-
Bug
-
Resolution: Won't Fix
-
Low
-
None
-
all
-
2
-
Severity 2 - Major
-
1
-
Suggestion Description
Confluence Server REST API is active by default and there is no way to deactivate.
It should have a similar option like the Enabling the Remote API where you can simply deactivate the functionality if you do no use it or even to prevent bad use of it.
- is cloned from
-
CONFSERVER-54412 REST API - Improved HTTP Authentication
-
- Closed
-
- mentioned in
-
Page Failed to load
[CONFSERVER-59919] REST API - Deactivate the REST API
Remote Link | New: This issue links to "Page (Extranet)" [ 1024030 ] |
Remote Link | Original: This issue links to "Page (Confluence)" [ 487737 ] |
QA Demo Status | Original: Not Done [ 14330 ] | New: Not Needed [ 14332 ] |
QA Kickoff Status | Original: Not Done [ 14234 ] | New: Not Needed [ 14236 ] |
Resolution | New: Won't Fix [ 2 ] | |
Status | Original: Gathering Impact [ 12072 ] | New: Closed [ 6 ] |
Support reference count | Original: 1 | New: 2 |
Labels | Original: authentication no-cvss-required pse-request rest security | New: authentication dmb-legacy-jac-none no-cvss-required pse-request rest security |
UIS | Original: 11 | New: 1 |
Support reference count | Original: 26 | New: 1 |
Remote Link | New: This issue links to "Page (Confluence)" [ 487737 ] |
Description |
Original:
h4. Suggestion Description
[Confluence Server REST API|https://developer.atlassian.com/confdev/confluence-server-rest-api] is active by default and there is no way to deactivate. It should have a similar option like the [Enabling the Remote API|https://confluence.atlassian.com/doc/enabling-the-remote-api-150460.html] where you can simple deactivate the functionality if you do no use it or even to prevent bad use of it. |
New:
h4. Suggestion Description
[Confluence Server REST API|https://developer.atlassian.com/confdev/confluence-server-rest-api] is active by default and there is no way to deactivate. It should have a similar option like the [Enabling the Remote API|https://confluence.atlassian.com/doc/enabling-the-remote-api-150460.html] where you can simply deactivate the functionality if you do no use it or even to prevent bad use of it. |
Confluence's REST API underpins multiple parts of the user interface, and cannot be disabled without also breaking the UI.