<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>article QlikView Management Console access denied: Invalid request parameter due to cross-site request forgery token. in Official Support Articles</title>
    <link>https://community.qlik.com/t5/Official-Support-Articles/QlikView-Management-Console-access-denied-Invalid-request/ta-p/1716005</link>
    <description>&lt;P&gt;The QlikView Management Console denies access due to an Invalid cross-site request forgery token.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4&gt;Environment:&lt;/H4&gt;
&lt;DIV class="lia-indent-padding-left-30px"&gt;&lt;LI-PRODUCT title="QlikView" id="qlikView"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;&lt;BR /&gt;After an upgrade, or fresh installation of QlikView November 2018 (12.30), access to the Management Console fails with:&lt;BR /&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;Invalid request parameter. Please refer to the QMS logs for more information&lt;/SPAN&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;BR /&gt;The QlikView Management Service logs read:&lt;BR /&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;Error Request failed: System.Security.SecurityException: Invalid cross-site request forgery token. IP address of the sender: ::1 || at QMS.BackstageWebServer.PreventCrossSiteRequestForgery(HttpListenerRequest request, XmlDocument document) || at QMS.BackstageWebServer.HandleRequest(HttpListenerContext context) || The Zone of the assembly that failed was ....&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H3&gt;&lt;SPAN&gt;Resolution&lt;/SPAN&gt;&lt;/H3&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This is solved in QlikView 12.40.20000 (April 2019).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;STRONG&gt;Workaround:&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;Option 1:&amp;nbsp;&amp;nbsp;Disable &lt;STRONG&gt;Automatic refresh of task list&lt;/STRONG&gt; in the QMC -&amp;gt; Status -&amp;gt; Tasks tab at the bottom right of the window.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Option 2 (not recommended): Disable Cross Site Request Forgery prevention following&amp;nbsp;&lt;A href="https://community.qlik.com/t5/Knowledge-Base/QlikView-Management-Console-Enable-Cross-site-scripting/ta-p/1716809" target="_blank" rel="noopener" data-cke-saved-href="/articles/Basic/QlikView-Management-Console-Enable-Cross-site-scripting-protection"&gt;QlikView Management Console : Enable Cross site scripting protection&lt;/A&gt;, setting it from TRUE to FALSE. While not recommended, this step can be used to verify if the issue is caused by Cross-Site Request Forgery prevention being enabled.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 22 Jun 2021 15:08:16 GMT</pubDate>
    <dc:creator>Sonja_Bauernfeind</dc:creator>
    <dc:date>2021-06-22T15:08:16Z</dc:date>
    <item>
      <title>QlikView Management Console access denied: Invalid request parameter due to cross-site request forgery token.</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/QlikView-Management-Console-access-denied-Invalid-request/ta-p/1716005</link>
      <description>&lt;P&gt;The QlikView Management Console denies access due to an Invalid cross-site request forgery token.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4&gt;Environment:&lt;/H4&gt;
&lt;DIV class="lia-indent-padding-left-30px"&gt;&lt;LI-PRODUCT title="QlikView" id="qlikView"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;&lt;BR /&gt;After an upgrade, or fresh installation of QlikView November 2018 (12.30), access to the Management Console fails with:&lt;BR /&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;Invalid request parameter. Please refer to the QMS logs for more information&lt;/SPAN&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;BR /&gt;The QlikView Management Service logs read:&lt;BR /&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;Error Request failed: System.Security.SecurityException: Invalid cross-site request forgery token. IP address of the sender: ::1 || at QMS.BackstageWebServer.PreventCrossSiteRequestForgery(HttpListenerRequest request, XmlDocument document) || at QMS.BackstageWebServer.HandleRequest(HttpListenerContext context) || The Zone of the assembly that failed was ....&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H3&gt;&lt;SPAN&gt;Resolution&lt;/SPAN&gt;&lt;/H3&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This is solved in QlikView 12.40.20000 (April 2019).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;STRONG&gt;Workaround:&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;Option 1:&amp;nbsp;&amp;nbsp;Disable &lt;STRONG&gt;Automatic refresh of task list&lt;/STRONG&gt; in the QMC -&amp;gt; Status -&amp;gt; Tasks tab at the bottom right of the window.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Option 2 (not recommended): Disable Cross Site Request Forgery prevention following&amp;nbsp;&lt;A href="https://community.qlik.com/t5/Knowledge-Base/QlikView-Management-Console-Enable-Cross-site-scripting/ta-p/1716809" target="_blank" rel="noopener" data-cke-saved-href="/articles/Basic/QlikView-Management-Console-Enable-Cross-site-scripting-protection"&gt;QlikView Management Console : Enable Cross site scripting protection&lt;/A&gt;, setting it from TRUE to FALSE. While not recommended, this step can be used to verify if the issue is caused by Cross-Site Request Forgery prevention being enabled.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Jun 2021 15:08:16 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/QlikView-Management-Console-access-denied-Invalid-request/ta-p/1716005</guid>
      <dc:creator>Sonja_Bauernfeind</dc:creator>
      <dc:date>2021-06-22T15:08:16Z</dc:date>
    </item>
  </channel>
</rss>

