FrontAccounting 2.4.20 on PHP 8.3, site published through Cloudflare with the proxy on (orange cloud). Problem: The login was dropped every few screens, and in particular each time a main-menu tab was opened (index.php?application=...). Logging in again worked, until the next tab. SessionManager stores the client address on the session and, in preventHijacking(), treats a different address as a hijack and wipes the session. Behind Cloudflare, REMOTE_ADDR is a Cloudflare edge address, and that address changes from one request to the next. The visitor has not changed. The next menu click looks like a hijack, and the login is cleared. Solution: I enabled a solution that works for all users as it currently does, but also for servers who use Cloudflare Orange. What I changed: 1. The address stored and compared is the visitor address Cloudflare sends (CF-Connecting-IP), and only when the request also has Cloudflare's CF-RAY header. Both headers are required so a client who simply sends CF-Connecting-IP is not trusted. Users who are not coming through Cloudflare orange-cloud, or through another proxy that sets those two headers, are not affected. A LAN client, or a WAN client hitting the server directly, has no CF-RAY header, so clientAddress() returns REMOTE_ADDR and the check is the same as before. 2. I removed the 5% random call to regenerateSession() on every request. That path is not specific to Cloudflare. On PHP 8, regenerateSession() (session_regenerate_id, session_write_clo
Forum FrontAccounting forum
frontaccounting.com/punbb ↗Forum PunBB in inglese. 11 sezioni seguite: Reporting, Installation, Announcements, Banking and General Ledger, Banking and General Ledger, Setup, Accounts Receivable, Accounts Payable, Items and Inventory, Manufacturing e Dimensions.
- Discussioni al giorno
- 0
- Discussioni raccolte
- 118
- Messaggi al giorno
- 5
- Sezioni
- 11
- Fonti seguite
- 15
- Motore
- PunBB
Ultime discussioni
Raccolte ogni 4 ore dal feed pubblico del forum. Riproduciamo solo il titolo, il link e l'inizio del messaggio; ogni link rimanda alla fonte.
FrontAccounting 2.4.20 on PHP 8.3, site published through Cloudflare with the proxy on (orange cloud). Problem: The login was dropped every few screens, and in particular each time a main-menu tab was opened (index.php?application=...). Logging in again worked, until the next tab. SessionManager stores the client address on the session and, in preventHijacking(), treats a different address as a hijack and wipes the session. Behind Cloudflare, REMOTE_ADDR is a Cloudflare edge address, and that address changes from one request to the next. The visitor has not changed. The next menu click looks like a hijack, and the login is cleared. Solution: I enabled a solution that works for all users as it currently does, but also for servers who use Cloudflare Orange. What I changed: 1. The address stored and compared is the visitor address Cloudflare sends (CF-Connecting-IP), and only when the request also has Cloudflare's CF-RAY header. Both headers are required so a client who simply sends CF-Connecting-IP is not trusted. Users who are not coming through Cloudflare orange-cloud, or through another proxy that sets those two headers, are not affected. A LAN client, or a WAN client hitting the server directly, has no CF-RAY header, so clientAddress() returns REMOTE_ADDR and the check is the same as before. 2. I removed the 5% random call to regenerateSession() on every request. That path is not specific to Cloudflare. On PHP 8, regenerateSession() (session_regenerate_id, session_write_clo
I found a reproducible cross-company session/context problem in FrontAccounting 2.4.20 when browser tabs opened under different company contexts remain open. Steps to reproduce 1. Open FrontAccounting in company A and open Banking and General Ledger → Journal Inquiry. 2. Company A uses - as the date separator, so the page contains dates such as 2025-01-01 and 2025-12-31. 3. Change the active FrontAccounting session to company B in another browser tab. Company B uses / as the date separator. 4. Return to the old Journal Inquiry tab which was generated while company A was active. 5. Press Search without reloading that page. Actual result The old page is still displayed as belonging to company A, but the request is processed using the preferences of the currently active company B session. The following PHP warnings are produced: Undefined array key 1 in /srv/frontaccounting/includes/date_functions.inc at line 398 Undefined array key 2 in /srv/frontaccounting/includes/date_functions.inc at line 398 A non-numeric value encountered in /srv/frontaccounting/includes/date_functions.inc at line 405 The call shown in the error output is, for example: date2sql('2025-01-01') date2sql() obtains the current separator using: $sep = $SysPrefs->dateseps[user_date_sep()]; and for the YYYYMMDD date format eventually executes: list($year, $month, $day) = explode($sep, $date_); user_date_sep() in includes/current_user.inc gets the separator from the current session: return isset($_SESSION["wa_curr
I found a reproducible cross-company session/context problem in FrontAccounting 2.4.20 when browser tabs opened under different company contexts remain open. Steps to reproduce 1. Open FrontAccounting in company A and open Banking and General Ledger → Journal Inquiry. 2. Company A uses - as the date separator, so the page contains dates such as 2025-01-01 and 2025-12-31. 3. Change the active FrontAccounting session to company B in another browser tab. Company B uses / as the date separator. 4. Return to the old Journal Inquiry tab which was generated while company A was active. 5. Press Search without reloading that page. Actual result The old page is still displayed as belonging to company A, but the request is processed using the preferences of the currently active company B session. The following PHP warnings are produced: Undefined array key 1 in /srv/frontaccounting/includes/date_functions.inc at line 398 Undefined array key 2 in /srv/frontaccounting/includes/date_functions.inc at line 398 A non-numeric value encountered in /srv/frontaccounting/includes/date_functions.inc at line 405 The call shown in the error output is, for example: date2sql('2025-01-01') date2sql() obtains the current separator using: $sep = $SysPrefs->dateseps[user_date_sep()]; and for the YYYYMMDD date format eventually executes: list($year, $month, $day) = explode($sep, $date_); user_date_sep() in includes/current_user.inc gets the separator from the current session: return isset($_SESSION["wa_curr
Has anyone else been looking for a reliable bookkeeper in Melbourne for their small business? I came across AffordBooksTax, which offers bookkeeping and accounting support including bank reconciliation, BAS preparation, payroll, financial reporting and Xero services. They seem to focus on practical support and transparent pricing, which can be helpful for small businesses trying to stay organised with their accounts and tax obligations. If anyone is interested, you can contact AffordBooksTax on (03) 7071 1180, 0416 339 239, or 0402 124 067.
Has anyone else been looking for a reliable bookkeeper in Melbourne for their small business? I came across AffordBooksTax, which offers bookkeeping and accounting support including bank reconciliation, BAS preparation, payroll, financial reporting and Xero services. They seem to focus on practical support and transparent pricing, which can be helpful for small businesses trying to stay organised with their accounts and tax obligations. If anyone is interested, you can contact AffordBooksTax on (03) 7071 1180, 0416 339 239, or 0402 124 067.
Has anyone else been looking for a reliable bookkeeper in Melbourne for their small business? I came across AffordBooksTax, which offers bookkeeping and accounting support including bank reconciliation, BAS preparation, payroll, financial reporting and Xero services. They seem to focus on practical support and transparent pricing, which can be helpful for small businesses trying to stay organised with their accounts and tax obligations. If anyone is interested, you can contact AffordBooksTax on (03) 7071 1180, 0416 339 239, or 0402 124 067.
Has anyone else been looking for a reliable bookkeeper in Melbourne for their small business? I came across AffordBooksTax, which offers bookkeeping and accounting support including bank reconciliation, BAS preparation, payroll, financial reporting and Xero services. They seem to focus on practical support and transparent pricing, which can be helpful for small businesses trying to stay organised with their accounts and tax obligations. If anyone is interested, you can contact AffordBooksTax on (03) 7071 1180, 0416 339 239, or 0402 124 067.
Has anyone else been looking for a reliable bookkeeper in Melbourne for their small business? I came across AffordBooksTax, which offers bookkeeping and accounting support including bank reconciliation, BAS preparation, payroll, financial reporting and Xero services. They seem to focus on practical support and transparent pricing, which can be helpful for small businesses trying to stay organised with their accounts and tax obligations. If anyone is interested, you can contact AffordBooksTax on (03) 7071 1180, 0416 339 239, or 0402 124 067.
Has anyone else been looking for a reliable bookkeeper in Melbourne for their small business? I came across AffordBooksTax, which offers bookkeeping and accounting support including bank reconciliation, BAS preparation, payroll, financial reporting and Xero services. They seem to focus on practical support and transparent pricing, which can be helpful for small businesses trying to stay organised with their accounts and tax obligations. If anyone is interested, you can contact AffordBooksTax on (03) 7071 1180, 0416 339 239, or 0402 124 067.
it appears that the Transaction References do not look at the prefix when determining uniqueness. I have 2 Supplier Transaction References set up. 1 with no prefix (generic payments) and 1 with a prefix (checking account and check number as a reference) When entering a Supplier Payment, only the reference number is check for uniqueness, preventing references with the same number but different prefixes from being accepted. It seems that the Supplier Payment form will return the Reference List (ref_list) index but not the prefix value. Is there an easy way to allow duplicate reference numbers with different prefixes? Thanks
it appears that the Transaction References do not look at the prefix when determining uniqueness. I have 2 Supplier Transaction References set up. 1 with no prefix (generic payments) and 1 with a prefix (checking account and check number as a reference) When entering a Supplier Payment, only the reference number is check for uniqueness, preventing references with the same number but different prefixes from being accepted. It seems that the Supplier Payment form will return the Reference List (ref_list) index but not the prefix value. Is there an easy way to allow duplicate reference numbers with different prefixes? Thanks
118 discussioni raccolte dal 31 agosto 2026. Segui questo forum con una parola chiave →