Uploaded image for project: 'Confluence Data Center'
  1. Confluence Data Center
  2. CONFSERVER-99436

User accessing a Jira ticket that is linked to a restricted Confluence page results in a 'User tried to access restricted page' entry in 'Security' category on Confluence Audit logs

XMLWordPrintable

      Issue Summary

      User accessing a Jira ticket that is linked to a restricted Confluence page results in a 'User tried to access restricted page' entry in 'Security' category on Confluence Audit logs. In other words, when a user views a Jira ticket that contains the Confluence page to which his/her permissions are restricted, it causes an entry in the audit logs on the Confluence side. Please note that the user never opens the restricted Confluence page(only Jira ticket is accessed). 

      Steps to Reproduce

      1. Set up Confluence and Jira. The following versions were tested:
        • Confluence 9.3.2 + Jira 10.5.0 (latest releases)
        • Confluence 9.2.2 + Jira 10.3.4 (latest LTS)
        • Confluence 8.5.19 + Jira 9.12.15
      2. Setup Jira as the User directory for Confluence so that Users are shared between both products
      3. Setup Application link between Jira and Confluence
      4. Go to Audit logs settings and increase the coverage of 'Security' to Advanced or Full
      5. As the admin user, Create a Page in Confluence and add a Jira ticket to it using Jira issue macro
      6. Go to Jira and open the corresponding ticket to verify that Confluence page is reflected in the 'Issue Links - mentioned in' section
      7. Restrict the page so that only the admin user can view/edit it
      8. Login to Jira as User1 and access the corresponding Jira ticket
      9. User1 will see 'No Confluence page found with the given URL' message against the linked Confluence page
      10. Check Audit logs on the Confluence side

      Expected Results

      Confluence Audit log shouldn't have a Security entry because User 1 didn't access the restricted Confluence page

      Actual Results

      An entry gets populated in the Confluence Audit log against Security category which says 'User tried to access restricted page'

      Workaround

      Currently there is no known workaround for this behavior. A workaround will be added here when available

        1. image-2025-03-14-18-13-09-159.png
          11 kB
          Juwin Zam
        2. image-2025-03-14-18-16-44-618.png
          12 kB
          Juwin Zam

              Unassigned Unassigned
              71e254add3b5 Juwin Zam
              Votes:
              3 Vote for this issue
              Watchers:
              4 Start watching this issue

                Created:
                Updated: