Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!

Supported by

Local JATOS installation, cannot download *any* results due to CSRF restrictions

I'm running local JATOS under virtual linux (Win10 / Ubuntu 18.04 LTS), accessing the local server via http://127.0.0.1:9000 (built-in admin as the only user). This setup has been working fine for some time. Now, following JATOS 3.9.3 => 3.9.6 upgrade (via admin interface) I cannot download any results, the txt/zip/jatos experiment files end up with one-liner text content

You're not allowed to access this resource.

even though JATOS GUI shows notification that the file was downloaded successfully. Looking at JATOS application log, there's a reference to CSRF token which seems to refer to some cross-site scripting security feature:

2025-07-08 11:40:42,964 [INFO] - g.ErrorHandler - forbidden: No CSRF token found for application/json body
2025-07-08 11:40:42,964 [WARN] - p.f.CSRF - [CSRF] Check failed because application/json for request /jatos/api/v1/results/data?asPlainText=true&isApiCall=false
2025-07-08 11:40:33,792 [INFO] - gui_access - GET /jatos/componentResults/tableData?componentId=115&_=1751964033695 (admin)
2025-07-08 11:40:33,627 [INFO] - gui_access - GET /jatos/57/115/results (admin)
2025-07-08 11:40:32,104 [INFO] - gui_access - GET /jatos/57/componentsTableData?_=1751964032023 (admin)

I'm assuming this is related to JATOS 3.9.3 CSRF vulnerability https://nvd.nist.gov/vuln/detail/CVE-2024-51382 . I already tried out creating a new user (instead of admin) and using that to download the results file, but end up with the same broken results file output. Spending some time in JATOS github repo (with CSRF search terms) I ended up with a workaround of adding these to jatos.conf effectively removing these CSRF features completely (I would assume) but I feel it's a bit hacky..

play.filters {
 enabled -= play.filters.csrf.CSRFFilter
}

Should this be documented somewhere more clearly? I'm fine with this workaround, but somehow feel it should be default config for new users.

Comments

  • That's is strange. It looks like the CSRF token isn't send with the request. I just tried it out, just to be sure, with a new installation on Ubuntu 22.04 and the result download worked without problems. I don't think your issue has something to do with your Ubuntu being older or that it is a virtual one running on Win10.

    I have some questions:

    • How does your jatos.conf look like? Did you configure something there?
    • Does the issue persist even after restarting JATOS?
    • Does the issue happen in different browsers?
    • Can you please try to turn off the cache in your browser and try if you can download results now.

    Best,

    K.

  • Yep, this seemed weird indeed. Following Windows 10 restart due to upgrades I reverted back to "default" jatos.conf (no play.filters section) and cannot reproduce the download issue anymore with the same virtual Ubuntu 18.04 (I was using Chrome at that time if it matters). During the issues the jatos.conf on the testing machine was plain default, no modifications whatsoever, only application.conf included and rest of the file was commented out.

    This might indeed have something to do with browser cache/cookies. If I recall correctly, prior to doing the JATOS 3.9.3=>3.9.6 upgrade the JATOS experiment admin interface had some UI issues, it wasn't showing any component results listed in table format for one specific component ("select all" upgraded the count in the bottom of the page but didn't eventually download anything). I cleared the browser cache only to localhost at that time, it helped with this visibility issue, but I probably didn't do this cleanly enough (i.e. localhost JATOS page was open during that time when I cleared the cookies and it helped practically instantly).

    All in all, it seems it was a temporary glitch, fortunately.

  • Nice you could solve it!

Sign In or Register to comment.

agen judi bola , sportbook, casino, togel, number game, singapore, tangkas, basket, slot, poker, dominoqq, agen bola. Semua permainan bisa dimainkan hanya dengan 1 ID. minimal deposit 50.000 ,- bonus cashback hingga 10% , diskon togel hingga 66% bisa bermain di android dan IOS kapanpun dan dimana pun. poker , bandarq , aduq, domino qq , dominobet. Semua permainan bisa dimainkan hanya dengan 1 ID. minimal deposit 10.000 ,- bonus turnover 0.5% dan bonus referral 20%. Bonus - bonus yang dihadirkan bisa terbilang cukup tinggi dan memuaskan, anda hanya perlu memasang pada situs yang memberikan bursa pasaran terbaik yaitu http://45.77.173.118/ Bola168. Situs penyedia segala jenis permainan poker online kini semakin banyak ditemukan di Internet, salah satunya TahunQQ merupakan situs Agen Judi Domino66 Dan BandarQ Terpercaya yang mampu memberikan banyak provit bagi bettornya. Permainan Yang Di Sediakan Dewi365 Juga sangat banyak Dan menarik dan Peluang untuk memenangkan Taruhan Judi online ini juga sangat mudah . Mainkan Segera Taruhan Sportbook anda bersama Agen Judi Bola Bersama Dewi365 Kemenangan Anda Berapa pun akan Terbayarkan. Tersedia 9 macam permainan seru yang bisa kamu mainkan hanya di dalam 1 ID saja. Permainan seru yang tersedia seperti Poker, Domino QQ Dan juga BandarQ Online. Semuanya tersedia lengkap hanya di ABGQQ. Situs ABGQQ sangat mudah dimenangkan, kamu juga akan mendapatkan mega bonus dan setiap pemain berhak mendapatkan cashback mingguan. ABGQQ juga telah diakui sebagai Bandar Domino Online yang menjamin sistem FAIR PLAY disetiap permainan yang bisa dimainkan dengan deposit minimal hanya Rp.25.000. DEWI365 adalah Bandar Judi Bola Terpercaya & resmi dan terpercaya di indonesia. Situs judi bola ini menyediakan fasilitas bagi anda untuk dapat bermain memainkan permainan judi bola. Didalam situs ini memiliki berbagai permainan taruhan bola terlengkap seperti Sbobet, yang membuat DEWI365 menjadi situs judi bola terbaik dan terpercaya di Indonesia. Tentunya sebagai situs yang bertugas sebagai Bandar Poker Online pastinya akan berusaha untuk menjaga semua informasi dan keamanan yang terdapat di POKERQQ13. Kotakqq adalah situs Judi Poker Online Terpercayayang menyediakan 9 jenis permainan sakong online, dominoqq, domino99, bandarq, bandar ceme, aduq, poker online, bandar poker, balak66, perang baccarat, dan capsa susun. Dengan minimal deposit withdraw 15.000 Anda sudah bisa memainkan semua permaina pkv games di situs kami. Jackpot besar,Win rate tinggi, Fair play, PKV Games