#CSRF token mismatch
8 messages · Page 1 of 1 (latest)
Is SESSION_SECURE_COOKIE set to true in the .env?
When you tried with that set, did you clear the cache server-side
php /var/www/pterodactyl/artisan config:clear
and client-side (Troubleshoot in a private/incognito window)?
Redid it. Ensured via developer console that secure is not set. Still CSRF token mismatch. HttpOnly is set SameSite is Lax.
@steep gulch; Enable SSL for your Panel with HTTPS protocol scheme in the APP_URL, or set SESSION_SECURE_COOKIE to false in your .env which is a hidden file located at /var/www/pterodactyl.
You can open it directly with nano /var/www/pterodactyl/.env. Refresh config cache with cd /var/www/pterodactyl && php artisan config:clear