Can't verify CSRF token authenticity ... while trying to get AD users to authenticate via SAML
Background:
I have this issue on 10.6.0. We have new certificate from ADFS, after change it and upgrade gitlab to 10.6.0 I have this lines in logs:
Processing by Gitlab::RequestForgeryProtection::Controller#index as HTML
Parameters: {"authenticity_token"=>"[FILTERED]"}
Completed 200 OK in 0ms (ActiveRecord: 0.0ms)
Started POST "/users/auth/saml/callback" for 10.151.64.32 at 2018-04-02 17:23:00 +0300
Processing by OmniauthCallbacksController#failure as HTML
Parameters: {"SAMLResponse"=>"<samlp:Response ID="_33170a00-11cc-40a1-8ded-45e3c872effb" Version="2.0" IssueInstant="2018-04-02T14:22:59.978Z" Destination="https://gitlab.rnd.wargaming.net/users/auth/saml/callback" Consent="urn:oasis:names:tc:SAML:2.0:consent:unspecified" InResponseTo="_9b309f1e-e3f1-47ae-bd43-289430f73810" xmlns:samlp="urn:oasis:names:tc:SAML:2.0:protocol"><Issuer xmlns="urn:oasis:names:tc:SAML:2.0:assertion">http://sso.wargaming.net/adfs/services/trust</Issuer><samlp:Status><samlp:StatusCode Value="urn:oasis:names:tc:SAML:2.0:status:Success" /></samlp:Status><Assertion ID="_9881fb5f-0cff-4e3d-8e87-075b1bf5aff6" IssueInstant="2018-04-02T14:22:59.978Z" Version="2.0" xmlns="urn:oasis:names:tc:SAML:2.0:assertion"><Issuer>http://sso.wargaming.net/adfs/services/trust</Issuer><ds:Signature xmlns:ds="http://www.w3.org/2000/09/xmldsig#"><ds:SignedInfo><ds:CanonicalizationMethod Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#" /><ds:SignatureMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha256" /><ds:Reference URI="#_9881fb5f-0cff-4e3d-8e87-075b1bf5aff6"><ds:Transforms><ds:Transform Algorithm="http://www.w3.org/2000/09/xmldsig#enveloped-signature" /><ds:Transform Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#" /></ds:Transforms><ds:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha256" /><ds:DigestValue>C6h5H+TVo4Vq3LWglo0H9Lwpyl1szLLxQb6mRmauSyg=</ds:DigestValue></ds:Reference></ds:SignedInfo><ds:SignatureValue>MPjNNx3C7Rq7LW4e1m35+seZvZ7JK215ZQFh9720172c+pklb2Cm6xGjT1xlY/ji3l3oWP+UQm56N7HMeOTtENAQGQ8IcI9rPF7QigZIixSRuUL7t7RmZs7JcQGsv8BnNJ/gAYJV3oEKHwPjwHNSkhec3T+PQ19PpdhGSyuS7qIkhR0XxDrYBHkK/nOeoNVDQs98+7guHZ/WggrAdz9fewU8CwcP7eJu/K9gFSpdZCkMTltqSndbdlMpIvXiN23XlVPzRnYif6Q4r8JxcSVbRWXzfABlbM3P6FfanW9tQgE0Ny/UHAxdrsj1QjicWp6bkM/5gbolsWqD/cx01njMEQ==</ds:SignatureValue><KeyInfo xmlns="http://www.w3.org/2000/09/xmldsig#"><ds:X509Data><ds:X509Certificate>MIIC3jCCAcagAwIBAgIQH1swlkrXv5xD4v9l6YpEyDANBgkqhkiG9w0BAQsFADArMSkwJwYDVQQDEyBBREZTIFNpZ25pbmcgLSBzc28ud2FyZ2FtaW5nLm5ldDAeFw0xODAyMjQxMDU4MjBaFw0yMzAyMjMxMDU4MjBaMCsxKTAnBgNVBAMTIEFERlMgU2lnbmluZyAtIHNzby53YXJnYW1pbmcubmV0MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAk0fslpZUGNHalU2JK32TbdHKjlg0Vg6wq7ikWLXrPE6BaqcYO4697QPc4UKT5z82ZgbLDgAOZ4zTa3lk56veaRVi2Son5nBn7iszCtlpS7FVEZE1kjhADH7aif6SYMCF1XQ5eeTJcGfp4/ZAgjjUDY1wq1EjuGGtIEcVTcXIltLf+sPfMj0BbkkoWWtbBOrjVa7JRn4pk+wKKRNr3Jyo0+5r1hOQeyS5ut8TMQUY4baaqg28dZ1G8jcsFNxFi0eKsvhFNK1aBW4m5QApQ5Fqfy5XXoEr/OXQhMRg0XHOuc7apkxyUM+Zo1uxwQEbTAd5eXtEVQNEuQ5BRvRY8jOxbQIDAQABMA0GCSqGSIb3DQEBCwUAA4IBAQBvX2z30PXkUXPZ7D6W5uAIxwdyYwvpfr4JKj7/QWuQKuexWgr1TV12/Ub7OIF711hV/PpC5ABeDxbSC8mbwezs4xwTdHQi5shp0bm9zBEX645gVbM8ovat88c3beoDGwbV6txen5bQXnisurucwJYCenegyCgyiCEGukzOAgvUR49KIvvqZYYmgimZle9CKp1yoCRiXZdryoncg7v9zR2RcdFxLNjivESn/uFtyb77L2DyuQpD6rBpeLT8bYo8/gqUTqPbBXWYC+n6NVRAsJwwfsaByDyU6EBw9CqCcJd6a4D520WyFqMHrbzxkAZI5UsU1shTdVDOF0BO7uVS+x1M</ds:X509Certificate></ds:X509Data></KeyInfo></ds:Signature><Subject><NameID Format="urn:oasis:names:tc:SAML:2.0:nameid-format:transient">i_skiridomov@wargaming.net</NameID><SubjectConfirmation Method="urn:oasis:names:tc:SAML:2.0:cm:bearer"><SubjectConfirmationData InResponseTo="_9b309f1e-e3f1-47ae-bd43-289430f73810" NotOnOrAfter="2018-04-02T14:27:59.978Z" Recipient="https://gitlab.rnd.wargaming.net/users/auth/saml/callback" /></SubjectConfirmation></Subject><Conditions NotBefore="2018-04-02T14:22:59.947Z" NotOnOrAfter="2018-04-02T15:22:59.947Z"><AudienceRestriction><Audience>https://gitlab.rnd.wargaming.net</Audience></AudienceRestriction></Conditions><AttributeStatement><Attribute Name="http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress"><AttributeValue>i_skiridomov@wargaming.net</AttributeValue></Attribute><Attribute Name="http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name"><AttributeValue>Ivan Skiridomov</AttributeValue></Attribute><Attribute Name="agroups"><AttributeValue>Domain Users</AttributeValue><AttributeValue>Users (CY1)</AttributeValue><AttributeValue>NET-Dev</AttributeValue><AttributeValue>VPN Users (All)</AttributeValue><AttributeValue>DFS-BY-DepartExch-VideoExchange_R</AttributeValue><AttributeValue>VPN Users (CY1)</AttributeValue><AttributeValue>Employees (Wargaming)</AttributeValue><AttributeValue>DFS-BY-DepartExch-QA_Performance_R</AttributeValue><AttributeValue>NET-Dev-CY</AttributeValue><AttributeValue>US4-JIRA-EXCALIBUR</AttributeValue><AttributeValue>NET-DevPC-SG1</AttributeValue><AttributeValue>Grafana-Users</AttributeValue><AttributeValue>DFS-BY-DepartExch-Symbols_R</AttributeValue><AttributeValue>DFS-BY-DepartExch-History_File_Repository_R</AttributeValue><AttributeValue>DFS-BY-DepartExch-History_File_Repository-Exchange_Info_RW</AttributeValue><AttributeValue>DFS-BY-DepartExch-History_File_Repository-History_Info_R</AttributeValue><AttributeValue>DFS-BY-DepartExch-ART_Library_Pub_R</AttributeValue><AttributeValue>rnd-seafile-users</AttributeValue><AttributeValue>testrail-users-wowp</AttributeValue><AttributeValue>WGFacebook-users</AttributeValue><AttributeValue>share-users</AttributeValue><AttributeValue>US4-JIRA</AttributeValue><AttributeValue>wg-art_users</AttributeValue><AttributeValue>wgnmit-user</AttributeValue><AttributeValue>DFS-BY-DepartExch-mediateam_video_R</AttributeValue><AttributeValue>orgchart-users</AttributeValue><AttributeValue>crowduser-ix</AttributeValue><AttributeValue>crowduser-ixs</AttributeValue><AttributeValue>alerta_ro</AttributeValue><AttributeValue>US4-CONFLUENCE-EXCENG</AttributeValue><AttributeValue>mm-users</AttributeValue><AttributeValue>grhouse-users</AttributeValue><AttributeValue>FSTR-Custom-excalibur_share_R</AttributeValue><AttributeValue>tprocess-user</AttributeValue><AttributeValue>artifactory_rnd_admin</AttributeValue><AttributeValue>moodle-users</AttributeValue><AttributeValue>gitlab_rnd_user</AttributeValue><AttributeValue>FSTR-Custom-Excalibur_3PD_R</AttributeValue><AttributeValue>bnwms-user</AttributeValue><AttributeValue>bnwms-cn-user</AttributeValue><AttributeValue>SP_IP2_IP_Viewers</AttributeValue><AttributeValue>O365-Ent-E3</AttributeValue><AttributeValue>DFS-BY-DepartExch-Internship_R</AttributeValue><AttributeValue>DFS-BY-DepartExch-Internship_RW</AttributeValue><AttributeValue>Concur_abilitytologin</AttributeValue><AttributeValue>assetbank01</AttributeValue><AttributeValue>O365-EMS-E3</AttributeValue></Attribute></AttributeStatement><AuthnStatement AuthnInstant="2018-04-02T13:59:52.949Z" SessionIndex="_9881fb5f-0cff-4e3d-8e87-075b1bf5aff6"><AuthnContext><AuthnContextClassRef>urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport</AuthnContextClassRef></AuthnContext></AuthnStatement></Assertion></samlp:Response>"}
Can't verify CSRF token authenticity
Redirected to https://gitlab.rnd.wargaming.net/users/sign_in
Completed 302 Found in 6ms (ActiveRecord: 0.0ms)
I have modified omniauth_callbacks_controller.rb
and restart unicorn gitlab-ctl restart unicorn
class OmniauthCallbacksController < Devise::OmniauthCallbacksController
skip_before_action :verify_authenticity_token
include AuthenticatesWithTwoFactor
include Devise::Controllers::Rememberable
#protect_from_forgery except: [:kerberos, :saml, :cas3]
But nothing new in logs. Still same messages.
What questions are you trying to answer? What I need to do, to get more debug message ?