Index: openacs-4/packages/acs-tcl/tcl/security-procs.tcl =================================================================== RCS file: /usr/local/cvsroot/openacs-4/packages/acs-tcl/tcl/security-procs.tcl,v diff -u -N -r1.78.2.46 -r1.78.2.47 --- openacs-4/packages/acs-tcl/tcl/security-procs.tcl 1 Mar 2017 23:55:56 -0000 1.78.2.46 +++ openacs-4/packages/acs-tcl/tcl/security-procs.tcl 26 Mar 2017 15:05:39 -0000 1.78.2.47 @@ -93,7 +93,7 @@ if {$::security::log(login_cookie) ne "debug"} { foreach c [list ad_session_id ad_secure_token ad_user_login ad_user_login_secure] { - lappend msg "$c [ad_get_cookie $c]" + lappend msg "$c '[ad_get_cookie $c]'" } ns_log notice "OACS [ns_conn url] cookies: $msg" } @@ -108,7 +108,13 @@ # Now check for login cookie ns_log $::security::log(login_cookie) "OACS: Not a valid session cookie, looking for login cookie '$errmsg'" - ad_user_logout + if {![string match "*does not exist*" $errmsg]} { + # + # Current firefox does not seem to include cookies in CSP + # messages sent via "report-uri" + # + ad_user_logout + } sec_login_handler } else { # The session cookie already exists and is valid.