Support

Admin Tools

#15727 Testing CSRFShield

Posted in ‘Admin Tools for Joomla! 4 & 5’
This is a public ticket

Everybody will be able to see its contents. Do not include usernames, passwords or any other sensitive information.

Environment Information

Joomla! version
n/a
PHP version
n/a
Admin Tools version
n/a

Latest post by tampe125 on Thursday, 11 April 2013 05:04 CDT

gakijken
As we are suffering a lot of spam in our forms I wanted to test the CSRFShield in our RSForm!Pro forms. In the advanced setup a hidden field would be injected into the form.
I tried this and checked the HTML code of the form. Maybe I am missing something but I could find the hidden input field. How can I check to see if this is working correctly?
Thanks and regards,
Rene Kreijveld

tampe125
Akeeba Staff
Hi Rene,

is the new field in your form or not?
Can you post a link to your page so I can check?

Davide Tampellini

Developer and Support Staff

🇮🇹Italian: native 🇬🇧English: good • 🕐 My time zone is Europe / Rome (UTC +1)
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

gakijken
Hi Davide,
Here is the link: http://lararongen.publicanda.nl/contact
Maybe I am overlooking it but I couldn't find the extra form field.
I have setup ATPro as follows:
CSRF/Anti-spam form protection (CSRFShield): Advanced

Regards, Rene

tampe125
Akeeba Staff
Hi Rene,

I just tested it against the latest version of RSForm and it works for me.
Which version are you using?
Is the Admin Tools system plugin correctly published?
Can you tell me the order of this plugin?

Davide Tampellini

Developer and Support Staff

🇮🇹Italian: native 🇬🇧English: good • 🕐 My time zone is Europe / Rome (UTC +1)
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

gakijken
Hi Davide,

Joomla 2.5.9
Admin Tools Pro 2.5.3
RSForm!Pro 1.4.0 REV 46
System - Admin Tools plugin IS published

PHP 5.3.16
MySQL 5.5.16
Apache 2

Order of the published System Plugins:

ACL Manager: 0
Snippets: 0
Sliders: 0
Modules Anywhere: 0
JCE Media Box: 0
Sourcerer: 0
Content Templater: 0
Cache Cleaner: 0
Admin Tools: 1
RSForm! Pro: 2
NoNumber Framework: 5
Advanced Module Manager: 9
P3P Policy: 14
Logout: 15
Foutopsporing: 16 (errordetection)
Log: 17
Verwijzingen: 18 (redirects)
Onthoud mij: 19 (remember me)
Highligt: 20
SEF: 21

tampe125
Akeeba Staff
Please can you try to move the RSForm plugin before the Admin Tools one?
If it's not working, can you set the Admin Tools plugin order to -30000, its default value?

Davide Tampellini

Developer and Support Staff

🇮🇹Italian: native 🇬🇧English: good • 🕐 My time zone is Europe / Rome (UTC +1)
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

gakijken
Hi Davide,

It is working now!

I first moved the rsform plugin before the admin tools plugin. That made the form working.

I then moved the admin tools plugin to position -3000. Then the hidden field disappeared again.
So then I moved the rsform plugin to position -3001. This way the rsform plugin comes before the admin tools plugin, but the admin tools plugin still comes before all other plugins.

Thanks for your excellent suggestions Davide!

tampe125
Akeeba Staff
You're welcome!

Davide Tampellini

Developer and Support Staff

🇮🇹Italian: native 🇬🇧English: good • 🕐 My time zone is Europe / Rome (UTC +1)
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

Support Information

Working hours: We are open Monday to Friday, 9am to 7pm Cyprus timezone (EET / EEST). Support is provided by the same developers writing the software, all of which live in Europe. You can still file tickets outside of our working hours, but we cannot respond to them until we're back at the office.

Support policy: We would like to kindly inform you that when using our support you have already agreed to the Support Policy which is part of our Terms of Service. Thank you for your understanding and for helping us help you!