Support

Admin Tools

#35042 Using htaccess maker for Invalid Token issue

Posted in ‘Admin Tools for Joomla! 4 & 5’
This is a public ticket

Everybody will be able to see its contents. Do not include usernames, passwords or any other sensitive information.

Environment Information

Joomla! version
n/a
PHP version
n/a
Admin Tools version
n/a

Latest post by on Friday, 14 May 2021 20:17 CDT

dunwin

We are having some problems with users getting Invalid Access Token messages. Doing some research, one option is to increase Session time which we have done. Another option is to have  non-www to www redirect set up in htaccess.

Up to now I have been reluctant to us htaccess on our production site as experience in the past has been that one change can cause all kinds of problems and I am NO EXPERT in htaccess.

So, I have 3 questions.

1. Can I use htaccess maker to set up 'non-www to www redirect' 

2. is it ok to use the default settings of htaccess.maker (see screen shot attached)

3. How do I get out of trouble if things go wrong??

Thanks in advance for your help.

David

 

 

 David Unwin - London UK

tampe125
Akeeba Staff

Hello,

when this happens? When you try to login inside the backend? If that's the case, the culprit is not your server or website, but your browser. They cache the login page to make it "load faster", however the access token expires so you get the error.

To be honest, this should be just a rare issue, happening from time to time. Do you get it very often?

Davide Tampellini

Developer and Support Staff

🇮🇹Italian: native 🇬🇧English: good • 🕐 My time zone is Europe / Rome (UTC +1)
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

dunwin

Hi Davide,

It is our registered users in the Front End who have the problem, not back-end users like myself. Our users are only really active in the summer months (We are an open air swimming pool) from May to September. We had a lot of issues with Invalid Token last year (2020). People are starting to login to the site now as we approach our opening and it will get busier. So, I am trying to prevent the issues we had last year. So far, I have only had a couple of users report the problem.

So, I have changed the session time from 15mins to 1 Day, so hopefully that will eliminate some of the problems. 

I was trying improve things further by using non-www to www redirect set up in htaccess. which some Joomla experts said could also cause a problem. Some of the links to our site (i.e. from our Facebook page) are to https://cirenopenair.org.uk rather than www.cirenopenair.org.uk. 

So that was the reason for my questions to you.

Kind regards

David

 

 

 David Unwin - London UK

tampe125
Akeeba Staff

Ok, now I got it.

Redirection is completely unrelated to your issue. If you want to tackle it to fix your URLs, that's fine, but it won't fix your Invalid Access Token issue. Do you have cache enabled in any way (ie Joomla core one or provided by another plugin)? I suspect that the form with the login is served from the cache, which has an expired access token, so when users actually try to use it, they get the error message.

Looking at your Htaccess Maker configuration, it seems it's fine. You can create the redirection by enabling the corresponding option inside the page; if anything goes wrong, Admin Tools creates a backup of your .htaccess file name .htaccess.admintools . Simply rename it back and you'll get the previous version of your htaccess file.

Davide Tampellini

Developer and Support Staff

🇮🇹Italian: native 🇬🇧English: good • 🕐 My time zone is Europe / Rome (UTC +1)
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

dunwin

Hi Davide, Thanks for the info. on redirection, that is very useful. I will ignore this for my problem

We do have Cache set on, but we have disabled the cache plugin See screen shots

I suppose I am no asking something outside of the scope of Akeeba so don't feel obliged to research or answer this, but I would appreciate it if you could look at my cache settings. Do you think they are appropriate for our site?

 

Kind regards

 

 

 David Unwin - London UK

tampe125
Akeeba Staff

In theory yes, but I'd suggest to disable it for a few days to check if such problem goes away. Does it happen to all customers, or only to specific ones?

Davide Tampellini

Developer and Support Staff

🇮🇹Italian: native 🇬🇧English: good • 🕐 My time zone is Europe / Rome (UTC +1)
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

dunwin

Hi Davide,

Just a couple of users had the problem so far. One of them we had to get them to login with a different email address and with that everything works fine.  On the old email address, we checked their IP address was not blocked, cleared their history and cache settings, but still no joy. I asked the user to try their old email address in  day or so and come back to me. I could actually login to the user's account from my Laptop without any issue. So now my feeling is that it is some problem with their settings. They use Chrome on their phone, tablet and PC...All had the same problem, but I was not surprised as Chrome syncs their settings across all devices.

Thank you so much for looking at this problem. 

I will leave the ticket open for a few days and then close it, if we hear of no other problems

Kind regards

 

 

 David Unwin - London UK

tampe125
Akeeba Staff

Ok, let me know how it goes.

Davide Tampellini

Developer and Support Staff

🇮🇹Italian: native 🇬🇧English: good • 🕐 My time zone is Europe / Rome (UTC +1)
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

System Task
system
This ticket has been automatically closed. All tickets which have been inactive for a long time are automatically closed. If you believe that this ticket was closed in error, please contact us.

Support Information

Working hours: We are open Monday to Friday, 9am to 7pm Cyprus timezone (EET / EEST). Support is provided by the same developers writing the software, all of which live in Europe. You can still file tickets outside of our working hours, but we cannot respond to them until we're back at the office.

Support policy: We would like to kindly inform you that when using our support you have already agreed to the Support Policy which is part of our Terms of Service. Thank you for your understanding and for helping us help you!