Uploaded image for project: 'Bitbucket Data Center'
  1. Bitbucket Data Center
  2. BSERV-2465

Stash creates sessions for unauthenticated users

    XMLWordPrintable

Details

    • Bug
    • Resolution: Fixed
    • Low
    • 2.6.0
    • None
    • None

    Description

      This can potentially create resource issues (for instance, public JIRA instances can have problems caused by a large number of sessions created by bots crawling the site).

      If it's possible that Stash could be deployed in similar circumstances (ie, crawlable by unauthenticated users) it might be wise to head off trouble by not creating sessions for unauthenticated connections, or at least taking steps to minimise the impact of short-lived sessions.

      If Stash is only ever intended to be used by authenticated users, there seems little point worrying about this (unless a bot repeatedly hitting the login page could still generate sessions and potentially cause a DOS)

      Attachments

        Issue Links

          Activity

            People

              jhinch jhinch (Atlassian)
              jpolley James Polley
              Votes:
              1 Vote for this issue
              Watchers:
              7 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: