# Inconistent csrf issues

**URL:** <https://forum.mautic.org/t/inconistent-csrf-issues/34277>\
**Category:** Product Support\
**Created:** [December 2, 2024, 11:47am UTC](https://forum.mautic.org/t/inconistent-csrf-issues/34277 "2024-12-02T11:47:55Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![ldev](https://avatars.discourse-cdn.com/v4/letter/l/b38774/32.png) [@ldev](https://forum.mautic.org/u/ldev)\
**Post date:** [December 2, 2024, 11:47am UTC](https://forum.mautic.org/t/inconistent-csrf-issues/34277/1 "2024-12-02T11:47:55Z")

</div>

**Your software**  
My Mautic version is: 5.1.1  
My PHP version is: 8.1  
My Database type and version is: mysql

**Your problem**  
Inconsistent CSRF issues.  
Anyone is having troubles saving data - like adding contacts. where it would save sometimes but sometimes not saying csrf is ivalid?

---

<div class="post-metadata">

**Author:** ![ldev](https://avatars.discourse-cdn.com/v4/letter/l/b38774/32.png) [@ldev](https://forum.mautic.org/u/ldev)\
**Post date:** [December 2, 2024, 11:50am UTC](https://forum.mautic.org/t/inconistent-csrf-issues/34277/2 "2024-12-02T11:50:40Z")

</div>

OK, if any of you are running into a weird inconsistent CSRF problems with mautic after fresh installation.

Where sometimes mautic works, but in like 70% of cases it reports “The CSRF token is invalid. Please try to resubmit the form.” and doesn’t save on ajax/fetch calls…

Problem was as it turned out - In my docker setup - I intentionally have **ipv6** enabled.  
Also my docker networks have **IPv6** configured.  
So my mautic containers get both IPv6 and IPv4 - Docker will then use either one interchangeably and I think defaults to IPv6 now. So it would try IPv6 first, it wouldnt work, so it would return back 302 and page would reload. I observed it sometimes would reload the same page 3-6 times on IPv6, and then would try IPV4. But csrf token would be no longer valid because of those previous 302s would have I think used it up.

So you have to make sure to whitelist IPv6 range in trusted\_proxies as well (not only IPv4).  
Do something like this (obviously more precise ips/ranges are recommended):

```auto
        'trusted_proxies' => array(
                '0' => '0.0.0.0/0',
                '1' => '::/0'
        ),

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex020/uploads/mautic/original/1X/43c63600fe51440378769136903f1fa2a9a34102.png) [@system](https://forum.mautic.org/u/system)\
**Post date:** [December 3, 2024, 11:51pm UTC](https://forum.mautic.org/t/inconistent-csrf-issues/34277/3 "2024-12-03T23:51:25Z")

</div>

This topic was automatically closed 36 hours after the last reply. New replies are no longer allowed.
