Uploaded image for project: 'Bitbucket Data Center'
  1. Bitbucket Data Center
  2. BSERV-19537

Ability to have the Websudo functionality working with SAML / SSO

    • Icon: Suggestion Suggestion
    • Resolution: Unresolved
    • None
    • Single Sign On
    • None
    • 8
    • We collect Bitbucket feedback from various sources, and we evaluate what we've collected when planning our product roadmap. To understand how this piece of feedback will be reviewed, see our Implementation of New Features Policy.

      Problem

      SSO requests are currently exempted from websudo. Users logged in through SSO can go straight into administration functions without a websudo check which poses a security risk.

      Solution

      Allow websudo to work with SAML/SSO setup as well as to allow websudo to work with other marketplace SAML/SSO plugins.

      Workaround

      • Set a new password for the user that was created with JIT provisioning: JIT provisioning creates a user in Bitbucket's Internal Directory and you can define a password for this user. As a side-effect, an administrator will have 2 passwords - the IdP password to log in Confluence and the Internal password to authenticate in secure-sessions.

       

          Form Name

            [BSERV-19537] Ability to have the Websudo functionality working with SAML / SSO

            The mentioned workaround is a security issue for us and will confuse the users, as they have to maintain a Password directly within the app instead of using their Azure Login.

            Please asap provide the same websudo functionality as it is already true for Jira and Confluence where other SSO Providers like Resolution are able to provide a SSO  based solution for the Websudo.

            Michael Mohr added a comment - The mentioned workaround is a security issue for us and will confuse the users, as they have to maintain a Password directly within the app instead of using their Azure Login. Please asap provide the same websudo functionality as it is already true for Jira and Confluence where other SSO Providers like Resolution are able to provide a SSO  based solution for the Websudo.

              Unassigned Unassigned
              ysun Yingran Sun
              Votes:
              8 Vote for this issue
              Watchers:
              11 Start watching this issue

                Created:
                Updated: