Stash creates sessions for unauthenticated users

XMLWordPrintable

    • Type: Bug
    • Resolution: Fixed
    • Priority: Low
    • 2.6.0
    • Affects Version/s: None
    • Component/s: None

      This can potentially create resource issues (for instance, public JIRA instances can have problems caused by a large number of sessions created by bots crawling the site).

      If it's possible that Stash could be deployed in similar circumstances (ie, crawlable by unauthenticated users) it might be wise to head off trouble by not creating sessions for unauthenticated connections, or at least taking steps to minimise the impact of short-lived sessions.

      If Stash is only ever intended to be used by authenticated users, there seems little point worrying about this (unless a bot repeatedly hitting the login page could still generate sessions and potentially cause a DOS)

              Assignee:
              jhinch (Atlassian)
              Reporter:
              James Polley
              Votes:
              1 Vote for this issue
              Watchers:
              7 Start watching this issue

                Created:
                Updated:
                Resolved: