[TYPO3-core] RFC: #17289: Form protection tokens get lost because of a race condition when persisting tokens

Xavier Perseguers typo3 at perseguers.ch
Tue Jan 25 12:21:34 CET 2011


Hi,

>> Problem:
>> If two (or more) scripts are executed (almost) at the same time, both
>> scripts retrieve the same token array from the session. Both scripts
>> will create new tokens independently. The script that is executed last
>> will then overwrite the tokens generated by the first script.
>
> It seems like this is a show stopper!
>
> After some reports on twitter, I tried it myself: I can't log into the
> backend anymore, as the page doesn't load. I suppose there's some
> deadlock or infinite waiting to get a lock.
>
> My settings for lock are all the default ones.
>
> I hope this can be fixed ASAP and trigger release of RC3.

Exactly, I had to revert changesets 10295 and 10297 to see the page again.

Xavier


More information about the TYPO3-team-core mailing list