CSRF mail

This commit is contained in:
SansPseudoFix 2016-12-01 15:15:09 +01:00 committed by Dennis Schubert
parent dd9bda24f4
commit 61300dab59
No known key found for this signature in database
GPG key ID: 5A0304BEA7966D7E

View file

@ -707,12 +707,23 @@ en:
body: |-
Hello %{name},
We received a request with a wrong/missing CSRF token from your account. To prevent any possible damage you have been logged out.
diaspora* has detected an attempt to access your session which might be unauthorised. This might be completely innocent, but it could be a cross-site request forgery (CSRF). To avoid any chance of your data being compromised, you have been signed out.
A request made using a incorrect or missing CSRF token can be caused by:
- An add-on manipulating the request or making requests without the token;
- A tab left open from a past session;
- Another website making requests, with or without your permission;
- Various other external tools;
- Malicious code trying to access your data.
For more information on CSRF see [%{link}](%{link}).
Sorry,
Dont worry; you can safely sign in again now.
If you see this message regularly, please check your browsing settings.
Thank you,
The diaspora* email robot!
report_email:
type: