Base solution for your next web application
Open Closed

X-XSRF Token Issue in Dev Env #12532


User avatar
0
ips-jm created

Zero 14.3

Hi, we're frequently encountering this error in development environments. To resolve it, we need to manually clear the browser cache each time. Could you perhaps suggest a potential source of this issue?

INFO 2025-09-05 13:23:11,478 [68 ] Microsoft.AspNetCore.Hosting.Diagnostics - Request starting HTTP/2 POST https://localhost:44301/api/services/app/Install/CheckDatabase - - 0 INFO 2025-09-05 13:23:11,479 [68 ] pNetCore.Cors.Infrastructure.CorsService - CORS policy execution successful. INFO 2025-09-05 13:23:11,480 [68 ] on.JwtBearer.IPSwebAsyncJwtBearerHandler - Failed to validate the token. Microsoft.IdentityModel.Tokens.SecurityTokenExpiredException: IDX10223: Lifetime validation failed. The token is expired. ValidTo (UTC): '9/5/2025 10:54:09 AM', Current time (UTC): '9/5/2025 11:23:11 AM'. at Microsoft.IdentityModel.Tokens.ValidatorUtilities.ValidateLifetime(Nullable1 notBefore, Nullable1 expires, SecurityToken securityToken, TokenValidationParameters validationParameters) at Microsoft.IdentityModel.Tokens.Validators.ValidateLifetime(Nullable1 notBefore, Nullable1 expires, SecurityToken securityToken, TokenValidationParameters validationParameters) at System.IdentityModel.Tokens.Jwt.JwtSecurityTokenHandler.ValidateLifetime(Nullable1 notBefore, Nullable1 expires, JwtSecurityToken jwtToken, TokenValidationParameters validationParameters) at System.IdentityModel.Tokens.Jwt.JwtSecurityTokenHandler.ValidateTokenPayload(JwtSecurityToken jwtToken, TokenValidationParameters validationParameters, BaseConfiguration configuration) at System.IdentityModel.Tokens.Jwt.JwtSecurityTokenHandler.ValidateJWS(String token, TokenValidationParameters validationParameters, BaseConfiguration currentConfiguration, SecurityToken& signatureValidatedToken, ExceptionDispatchInfo& exceptionThrown) --- End of stack trace from previous location --- at System.IdentityModel.Tokens.Jwt.JwtSecurityTokenHandler.ValidateToken(String token, JwtSecurityToken outerToken, TokenValidationParameters validationParameters, SecurityToken& signatureValidatedToken) at System.IdentityModel.Tokens.Jwt.JwtSecurityTokenHandler.ValidateToken(String token, TokenValidationParameters validationParameters, SecurityToken& validatedToken) at IPSweb.Web.Authentication.JwtBearer.IPSwebAsyncJwtSecurityTokenHandler.ValidateToken(String securityToken, TokenValidationParameters validationParameters) in REDACTED.Web.Core/Authentication/JwtBearer/IPSwebAsyncJwtSecurityTokenHandler.cs:line 42 at IPSweb.Web.Authentication.JwtBearer.IPSwebAsyncJwtBearerHandler.HandleAuthenticateAsync() in REDACTED.Web.Core/Authentication/JwtBearer/IPSwebAsyncJwtBearerHandler.cs:line 142 INFO 2025-09-05 13:23:11,490 [68 ] on.JwtBearer.IPSwebAsyncJwtBearerHandler - Failed to validate the token. Microsoft.IdentityModel.Tokens.SecurityTokenExpiredException: IDX10223: Lifetime validation failed. The token is expired. ValidTo (UTC): '9/5/2025 10:54:09 AM', Current time (UTC): '9/5/2025 11:23:11 AM'. at Microsoft.IdentityModel.Tokens.ValidatorUtilities.ValidateLifetime(Nullable1 notBefore, Nullable1 expires, SecurityToken securityToken, TokenValidationParameters validationParameters) at Microsoft.IdentityModel.Tokens.Validators.ValidateLifetime(Nullable1 notBefore, Nullable1 expires, SecurityToken securityToken, TokenValidationParameters validationParameters) at System.IdentityModel.Tokens.Jwt.JwtSecurityTokenHandler.ValidateLifetime(Nullable1 notBefore, Nullable1 expires, JwtSecurityToken jwtToken, TokenValidationParameters validationParameters) at System.IdentityModel.Tokens.Jwt.JwtSecurityTokenHandler.ValidateTokenPayload(JwtSecurityToken jwtToken, TokenValidationParameters validationParameters, BaseConfiguration configuration) at System.IdentityModel.Tokens.Jwt.JwtSecurityTokenHandler.ValidateJWS(String token, TokenValidationParameters validationParameters, BaseConfiguration currentConfiguration, SecurityToken& signatureValidatedToken, ExceptionDispatchInfo& exceptionThrown) --- End of stack trace from previous location --- at System.IdentityModel.Tokens.Jwt.JwtSecurityTokenHandler.ValidateToken(String token, JwtSecurityToken outerToken, TokenValidationParameters validationParameters, SecurityToken& signatureValidatedToken) at System.IdentityModel.Tokens.Jwt.JwtSecurityTokenHandler.ValidateToken(String token, TokenValidationParameters validationParameters, SecurityToken& validatedToken) at IPSweb.Web.Authentication.JwtBearer.IPSwebAsyncJwtSecurityTokenHandler.ValidateToken(String securityToken, TokenValidationParameters validationParameters)in REDACTED.Web.Core/Authentication/JwtBearer/IPSwebAsyncJwtSecurityTokenHandler.cs:line 42 at IPSweb.Web.Authentication.JwtBearer.IPSwebAsyncJwtBearerHandler.HandleAuthenticateAsync() in REDACTED.Web.Core/Authentication/JwtBearer/IPSwebAsyncJwtBearerHandler.cs:line 165 INFO 2025-09-05 13:23:11,495 [68 ] on.JwtBearer.IPSwebAsyncJwtBearerHandler - Bearer was not authenticated. Failure message: One or more errors occurred. (IDX10223: Lifetime validation failed. The token is expired. ValidTo (UTC): '9/5/2025 10:54:09 AM', Current time (UTC): '9/5/2025 11:23:11 AM'.) (IDX10223: Lifetime validation failed. The token is expired. ValidTo (UTC): '9/5/2025 10:54:09 AM', Current time (UTC): '9/5/2025 11:23:11 AM'.) INFO 2025-09-05 13:23:11,495 [68 ] ft.AspNetCore.Routing.EndpointMiddleware - Executing endpoint 'IPSweb.Install.InstallAppService.CheckDatabase (IPSweb.Application)' INFO 2025-09-05 13:23:11,498 [68 ] c.Infrastructure.ControllerActionInvoker - Route matched with {area = "app", action = "CheckDatabase", controller = "Install"}. Executing controller action with signature IPSweb.Install.Dto.CheckDatabaseOutput CheckDatabase() on controller IPSweb.Install.InstallAppService (IPSweb.Application). ERROR 2025-09-05 13:23:11,499 [68 ] idateAntiforgeryTokenAuthorizationFilter - The required antiforgery header value "X-XSRF-TOKEN" is not present. Microsoft.AspNetCore.Antiforgery.AntiforgeryValidationException: The required antiforgery header value "X-XSRF-TOKEN" is not present. at Microsoft.AspNetCore.Antiforgery.DefaultAntiforgery.ValidateRequestAsync(HttpContext httpContext) at Abp.AspNetCore.Mvc.Antiforgery.AbpValidateAntiforgeryTokenAuthorizationFilter.OnAuthorizationAsync(AuthorizationFilterContext context) INFO 2025-09-05 13:23:11,499 [68 ] c.Infrastructure.ControllerActionInvoker - Authorization failed for the request at filter 'Abp.AspNetCore.Mvc.Antiforgery.AbpAutoValidateAntiforgeryTokenAuthorizationFilter'. INFO 2025-09-05 13:23:11,500 [68 ] icrosoft.AspNetCore.Mvc.StatusCodeResult - Executing StatusCodeResult, setting HTTP status code 400 INFO 2025-09-05 13:23:11,500 [68 ] c.Infrastructure.ControllerActionInvoker - Executed action IPSweb.Install.InstallAppService.CheckDatabase (IPSweb.Application) in 1.3717ms INFO 2025-09-05 13:23:11,502 [68 ] ft.AspNetCore.Routing.EndpointMiddleware - Executed endpoint 'IPSweb.Install.InstallAppService.CheckDatabase (IPSweb.Application)' INFO 2025-09-05 13:23:11,502 [68 ] Microsoft.AspNetCore.Hosting.Diagnostics - Request finished HTTP/2 POST https://localhost:44301/api/services/app/Install/CheckDatabase - 400 0 - 23.6246ms

Markdown is supported
Copy & paste or drag & drop images (max 30 MB per image)

4 Answer(s)
  • User Avatar
    0
    oguzhanagir created
    Support Team

    Hi @ips-jm

    Check token lifetimes: By default in ASP.NET Zero the AccessToken lifetime is 1 day and RefreshToken is 365 days. If you shortened these values, try reverting to defaults.

    Verify the refresh mechanism: On the Angular side, make sure the refreshToken endpoint is actually being called. If an expired token remains in the browser, automatic renewal may not be triggered.

    Review antiforgery configuration: Especially after login/logout, ensure the X-XSRF-TOKEN header is being sent along with requests. For development testing, you can temporarily disable antiforgery validation via AbpAntiForgeryManager to confirm if that’s the source of the issue.

    Markdown is supported
    Copy & paste or drag & drop images (max 30 MB per image)
  • User Avatar
    0
    kansoftware created

    [oguzhanagir] said: Hi @ips-jm

    Check token lifetimes: By default in ASP.NET Zero the AccessToken lifetime is 1 day and RefreshToken is 365 days. If you shortened these values, try reverting to defaults.

    Verify the refresh mechanism: On the Angular side, make sure the refreshToken endpoint is actually being called. If an expired token remains in the browser, automatic renewal may not be triggered.

    Review antiforgery configuration: Especially after login/logout, ensure the X-XSRF-TOKEN header is being sent along with requests. For development testing, you can temporarily disable antiforgery validation via AbpAntiForgeryManager to confirm if that’s the source of the issue.

    I am too facing this issue on different hosted environment and I also changed the token lifetime, access token to 1 hour and refresh token to 90 days. But I am usually facing this just after login. In which file does the refresh token logic is handled by zero

    Markdown is supported
    Copy & paste or drag & drop images (max 30 MB per image)
  • User Avatar
    0
    ips-jm created

    [oguzhanagir] said: Hi @ips-jm

    Check token lifetimes: By default in ASP.NET Zero the AccessToken lifetime is 1 day and RefreshToken is 365 days. If you shortened these values, try reverting to defaults.

    Verify the refresh mechanism: On the Angular side, make sure the refreshToken endpoint is actually being called. If an expired token remains in the browser, automatic renewal may not be triggered.

    Review antiforgery configuration: Especially after login/logout, ensure the X-XSRF-TOKEN header is being sent along with requests. For development testing, you can temporarily disable antiforgery validation via AbpAntiForgeryManager to confirm if that’s the source of the issue.

    We didn’t change the token lifetimes. Could it be that the refresh isn’t being called for the CheckDatabase call? It seems like there’s something wrong with the frontend, as there’s no way out of this error other than clearing the cache or cookies.

    Markdown is supported
    Copy & paste or drag & drop images (max 30 MB per image)
  • User Avatar
    0
    oguzhanagir created
    Support Team

    Hi

    Thank you for your feedback. We are investigating this issue and will update you here as soon as possible.

    Markdown is supported
    Copy & paste or drag & drop images (max 30 MB per image)