Uploaded image for project: 'Jira Data Center'
  1. Jira Data Center
  2. JRASERVER-77686

Wrong information about PAT implementation on Jira and Confluence on public document

    XMLWordPrintable

Details

    Description

      Problem Definition

      While Bitbucket and Bamboo have their own PAT implementation, Jira and Confluence share the same code base through a plugin.

      There's a public document on https://success.atlassian.com/solution-resources/agile-and-devops-ado/platform-administration/how-to-secure-jira-and-confluence-rest-api-calls-in-data-center stating:

      These tokens are to be used for REST API calls only, they cannot be used to log in to the product UI.

      While this is true for the design implementation on Bamboo and Bitbucket, this wasn't an implementation decision for Jira and Confluence.

      Although there's no in-product UI to allow user authentication with a token, the solution doesn't filter out requests from a browser.

      Suggested Solution

      The document should be clear to which product that statement is true and provide more details on how it would work on Jira and Confluence

      Attachments

        Activity

          People

            a803384f6b1d Tomasz Prus
            tmasutti Thiago Masutti
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

            Dates

              Created:
              Updated: