LostaFound

How to use LostaFound

Login form and cross-site error recovery

  1. A previous security update incorrectly rejected normal browser form submissions under the no-referrer privacy policy. The compatibility fix accepts Origin: null only when the browser reports Sec-Fetch-Site: same-origin, then still verifies the session CSRF token. Privacy and cross-site protection remain enabled.
  2. Open a fresh LostaFound sign-in form and try again. In the app, reopen online or use Refresh; no reinstall is required. If you have unsaved report text, copy it before reloading. This update does not change your password or require a password reset.
  3. If the error continues, note the page and whether you used a browser or the app. Administrators can run the CSRF attack category and security-http regression. Do not share passwords, session cookies or form tokens in screenshots or logs. The security manual explains the exact checks and source files.

Open feature · All guides