October CMS 2.2.4 - Backend: Invalid Security Token

Viewed 124

I'm running October CMS v2.2.4 on a dedicated managed server with Cloudways. I keep getting "Invalid Security Token" every few minutes after saving any changes in the Backend and I'm forced to refresh the page, redo my changes, then save again. Any ideas on how to fix this?

2 Answers

This could be caused due to CSRF protection and Session.

  1. Check session.php file and increase session lifetime

'lifetime' => 120,

  1. Then run php artisan cache:clear

  2. Check for URL if it is running on https:// rather than http://

  3. If all of above points didn't help it could be a server configuration issue.

LukeTowers Explained this issue in following https://github.com/octobercms/october/issues/3266

Here are two possible solutions:

  1. Give 775 permission to storage directory. The server may not have permission to create a session file.

  2. Change session driver from file to database so the session will manage by the database instead.

SESSION_DRIVER=database
Related