Uploaded image for project: 'Confluence Server and Data Center'
  1. Confluence Server and Data Center
  2. CONFSERVER-55306

Add the possibility to edit Confluence error pages to remove stack trace from being output to the UI

    XMLWordPrintable

    Details

    • UIS:
      40
    • Support reference count:
      4
    • Feedback Policy:
      We collect Confluence feedback from various sources, and we evaluate what we've collected when planning our product roadmap. To understand how this piece of feedback will be reviewed, see our Implementation of New Features Policy.

      Description

      NOTE: This suggestion is for Confluence Server.

      Problem Definition

      The Confluence error page typically displays "Oops - an error has occurred", it displays System error, the cause, then the stack trace that deals with that error. This is not desirable for all instances as it could be a security risk or provide unnecessary complexity for normal users.
      As noted in Open Web Application Security's Improper Error Handling suggestions:

      Improper handling of errors can introduce a variety of security problems for a web site. The most common problem is when detailed internal error messages such as stack traces, database dumps, and error codes are displayed to the user (hacker). These messages reveal implementation details that should never be revealed. Such details can provide hackers important clues on potential flaws in the site and such messages are also disturbing to normal users.

      Suggested Solution

      Have Confluence error pages have the possibility to have admins edit this page to not show the stack trace (or display a custom message) and just inform the user that an error has happened and that he/she need to grab assistance from the admin.

        Attachments

          Issue Links

            Activity

              People

              Assignee:
              Unassigned
              Reporter:
              kcao@atlassian.com Kim My Cao (Inactive)
              Votes:
              33 Vote for this issue
              Watchers:
              26 Start watching this issue

                Dates

                Created:
                Updated: