Uploaded image for project: 'Confluence Data Center'
  1. Confluence Data Center
  2. CONFSERVER-29277

PDF files no longer open in browser, users are prompted to download.

      NOTE: This bug report is for Confluence Server. Using Confluence Cloud? See the corresponding bug report.

      The current behavior (Confluence not allowing PDF files to be opened in the browser) is a side effect of a security improvement added to the product. As PDF files can be "active content", the behavior in Confluence will not be reverted.

      Workarounds:

      For Self-Hosted Instances
      1. Click on cog at the Confluence header and choose "Confluence Admin"
      2. Under "Users & Security" choose "Security Configuration".
      3. Click any of the "Edit" buttons on the page and find the "Attachment Download Security Policy" section.
      4. Select the "Insecure: Display all attachments inline" option and click "Save".

      For OnDemand Instances
      Create a Support ticket at http://support.atlassian.com requesting the change to be done in your instance.

        1. SecuritySettings.png
          46 kB
          Renan Battaglin

            [CONFSERVER-29277] PDF files no longer open in browser, users are prompted to download.

            VitalyA added a comment -

            Opening PDF files in some browsers provides additional opportunities for cross-site scripting.

            VitalyA added a comment - Opening PDF files in some browsers provides additional opportunities for cross-site scripting.

            Jay Miller added a comment -

            How is it more secure to require users to download a PDF to their local machine and open the document? Isn't that equivalent in security (but less convenient) to opening it in the browser?

            Jay Miller added a comment - How is it more secure to require users to download a PDF to their local machine and open the document? Isn't that equivalent in security (but less convenient) to opening it in the browser?

            Hi All,

            The current behavior (Confluence not allowing PDF files to be opened in the browser) is a side effect of a security improvement added to the product. As PDF files can be "active content", the behavior in Confluence will not be reverted.

            Workarounds:

            For Self-Hosted Instances
            1. Click on cog at the Confluence header and choose "Confluence Admin"
            2. Under "Users & Security" choose "Security Configuration".
            3. Click any of the "Edit" buttons on the page and find the "Attachment Download Security Policy" section.
            4. Select the "Insecure: Display all attachments inline" option and click "Save".

            For OnDemand Instances
            Create a Support ticket at http://support.atlassian.com requesting the change to be done in your instance.

            Renan Battaglin added a comment - Hi All, The current behavior (Confluence not allowing PDF files to be opened in the browser) is a side effect of a security improvement added to the product. As PDF files can be "active content", the behavior in Confluence will not be reverted. Workarounds: For Self-Hosted Instances 1. Click on cog at the Confluence header and choose "Confluence Admin" 2. Under "Users & Security" choose "Security Configuration". 3. Click any of the "Edit" buttons on the page and find the "Attachment Download Security Policy" section. 4. Select the "Insecure: Display all attachments inline" option and click "Save". For OnDemand Instances Create a Support ticket at http://support.atlassian.com requesting the change to be done in your instance.

            Rina Nir added a comment -

            Very annoying! I think this is almost a blocker. pleases fix!

            Rina Nir added a comment - Very annoying! I think this is almost a blocker. pleases fix!

            This bug is driving me crazy!!!

            John Lammers added a comment - This bug is driving me crazy!!!

            Please fix this! It is a huge inconvenience to have to download pdfs before opening them.

            Michelle Benes added a comment - Please fix this! It is a huge inconvenience to have to download pdfs before opening them.

              Unassigned Unassigned
              maguiar Marlon Aguiar
              Affected customers:
              8 This affects my team
              Watchers:
              19 Start watching this issue

                Created:
                Updated:
                Resolved: