#tampermonkey

bonobo@pluspora.com

Anyone have an idea why #pluspora is frequently logging me out?

@diaspora* HQ? @David Thiery? @Di Cleverly?
- #Safari on #macOS 10.14.6
- Whitelisted in Ghostery Lite and AdGuard
- Using @Isaac Kuo’s awesome script for multi-column pluspora with #Tampermonkey (can't be the culprit, can it?)

After logging back in I get this mail:

Hello Bonobo,

diaspora* has detected an attempt to access your session which might be unauthorised. To avoid any chance of your data being compromised, you have been signed out. Don’t worry; you can safely sign in again now.

A request has been made using a incorrect or missing CSRF token. This might be completely innocent, but it could be a cross-site request forgery (CSRF) attack.

This could have been caused by:

  • An add-on manipulating the request or making requests without the token;
  • A tab left open from a past session;
  • Another website making requests, with or without your permission;
  • Various other external tools;
  • Malicious code trying to access your data.

For more information on CSRF see https://www.owasp.org/index.php/Cross-SiteRequestForgery_(CSRF).

(And that link gives me a 404 🤣)

If you see this message repeatedly, please check the points above, including any browser add-ons.

Thank you, The diaspora* email robot!

Any help is appreciated, thanks in advance!