[%# The contents of this file are subject to the Mozilla Public # License Version 1.1 (the "License"); you may not use this file # except in compliance with the License. You may obtain a copy of # the License at http://www.mozilla.org/MPL/ # # Software distributed under the License is distributed on an "AS # IS" basis, WITHOUT WARRANTY OF ANY KIND, either express or # implied. See the License for the specific language governing # rights and limitations under the License. # # The Original Code is the Bugzilla Bug Tracking System. # # The Initial Developer of the Original Code is Frédéric Buclin. # # Contributor(s): Frédéric Buclin #%] [%# INTERFACE: # abuser: identity of the user who created the (invalid?) token. # token_action: the action the token was supposed to serve. # expected_action: the action the user was going to do. # script_name: the script generating this warning. # alternate_script: the suggested script to redirect the user to # if he declines submission. #%] [% PROCESS "global/field-descs.none.tmpl" %] [% PROCESS global/header.html.tmpl title = "Suspicious Action" style_urls = ['skins/standard/global.css'] %] [% IF abuser %]

When you view an administrative form in [% terms.Bugzilla %], a token string is randomly generated and stored both in the database and in the form you loaded, to make sure that the requested changes are being made as a result of submitting a form generated by [% terms.Bugzilla %]. Unfortunately, the token used right now is incorrect, meaning that it looks like you didn't come from the right page. The following token has been used :

[% IF token_action != expected_action %] [% END %] [% IF abuser != user.identity %] [% END %]
Action stored: [% token_action FILTER html %]
  This action doesn't match the one expected ([% expected_action FILTER html %]).
Generated by: [% abuser FILTER html %]
  This token has not been generated by you. It is possible that someone tried to trick you!

Please report this problem to [%+ Param("maintainer") FILTER html %].

[% ELSE %]
It looks like you didn't come from the right page (you have no valid token for the [% expected_action FILTER html %] action while processing the '[% script_name FILTER html%]' script). The reason could be one of:
Are you sure you want to commit these changes anyway? This may result in unexpected and undesired results.
[% PROCESS "global/hidden-fields.html.tmpl" exclude="^(Bugzilla_login|Bugzilla_password)$" %]

Or throw away these changes and go back to [%- alternate_script FILTER html %].

[% END %] [% PROCESS global/footer.html.tmpl %]