# X-CSRF-Token Fehler

**URL:** <https://forum.shopware.com/t/x-csrf-token-fehler/43940>\
**Category:** Allgemein\
**Created:** [22. Februar 2017 um 12:36 UTC](https://forum.shopware.com/t/x-csrf-token-fehler/43940 "2017-02-22T12:36:15Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![exact](https://avatars.discourse-cdn.com/v4/letter/e/a87d85/32.png) [@exact](https://forum.shopware.com/u/exact)\
**Post date:** [22. Februar 2017 um 12:36 UTC](https://forum.shopware.com/t/x-csrf-token-fehler/43940/1 "2017-02-22T12:36:15Z")

</div>

Hallo Freunde,

seit Update 5.2.18. bekommen wir bei Login und bei Neu Anmeldung folgende Fehler:

The provided X-CSRF-Token for path „/account/login/sTarget/account/sTargetAction/index“ is invalid. Please go back, reload the page and try again. in engine/Shopware/Components/CSRFTokenValidator.php on line 158

```
 #0 engine/Library/Enlight/Event/Handler/Default.php(91): Shopware\Components\CSRFTokenValidator-\>checkFrontendTokenValidation(Object(Enlight\_Controller\_ActionEventArgs)) #1 engine/Library/Enlight/Event/EventManager.php(214): Enlight\_Event\_Handler\_Default-\>execute(Object(Enlight\_Controller\_ActionEventArgs)) #2 engine/Library/Enlight/Controller/Action.php(141): Enlight\_Event\_EventManager-\>notify('Enlight\_Control...', Object(Enlight\_Controller\_ActionEventArgs)) #3 engine/Library/Enlight/Controller/Dispatcher/Default.php(523): Enlight\_Controller\_Action-\>dispatch('loginAction') #4 engine/Library/Enlight/Controller/Front.php(223): Enlight\_Controller\_Dispatcher\_Default-\>dispatch(Object(Enlight\_Controller\_Request\_RequestHttp), Object(Enlight\_Controller\_Response\_ResponseHttp)) #5 engine/Shopware/Kernel.php(180): Enlight\_Controller\_Front-\>dispatch() #6 vendor/symfony/http-kernel/HttpCache/HttpCache.php(487): Shopware\Kernel-\>handle(Object(Enlight\_Controller\_Request\_RequestHttp), 1, true) #7 engine/Shopware/Components/HttpCache/AppCache.php(255): Symfony\Component\HttpKernel\HttpCache\HttpCache-\>forward(Object(Symfony\Component\HttpFoundation\Request), true, NULL) #8 vendor/symfony/http-kernel/HttpCache/HttpCache.php(258): Shopware\Components\HttpCache\AppCache-\>forward(Object(Symfony\Component\HttpFoundation\Request), true) #9 vendor/symfony/http-kernel/HttpCache/HttpCache.php(275): Symfony\Component\HttpKernel\HttpCache\HttpCache-\>pass(Object(Symfony\Component\HttpFoundation\Request), true) #10 engine/Shopware/Components/HttpCache/AppCache.php(133): Symfony\Component\HttpKernel\HttpCache\HttpCache-\>invalidate(Object(Symfony\Component\HttpFoundation\Request), true) #11 vendor/symfony/http-kernel/HttpCache/HttpCache.php(206): Shopware\Components\HttpCache\AppCache-\>invalidate(Object(Symfony\Component\HttpFoundation\Request), true) #12 engine/Shopware/Components/HttpCache/AppCache.php(114): Symfony\Component\HttpKernel\HttpCache\HttpCache-\>handle(Object(Symfony\Component\HttpFoundation\Request), 1, true) #13 shopware.php(117): Shopware\Components\HttpCache\AppCache-\>handle(Object(Symfony\Component\HttpFoundation\Request)) #14 {main}

```

Leider nach Reload weiterhin ist&nbsp; Fehler vorhanden.

Hat jemand solche Fehler und Hinweise schon erlebt ?

Vielen Dank

MfG

Alex

&nbsp;

---

<div class="post-metadata">

**Author:** ![Tanny](https://avatars.discourse-cdn.com/v4/letter/t/dfb087/32.png) [@Tanny](https://forum.shopware.com/u/Tanny)\
**Post date:** [22. Februar 2017 um 12:48 UTC](https://forum.shopware.com/t/x-csrf-token-fehler/43940/2 "2017-02-22T12:48:27Z")

</div>

> [@exact schrieb:](https://forum.shopware.com/profile/5100/exact "exact")
> 
> …Hat jemand solche Fehler und Hinweise schon erlebt ?
> 
> Vielen Dank
> 
> MfG
> 
> Alex
> 
> &nbsp;

Mehr als einer…

Die Forensuche hilft da weiter:  
[https://forum.shopware.com/discussion/comment/188255#Comment\_188255](https://forum.shopware.com/discussion/comment/188255#Comment_188255)&nbsp;

---

<div class="post-metadata">

**Author:** ![exact](https://avatars.discourse-cdn.com/v4/letter/e/a87d85/32.png) [@exact](https://forum.shopware.com/u/exact)\
**Post date:** [22. Februar 2017 um 12:55 UTC](https://forum.shopware.com/t/x-csrf-token-fehler/43940/3 "2017-02-22T12:55:37Z")

</div>

Forensuche hilft wirklich, echt jetzt 😉

[https://forum.shopware.com/discussion/comment/188014/#Comment\_188014](https://forum.shopware.com/discussion/comment/188014/#Comment_188014)

---

<div class="post-metadata">

**Author:** ![exact](https://avatars.discourse-cdn.com/v4/letter/e/a87d85/32.png) [@exact](https://forum.shopware.com/u/exact)\
**Post date:** [22. Februar 2017 um 13:03 UTC](https://forum.shopware.com/t/x-csrf-token-fehler/43940/4 "2017-02-22T13:03:24Z")

</div>

Um zum verkurzen 😉

Wenn solche Fehler meldungen auftauchen, einfach in config.php (shopware root)

folgende zufügen

&nbsp;‘csrfProtection’ =\> [  
&nbsp;&nbsp;&nbsp; ‘frontend’ =\> false,  
&nbsp;&nbsp;&nbsp; ‘backend’ =\> false  
],

Gruße

Alex

&nbsp;

---

<div class="post-metadata">

**Author:** ![shcshopware](https://avatars.discourse-cdn.com/v4/letter/s/46a35a/32.png) [@shcshopware](https://forum.shopware.com/u/shcshopware)\
**Post date:** [3. März 2017 um 14:03 UTC](https://forum.shopware.com/t/x-csrf-token-fehler/43940/5 "2017-03-03T14:03:48Z")

</div>

Wichtig! Fehler immer noch nicht ganz korrigiert.

Ich habe nun auf 5.2.20 upgedatet und die Configanweisung (siehe oben) wieder entfernt.

Wenn ich mich anmelde und wieder abmelde und dann auf " **Erneut anmelden**" klicke, kommt ein falsches Template (wie vorher).  
Verwende auch Business Essentials in der aktuellen Version und einen 2. Shop (B2B). Dessen Footer wird mit angezeigt.

[https://swiss-healthcare.de/account/logout](https://swiss-healthcare.de/account/logout)

 ![](https://europe1.discourse-cdn.com/flex013/uploads/shopware/original/2X/0/0a0c32d53006aeda923daabcf05f6907cf511d7c.jpeg)

---

<div class="post-metadata">

**Author:** ![NextMike](https://avatars.discourse-cdn.com/v4/letter/n/838e76/32.png) [@NextMike](https://forum.shopware.com/u/NextMike)\
**Post date:** [3. März 2017 um 14:05 UTC](https://forum.shopware.com/t/x-csrf-token-fehler/43940/6 "2017-03-03T14:05:21Z")

</div>

Ich gehe nicht davon aus, dass es mit dem Topic hier zu tun hat.

---

<div class="post-metadata">

**Author:** ![shcshopware](https://avatars.discourse-cdn.com/v4/letter/s/46a35a/32.png) [@shcshopware](https://forum.shopware.com/u/shcshopware)\
**Post date:** [3. März 2017 um 14:12 UTC](https://forum.shopware.com/t/x-csrf-token-fehler/43940/7 "2017-03-03T14:12:46Z")

</div>

Der Fehler ist aufgetreten nach dem Update auf 5.2.18

---

<div class="post-metadata">

**Author:** ![NextMike](https://avatars.discourse-cdn.com/v4/letter/n/838e76/32.png) [@NextMike](https://forum.shopware.com/u/NextMike)\
**Post date:** [3. März 2017 um 14:14 UTC](https://forum.shopware.com/t/x-csrf-token-fehler/43940/8 "2017-03-03T14:14:40Z")

</div>

> [@shcshopware schrieb:](https://forum.shopware.com/profile/21215/shcshopware "shcshopware")
> 
> Der Fehler ist aufgetreten nach dem Update auf 5.2.18

das kann sein, es sieht für mich nach Eurem individuellen Problem aus. Frag mal denjenigen der das Theme angepasst hatte.&nbsp;

---

<div class="post-metadata">

**Author:** ![shcshopware](https://avatars.discourse-cdn.com/v4/letter/s/46a35a/32.png) [@shcshopware](https://forum.shopware.com/u/shcshopware)\
**Post date:** [3. März 2017 um 14:16 UTC](https://forum.shopware.com/t/x-csrf-token-fehler/43940/9 "2017-03-03T14:16:46Z")

</div>

Brauche ich nach dem Update auf 5.2.20 noch die&nbsp;csrfProtection Anweisung in der config.php?

---

<div class="post-metadata">

**Author:** ![NextMike](https://avatars.discourse-cdn.com/v4/letter/n/838e76/32.png) [@NextMike](https://forum.shopware.com/u/NextMike)\
**Post date:** [3. März 2017 um 14:18 UTC](https://forum.shopware.com/t/x-csrf-token-fehler/43940/10 "2017-03-03T14:18:28Z")

</div>

> [@shcshopware schrieb:](https://forum.shopware.com/profile/21215/shcshopware "shcshopware")
> 
> Brauche ich nach dem Update auf 5.2.20 noch die&nbsp;csrfProtection Anweisung in der config.php?

kommt darauf an ob Du Probleme mit CSRF hast, mach es raus und beobachte die Logfiles.&nbsp;

---

<div class="post-metadata">

**Author:** ![shcshopware](https://avatars.discourse-cdn.com/v4/letter/s/46a35a/32.png) [@shcshopware](https://forum.shopware.com/u/shcshopware)\
**Post date:** [3. März 2017 um 15:52 UTC](https://forum.shopware.com/t/x-csrf-token-fehler/43940/11 "2017-03-03T15:52:07Z")

</div>

> [@NextMike schrieb:](https://forum.shopware.com/profile/19433/NextMike "NextMike")
> 
> > [@shcshopware schrieb:](https://forum.shopware.com/profile/21215/shcshopware "shcshopware")
> > 
> > Der Fehler ist aufgetreten nach dem Update auf 5.2.18
> 
> das kann sein, es sieht für mich nach Eurem individuellen Problem aus. Frag mal denjenigen der das Theme angepasst hatte.&nbsp;
> 
> _NEIN! Der Fehler tritt auch im Demo-Shop auf._

---

<div class="post-metadata">

**Author:** ![Wulffmedia](https://avatars.discourse-cdn.com/v4/letter/w/d6d6ee/32.png) [@Wulffmedia](https://forum.shopware.com/u/Wulffmedia)\
**Post date:** [3. März 2017 um 15:56 UTC](https://forum.shopware.com/t/x-csrf-token-fehler/43940/12 "2017-03-03T15:56:32Z")

</div>

Erstmal ist dein NEIN! unhöflich.

Demo shop mit Standard theme?

---

<div class="post-metadata">

**Author:** ![shcshopware](https://avatars.discourse-cdn.com/v4/letter/s/46a35a/32.png) [@shcshopware](https://forum.shopware.com/u/shcshopware)\
**Post date:** [3. März 2017 um 16:02 UTC](https://forum.shopware.com/t/x-csrf-token-fehler/43940/13 "2017-03-03T16:02:32Z")

</div>

unhöflich: das war nicht meine Absicht!

Ja, auch im Demoshop mit Standardtemplate

Vor dem Update auf 5.2.18 hatte es immer korrekt funktioniert.

[http://www.shopwaredemo.de/account](http://www.shopwaredemo.de/account)

---

<div class="post-metadata">

**Author:** ![NextMike](https://avatars.discourse-cdn.com/v4/letter/n/838e76/32.png) [@NextMike](https://forum.shopware.com/u/NextMike)\
**Post date:** [3. März 2017 um 16:05 UTC](https://forum.shopware.com/t/x-csrf-token-fehler/43940/14 "2017-03-03T16:05:19Z")

</div>

> [@shcshopware schrieb:](https://forum.shopware.com/profile/21215/shcshopware "shcshopware")
> 
> unhöflich: das war nicht meine Absicht!
> 
> Ja, auch im Demoshop mit Standardtemplate
> 
> Vor dem Update auf 5.2.18 hatte es immer korrekt funktioniert.
> 
> [http://www.shopwaredemo.de/account](http://www.shopwaredemo.de/account)

Ich glaube Du musst hier für Aufklärung sorgen: schreibst Du von dem doppelten Footer oder von dem CSRF-Fehler?&nbsp;

---

<div class="post-metadata">

**Author:** ![shcshopware](https://avatars.discourse-cdn.com/v4/letter/s/46a35a/32.png) [@shcshopware](https://forum.shopware.com/u/shcshopware)\
**Post date:** [3. März 2017 um 16:12 UTC](https://forum.shopware.com/t/x-csrf-token-fehler/43940/15 "2017-03-03T16:12:55Z")

</div>

Es geht um den doppelten Footer!

---

<div class="post-metadata">

**Author:** ![NextMike](https://avatars.discourse-cdn.com/v4/letter/n/838e76/32.png) [@NextMike](https://forum.shopware.com/u/NextMike)\
**Post date:** [3. März 2017 um 16:20 UTC](https://forum.shopware.com/t/x-csrf-token-fehler/43940/16 "2017-03-03T16:20:15Z")

</div>

> [@shcshopware schrieb:](https://forum.shopware.com/profile/21215/shcshopware "shcshopware")
> 
> Es geht um den doppelten Footer!

und den doppelten Footer gibt es auch in dem Demo-Shop?&nbsp;

---

<div class="post-metadata">

**Author:** ![shcshopware](https://avatars.discourse-cdn.com/v4/letter/s/46a35a/32.png) [@shcshopware](https://forum.shopware.com/u/shcshopware)\
**Post date:** [3. März 2017 um 16:24 UTC](https://forum.shopware.com/t/x-csrf-token-fehler/43940/17 "2017-03-03T16:24:56Z")

</div>

Ja, siehe hier:  
[http://www.shopwaredemo.de/account](http://www.shopwaredemo.de/account)

---

<div class="post-metadata">

**Author:** ![Moritz\_Naczenski](https://dub1.discourse-cdn.com/flex013/user_avatar/forum.shopware.com/moritz_naczenski/32/7792_2.png) [@Moritz\_Naczenski](https://forum.shopware.com/u/Moritz_Naczenski)\
**Post date:** [3. März 2017 um 16:29 UTC](https://forum.shopware.com/t/x-csrf-token-fehler/43940/18 "2017-03-03T16:29:06Z")

</div>

Scheint mir aber dennoch aus einem Plugin zu kommen. Würde Business Essentials vermuten.

---

<div class="post-metadata">

**Author:** ![shcshopware](https://avatars.discourse-cdn.com/v4/letter/s/46a35a/32.png) [@shcshopware](https://forum.shopware.com/u/shcshopware)\
**Post date:** [3. März 2017 um 16:36 UTC](https://forum.shopware.com/t/x-csrf-token-fehler/43940/19 "2017-03-03T16:36:46Z")

</div>

Habe Business Essentials (aktuelle Version 3.0.1) schon seit 2 Jahren im Einsatz.  
Das Problem trat erst nach dem Update auf 5.2.18 auf.

 ![](https://europe1.discourse-cdn.com/flex013/uploads/shopware/original/2X/f/f0ccfe01135082584c42bc4456b56d3da2cf3856.jpeg)

---

<div class="post-metadata">

**Author:** ![shcshopware](https://avatars.discourse-cdn.com/v4/letter/s/46a35a/32.png) [@shcshopware](https://forum.shopware.com/u/shcshopware)\
**Post date:** [3. März 2017 um 16:44 UTC](https://forum.shopware.com/t/x-csrf-token-fehler/43940/20 "2017-03-03T16:44:31Z")

</div>

Es liegt am Business Essemtial. Habe das Plugin deaktiviert und der doppelte Footer trat nicht mehr auf.

Interessanterweise tritt der Fehler bei einer anderen Shopwareversion ([https://shop.cmr-hydraulik.de/](https://shop.cmr-hydraulik.de/)) ohne Business Essentials in der Version 5.2.20 auch nicht auf.

[Nächste Seite](https://forum.shopware.com/t/x-csrf-token-fehler/43940.md?page=2)
