<div><br>
</div>
<div>We are running eprints 3.4.1 and would like know if CSRF is enabled by default or we need to enable it in the configuration?</div>
<div><br>
</div>
<div>Thanks</div>
<div>Maher</div>
</div>
<br>
<fieldset class="mimeAttachmentHeader"></fieldset>
<pre class="moz-quote-pre" wrap="">*** Options: <a class="moz-txt-link-freetext" href="http://mailman.ecs.soton.ac.uk/mailman/listinfo/eprints-tech">http://mailman.ecs.soton.ac.uk/mailman/listinfo/eprints-tech</a>
*** Archive: <a class="moz-txt-link-freetext" href="https://eur03.safelinks.protection.outlook.com/?url=http%3A%2F%2Fwww.eprints.org%2Ftech.php%2F&amp;data=01%7C01%7C%7C03f14f56d07e4336d14408d7637bdd29%7C4a5378f929f44d3ebe89669d03ada9d8%7C0&amp;sdata=5AuNy97xqjXuXsHIoYB%2BmmkuAOTkWOo3ZEjUCyJcCoA%3D&amp;reserved=0" originalsrc="http://www.eprints.org/tech.php/" shash="W9kGfdtICwM8xm2ncClHCjnQ/CPyYCfWlNnzfvfFDsf22fPPTn0lMVWAk37r5gVnI0FfyKqtc7hAmgS9Ksuq/FRV3LNlN16OrDi2tzNVWdl8e&#43;Gx68Dw&#43;ApF5/xeWkeEmEINGqZQkDoc&#43;UiOzy9nCQ0459WBEO4rq8Prn&#43;qA/xA=">http://www.eprints.org/tech.php/</a>
*** EPrints community wiki: <a class="moz-txt-link-freetext" href="https://eur03.safelinks.protection.outlook.com/?url=http%3A%2F%2Fwiki.eprints.org%2F&amp;data=01%7C01%7C%7C03f14f56d07e4336d14408d7637bdd29%7C4a5378f929f44d3ebe89669d03ada9d8%7C0&amp;sdata=TWio0NYpBJrdy6NTvRifpqYF1xEgfSeBTVA1b8Km0vI%3D&amp;reserved=0" originalsrc="http://wiki.eprints.org/" shash="d7WB7VkUu0klizM&#43;hl2wUA&#43;6NQlXj98d2piC8iPbVDHCJy56fAEyfNKlEUTfezX&#43;OYJHplXTJejXd&#43;m8cauj2IcxkCKBY8jyrkxFjbJ4MZZSDveY7ToL0q459IqKyzdVmIIsftgnydLAL5eXpYNkDp5O9xP/i7LUFhKV3FG&#43;99w=">http://wiki.eprints.org/</a>
*** EPrints developers Forum: <a class="moz-txt-link-freetext" href="https://eur03.safelinks.protection.outlook.com/?url=http%3A%2F%2Fforum.eprints.org%2F&amp;data=01%7C01%7C%7C03f14f56d07e4336d14408d7637bdd29%7C4a5378f929f44d3ebe89669d03ada9d8%7C0&amp;sdata=V32vlLOkMDQypjBwkRazWdbMfv96o1ANpWeSdKq7MEs%3D&amp;reserved=0" originalsrc="http://forum.eprints.org/" shash="KLrq&#43;vFR13312NbLfGn3rEqU1xvysywXUAgcFrDTx9eTBxvJSoz7BrW4xhQ9STTRUfpb0lh0CViY4pu3c7nJEF2SxaUm&#43;QcnEOJXwOiMwtPRHg5YvznmIhbcrPQV&#43;PMA5&#43;BtIgG3E34nhIz6sMaWntDTpt9rHs/CFjx4XK9SaHo=">http://forum.eprints.org/</a>
</pre>
</blockquote>
</body>
</html>